Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81879 | MEDIUM | 5.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the … | Sep 22, 2026 |
| CVE-2026-81878 | MEDIUM | 5.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal … | Sep 22, 2026 |
| CVE-2026-80156 | CRITICAL | 9.1 | Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management portal … | Sep 22, 2026 |
| CVE-2026-80155 | CRITICAL | 10.0 | Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web management portal … | Sep 22, 2026 |
| CVE-2026-80154 | CRITICAL | 9.6 | All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated … | Sep 22, 2026 |
| CVE-2026-80152 | CRITICAL | 9.1 | Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with … | Sep 22, 2026 |
| CVE-2026-80151 | CRITICAL | 9.1 | Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with … | Sep 22, 2026 |
| CVE-2026-80150 | HIGH | 7.5 | Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener … | Sep 22, 2026 |
| CVE-2026-80149 | HIGH | 8.6 | Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener … | Sep 22, 2026 |
| CVE-2026-80148 | HIGH | 8.6 | Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener … | Sep 22, 2026 |
| CVE-2026-80147 | CRITICAL | 9.9 | Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers … | Sep 22, 2026 |
| CVE-2026-80146 | CRITICAL | 9.9 | Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers … | Sep 22, 2026 |
| CVE-2026-80145 | CRITICAL | 9.1 | Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with … | Sep 22, 2026 |
| CVE-2026-80144 | CRITICAL | 9.9 | Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to … | Sep 22, 2026 |
| CVE-2026-80143 | CRITICAL | 9.9 | Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to … | Sep 22, 2026 |
| CVE-2026-79913 | MEDIUM | 6.5 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP … | Sep 22, 2026 |
| CVE-2026-79312 | MEDIUM | 6.8 | webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, … | Sep 22, 2026 |
| CVE-2026-79311 | UNKNOWN | — | webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__(). | Sep 22, 2026 |
| CVE-2026-77637 | LOW | 3.8 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in routers/router.go inherit ScopeAdminRead but omit the RequiredScopes(types.ScopeAdminWrite) middleware applied … | Sep 22, 2026 |
| CVE-2026-77633 | HIGH | 7.1 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and … | Sep 22, 2026 |
| CVE-2026-77621 | UNKNOWN | — | Vector is a high-performance observability data pipeline. From 0.10.0 until 0.57.0, the file sink renders its templated path from event fields and opens the result … | Sep 22, 2026 |
| CVE-2026-77620 | UNKNOWN | — | Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decompressed frame back into its decoder without limiting nested … | Sep 22, 2026 |
| CVE-2026-77619 | UNKNOWN | — | Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it … | Sep 22, 2026 |
| CVE-2026-75608 | HIGH | 7.7 | Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does not require an administrator … | Sep 22, 2026 |
| CVE-2026-75607 | HIGH | 8.1 | Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards attacker-selected message topics to the dispatcher without checking … | Sep 22, 2026 |