Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55396 | UNKNOWN | — | Cleartext transmission without a cryptographic integrity check in operator control unit to robot UDP traffic in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 … | Oct 01, 2026 |
| CVE-2026-55395 | UNKNOWN | — | Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure … | Oct 01, 2026 |
| CVE-2026-55394 | UNKNOWN | — | Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against … | Oct 01, 2026 |
| CVE-2026-55393 | UNKNOWN | — | Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and … | Oct 01, 2026 |
| CVE-2026-27874 | UNKNOWN | — | : Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before … | Oct 01, 2026 |
| CVE-2026-104183 | MEDIUM | 5.1 | stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with … | Oct 01, 2026 |
| CVE-2026-104182 | MEDIUM | 6.2 | stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js … | Oct 01, 2026 |
| CVE-2026-104181 | MEDIUM | 5.4 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently … | Oct 01, 2026 |
| CVE-2026-104020 | HIGH | 7.5 | Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, … | Oct 01, 2026 |
| CVE-2026-102514 | UNKNOWN | — | Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and earlier allows an attacker who … | Oct 01, 2026 |
| CVE-2026-102370 | UNKNOWN | — | Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the … | Oct 01, 2026 |
| CVE-2026-93832 | MEDIUM | 4.4 | A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps. | Oct 01, 2026 |
| CVE-2026-82358 | MEDIUM | 6.5 | RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions … | Oct 01, 2026 |
| CVE-2026-82357 | MEDIUM | 6.5 | RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user … | Oct 01, 2026 |
| CVE-2026-71542 | UNKNOWN | — | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE … | Oct 01, 2026 |
| CVE-2026-71426 | UNKNOWN | — | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an … | Oct 01, 2026 |
| CVE-2026-70650 | UNKNOWN | — | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an … | Oct 01, 2026 |
| CVE-2026-56662 | CRITICAL | 9.6 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE … | Oct 01, 2026 |
| CVE-2026-56661 | HIGH | 7.5 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update … | Oct 01, 2026 |
| CVE-2026-56660 | CRITICAL | 9.1 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update … | Oct 01, 2026 |
| CVE-2026-55252 | UNKNOWN | — | OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on … | Oct 01, 2026 |
| CVE-2026-55251 | MEDIUM | 6.5 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs … | Oct 01, 2026 |
| CVE-2026-54049 | HIGH | 8.7 | Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores … | Oct 01, 2026 |
| CVE-2026-53964 | HIGH | 7.2 | Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, … | Oct 01, 2026 |
| CVE-2026-53953 | CRITICAL | 9.1 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset … | Oct 01, 2026 |