Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56172
Total
4442
Critical
16641
High
16421
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63458 | UNKNOWN | — | Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply … | Sep 18, 2026 |
| CVE-2026-63445 | UNKNOWN | — | Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project … | Sep 18, 2026 |
| CVE-2026-63199 | UNKNOWN | — | Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the … | Sep 18, 2026 |
| CVE-2026-62279 | HIGH | 7.1 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles … | Sep 18, 2026 |
| CVE-2026-62278 | HIGH | 8.1 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenticated non-administrative users could reach HandleTranslationFileUpload and influence the name … | Sep 18, 2026 |
| CVE-2026-61552 | HIGH | 7.2 | Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration … | Sep 18, 2026 |
| CVE-2026-61551 | HIGH | 8.6 | Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting … | Sep 18, 2026 |
| CVE-2026-61550 | CRITICAL | 9.8 | Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the … | Sep 18, 2026 |
| CVE-2026-59163 | CRITICAL | 9.1 | Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 … | Sep 18, 2026 |
| CVE-2026-33625 | HIGH | 8.8 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 … | Sep 18, 2026 |
| CVE-2026-32641 | HIGH | 7.5 | Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/http/middleware.rs uses unwrap() while parsing the x-amz-firehose-common-attributes header before … | Sep 18, 2026 |
| CVE-2025-66455 | CRITICAL | 9.8 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control … | Sep 18, 2026 |
| CVE-2026-93765 | CRITICAL | 9.1 | Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated … | Sep 18, 2026 |
| CVE-2026-93758 | HIGH | 8.1 | An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference … | Sep 18, 2026 |
| CVE-2026-93579 | MEDIUM | 6.5 | A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage … | Sep 18, 2026 |
| CVE-2026-93559 | HIGH | 7.3 | A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. … | Sep 18, 2026 |
| CVE-2026-93534 | MEDIUM | 6.3 | A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. … | Sep 18, 2026 |
| CVE-2026-93533 | MEDIUM | 6.3 | A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. … | Sep 18, 2026 |
| CVE-2026-93338 | MEDIUM | 5.3 | Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP … | Sep 18, 2026 |
| CVE-2026-91149 | HIGH | 7.5 | A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. … | Sep 18, 2026 |
| CVE-2026-91147 | MEDIUM | 5.9 | A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted … | Sep 18, 2026 |
| CVE-2026-91142 | LOW | 3.6 | A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, … | Sep 18, 2026 |
| CVE-2026-85497 | CRITICAL | 9.8 | CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who … | Sep 18, 2026 |
| CVE-2026-85478 | LOW | 3.5 | A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical … | Sep 18, 2026 |
| CVE-2026-81505 | UNKNOWN | — | Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls … | Sep 18, 2026 |