Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55255
Total
4360
Critical
16420
High
16093
Medium
CVE ID Severity Score Description Published
CVE-2026-80148 HIGH 8.6 Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener … Sep 22, 2026
CVE-2026-80147 CRITICAL 9.9 Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers … Sep 22, 2026
CVE-2026-80146 CRITICAL 9.9 Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers … Sep 22, 2026
CVE-2026-80145 CRITICAL 9.1 Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with … Sep 22, 2026
CVE-2026-80144 CRITICAL 9.9 Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to … Sep 22, 2026
CVE-2026-80143 CRITICAL 9.9 Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to … Sep 22, 2026
CVE-2026-79913 MEDIUM 6.5 Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP … Sep 22, 2026
CVE-2026-79312 MEDIUM 6.8 webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, … Sep 22, 2026
CVE-2026-79311 UNKNOWN — webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__(). Sep 22, 2026
CVE-2026-77637 LOW 3.8 Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in routers/router.go inherit ScopeAdminRead but omit the RequiredScopes(types.ScopeAdminWrite) middleware applied … Sep 22, 2026
CVE-2026-77633 HIGH 7.1 Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and … Sep 22, 2026
CVE-2026-77621 UNKNOWN — Vector is a high-performance observability data pipeline. From 0.10.0 until 0.57.0, the file sink renders its templated path from event fields and opens the result … Sep 22, 2026
CVE-2026-77620 UNKNOWN — Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decompressed frame back into its decoder without limiting nested … Sep 22, 2026
CVE-2026-77619 UNKNOWN — Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it … Sep 22, 2026
CVE-2026-75608 HIGH 7.7 Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does not require an administrator … Sep 22, 2026
CVE-2026-75607 HIGH 8.1 Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards attacker-selected message topics to the dispatcher without checking … Sep 22, 2026
CVE-2026-75517 MEDIUM 6.5 Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use cases including remove-integration, update-integration, auto-configure-integration, and set-integration-as-primary look … Sep 22, 2026
CVE-2026-75511 UNKNOWN — Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat webhook URLs from subscriber credentials.webhookUrl, channel endpoint endpoint.url, event … Sep 22, 2026
CVE-2026-75510 UNKNOWN — Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification … Sep 22, 2026
CVE-2026-70410 HIGH 8.8 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica. Plugin instantiation (via AvaticaUtils#instantiatePlugin and other methods) initializes arbitrary … Sep 22, 2026
CVE-2026-63374 UNKNOWN — AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() … Sep 22, 2026
CVE-2026-56681 HIGH 7.3 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust … Sep 22, 2026
CVE-2026-95754 UNKNOWN — In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its … Sep 22, 2026
CVE-2026-95703 UNKNOWN — In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded … Sep 22, 2026
CVE-2026-95701 UNKNOWN — In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization … Sep 22, 2026