Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-103533 | MEDIUM | 4.1 | A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. … | Oct 01, 2026 |
| CVE-2026-101887 | LOW | 3.5 | BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows a Bluetooth-adjacent attacker to crash the daemon by sending a … | Oct 01, 2026 |
| CVE-2026-93495 | UNKNOWN | — | Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device. | Oct 01, 2026 |
| CVE-2026-14157 | UNKNOWN | — | Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file … | Oct 01, 2026 |
| CVE-2026-13313 | UNKNOWN | — | An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass security mechanisms and … | Oct 01, 2026 |
| CVE-2026-103532 | MEDIUM | 5.3 | A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link … | Oct 01, 2026 |
| CVE-2026-103531 | MEDIUM | 5.5 | A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of … | Oct 01, 2026 |
| CVE-2026-103530 | HIGH | 7.3 | A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search … | Oct 01, 2026 |
| CVE-2026-103592 | MEDIUM | 6.5 | simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. … | Sep 30, 2026 |
| CVE-2026-103591 | HIGH | 7.5 | DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL … | Sep 30, 2026 |
| CVE-2026-103590 | MEDIUM | 5.4 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to … | Sep 30, 2026 |
| CVE-2026-103589 | MEDIUM | 5.4 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values … | Sep 30, 2026 |
| CVE-2026-103588 | MEDIUM | 5.4 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious … | Sep 30, 2026 |
| CVE-2026-103587 | MEDIUM | 5.4 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied … | Sep 30, 2026 |
| CVE-2026-103585 | UNKNOWN | — | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This … | Sep 30, 2026 |
| CVE-2026-103584 | UNKNOWN | — | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This … | Sep 30, 2026 |
| CVE-2026-47096 | MEDIUM | 6.1 | AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting … | Sep 30, 2026 |
| CVE-2026-103001 | MEDIUM | 6.5 | PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when … | Sep 30, 2026 |
| CVE-2026-101283 | UNKNOWN | — | iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), … | Sep 30, 2026 |
| CVE-2026-92173 | UNKNOWN | — | Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening … | Sep 30, 2026 |
| CVE-2026-92172 | UNKNOWN | — | Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering … | Sep 30, 2026 |
| CVE-2026-51872 | UNKNOWN | — | Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py. | Sep 30, 2026 |
| CVE-2026-51871 | UNKNOWN | — | Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the … | Sep 30, 2026 |
| CVE-2026-51870 | UNKNOWN | — | DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute. | Sep 30, 2026 |
| CVE-2026-51869 | UNKNOWN | — | DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host. | Sep 30, 2026 |