Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-14984 | UNKNOWN | — | Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic … | Oct 01, 2026 |
| CVE-2026-14983 | UNKNOWN | — | Missing authentication in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to achieve denial of service against Teledyne FLIR … | Oct 01, 2026 |
| CVE-2026-104286 | CRITICAL | 9.8 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 … | Oct 01, 2026 |
| CVE-2026-103484 | HIGH | 8.8 | IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution. | Oct 01, 2026 |
| CVE-2026-102671 | MEDIUM | 5.3 | The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default. | Oct 01, 2026 |
| CVE-2026-102670 | MEDIUM | 4.3 | Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it. | Oct 01, 2026 |
| CVE-2026-102669 | MEDIUM | 5.3 | Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages. | Oct 01, 2026 |
| CVE-2026-102668 | MEDIUM | 5.3 | The Joyland AI app accepts any TLS certificates from any server without validation. | Oct 01, 2026 |
| CVE-2026-102667 | HIGH | 8.3 | Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access … | Oct 01, 2026 |
| CVE-2026-102666 | MEDIUM | 6.5 | The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push … | Oct 01, 2026 |
| CVE-2026-102628 | CRITICAL | 9.3 | The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a … | Oct 01, 2026 |
| CVE-2026-100251 | MEDIUM | 6.5 | Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance … | Oct 01, 2026 |
| CVE-2026-8618 | UNKNOWN | — | A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before … | Oct 01, 2026 |
| CVE-2026-84682 | UNKNOWN | — | A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to … | Oct 01, 2026 |
| CVE-2026-63724 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Oct 01, 2026 |
| CVE-2026-63721 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Oct 01, 2026 |
| CVE-2026-55232 | HIGH | 7.6 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF … | Oct 01, 2026 |
| CVE-2026-55231 | HIGH | 7.2 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed … | Oct 01, 2026 |
| CVE-2026-55230 | HIGH | 8.7 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML … | Oct 01, 2026 |
| CVE-2026-55083 | CRITICAL | 9.1 | DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to … | Oct 01, 2026 |
| CVE-2026-27872 | UNKNOWN | — | - Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52. | Oct 01, 2026 |
| CVE-2026-15911 | HIGH | 7.4 | Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation. | Oct 01, 2026 |
| CVE-2026-104059 | HIGH | 8.1 | Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending … | Oct 01, 2026 |
| CVE-2026-104058 | MEDIUM | 5.3 | Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, … | Oct 01, 2026 |
| CVE-2026-104057 | HIGH | 7.5 | Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages … | Oct 01, 2026 |