Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56172
Total
4442
Critical
16641
High
16421
Medium
CVE ID Severity Score Description Published
CVE-2026-63458 UNKNOWN — Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply … Sep 18, 2026
CVE-2026-63445 UNKNOWN — Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project … Sep 18, 2026
CVE-2026-63199 UNKNOWN — Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the … Sep 18, 2026
CVE-2026-62279 HIGH 7.1 LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles … Sep 18, 2026
CVE-2026-62278 HIGH 8.1 LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenticated non-administrative users could reach HandleTranslationFileUpload and influence the name … Sep 18, 2026
CVE-2026-61552 HIGH 7.2 Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration … Sep 18, 2026
CVE-2026-61551 HIGH 8.6 Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting … Sep 18, 2026
CVE-2026-61550 CRITICAL 9.8 Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the … Sep 18, 2026
CVE-2026-59163 CRITICAL 9.1 Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 … Sep 18, 2026
CVE-2026-33625 HIGH 8.8 LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 … Sep 18, 2026
CVE-2026-32641 HIGH 7.5 Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/http/middleware.rs uses unwrap() while parsing the x-amz-firehose-common-attributes header before … Sep 18, 2026
CVE-2025-66455 CRITICAL 9.8 LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control … Sep 18, 2026
CVE-2026-93765 CRITICAL 9.1 Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated … Sep 18, 2026
CVE-2026-93758 HIGH 8.1 An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference … Sep 18, 2026
CVE-2026-93579 MEDIUM 6.5 A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage … Sep 18, 2026
CVE-2026-93559 HIGH 7.3 A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. … Sep 18, 2026
CVE-2026-93534 MEDIUM 6.3 A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. … Sep 18, 2026
CVE-2026-93533 MEDIUM 6.3 A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. … Sep 18, 2026
CVE-2026-93338 MEDIUM 5.3 Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP … Sep 18, 2026
CVE-2026-91149 HIGH 7.5 A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. … Sep 18, 2026
CVE-2026-91147 MEDIUM 5.9 A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted … Sep 18, 2026
CVE-2026-91142 LOW 3.6 A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, … Sep 18, 2026
CVE-2026-85497 CRITICAL 9.8 CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who … Sep 18, 2026
CVE-2026-85478 LOW 3.5 A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical … Sep 18, 2026
CVE-2026-81505 UNKNOWN — Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls … Sep 18, 2026