Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-104056 | UNKNOWN | — | Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response … | Oct 01, 2026 |
| CVE-2026-9032 | UNKNOWN | — | Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface is reachable without authentication after … | Oct 01, 2026 |
| CVE-2026-97662 | HIGH | 8.2 | An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate … | Oct 01, 2026 |
| CVE-2026-78578 | UNKNOWN | — | Tapo C120 v1 and C200 v5 do not enforce authentication for do method HTTPS onboarding connect actions after initial setup. An unauthenticated adjacent attacker can … | Oct 01, 2026 |
| CVE-2026-78577 | UNKNOWN | — | Tapo C120 v1 and C200 V5 contain a vulnerability in the HTTPS onboarding scan function due to missing authentication. After initial setup, an unauthenticated attacker … | Oct 01, 2026 |
| CVE-2026-73976 | UNKNOWN | — | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through … | Oct 01, 2026 |
| CVE-2026-68496 | HIGH | 7.5 | The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. … | Oct 01, 2026 |
| CVE-2026-68495 | HIGH | 7.5 | The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. … | Oct 01, 2026 |
| CVE-2026-56098 | MEDIUM | 4.3 | A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While … | Oct 01, 2026 |
| CVE-2026-56097 | MEDIUM | 6.5 | A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input … | Oct 01, 2026 |
| CVE-2026-12545 | MEDIUM | 6.7 | A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due … | Oct 01, 2026 |
| CVE-2026-12542 | MEDIUM | 5.3 | A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The … | Oct 01, 2026 |
| CVE-2026-104018 | HIGH | 8.8 | An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain … | Oct 01, 2026 |
| CVE-2026-103923 | UNKNOWN | — | KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for … | Oct 01, 2026 |
| CVE-2026-103922 | CRITICAL | 9.3 | Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard … | Oct 01, 2026 |
| CVE-2026-103884 | MEDIUM | 6.5 | A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate … | Oct 01, 2026 |
| CVE-2026-102369 | UNKNOWN | — | Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker … | Oct 01, 2026 |
| CVE-2026-102294 | UNKNOWN | — | TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system … | Oct 01, 2026 |
| CVE-2023-54404 | HIGH | 7.5 | Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application … | Oct 01, 2026 |
| CVE-2026-96659 | CRITICAL | 9.1 | A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to … | Oct 01, 2026 |
| CVE-2026-96658 | CRITICAL | 9.9 | A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the … | Oct 01, 2026 |
| CVE-2026-93546 | HIGH | 8.8 | Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt … | Oct 01, 2026 |
| CVE-2026-79768 | MEDIUM | 5.3 | Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) … | Oct 01, 2026 |
| CVE-2026-77387 | MEDIUM | 4.0 | geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an … | Oct 01, 2026 |
| CVE-2026-73975 | UNKNOWN | — | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) … | Oct 01, 2026 |