Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56172
Total
4442
Critical
16641
High
16421
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44639 | LOW | 3.7 | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c uses property_append() to walk the entire linked list for each … | Sep 18, 2026 |
| CVE-2026-93737 | MEDIUM | 6.5 | Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticated users to read any project's schedule configuration. Attackers can supply arbitrary … | Sep 18, 2026 |
| CVE-2026-93736 | MEDIUM | 4.3 | Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites … | Sep 18, 2026 |
| CVE-2026-93690 | HIGH | 7.5 | uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or … | Sep 18, 2026 |
| CVE-2026-93689 | MEDIUM | 5.5 | WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context … | Sep 18, 2026 |
| CVE-2026-93688 | HIGH | 7.5 | SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can … | Sep 18, 2026 |
| CVE-2026-93687 | HIGH | 7.5 | braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under … | Sep 18, 2026 |
| CVE-2026-93532 | MEDIUM | 6.3 | A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function application/modules/global/controllers/password.php::simpan/application/modules/global/controllers/profil.php::simpan of the file application/modules/global/controllers/password.php of the component … | Sep 18, 2026 |
| CVE-2026-93531 | MEDIUM | 4.3 | A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This manipulation causes cross-site request forgery. The attack may … | Sep 18, 2026 |
| CVE-2026-88259 | HIGH | 7.5 | CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected … | Sep 18, 2026 |
| CVE-2026-86689 | MEDIUM | 5.9 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers … | Sep 18, 2026 |
| CVE-2026-86520 | HIGH | 7.5 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers … | Sep 18, 2026 |
| CVE-2026-84451 | MEDIUM | 6.5 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an … | Sep 18, 2026 |
| CVE-2026-84450 | MEDIUM | 4.3 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an … | Sep 18, 2026 |
| CVE-2026-84449 | LOW | 3.7 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow … | Sep 18, 2026 |
| CVE-2026-84448 | MEDIUM | 4.0 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that … | Sep 18, 2026 |
| CVE-2026-84447 | HIGH | 7.5 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode … | Sep 18, 2026 |
| CVE-2026-84446 | HIGH | 7.5 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute … | Sep 18, 2026 |
| CVE-2026-84444 | HIGH | 7.4 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose … | Sep 18, 2026 |
| CVE-2026-84400 | LOW | 3.1 | CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network … | Sep 18, 2026 |
| CVE-2026-84398 | HIGH | 7.5 | CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected … | Sep 18, 2026 |
| CVE-2026-84384 | HIGH | 7.5 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data … | Sep 18, 2026 |
| CVE-2026-84383 | CRITICAL | 9.8 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested … | Sep 18, 2026 |
| CVE-2026-81946 | MEDIUM | 4.4 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An … | Sep 18, 2026 |
| CVE-2026-81945 | MEDIUM | 6.6 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bfore 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds … | Sep 18, 2026 |