Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56890
Total
4508
Critical
16896
High
16708
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-89028 | HIGH | 7.5 | MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by … | Sep 16, 2026 |
| CVE-2026-85104 | UNKNOWN | — | In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation parameters. | Sep 16, 2026 |
| CVE-2026-81736 | HIGH | 7.5 | If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will … | Sep 16, 2026 |
| CVE-2026-81563 | HIGH | 7.5 | A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens … | Sep 16, 2026 |
| CVE-2026-78301 | MEDIUM | 5.8 | A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a … | Sep 16, 2026 |
| CVE-2026-77692 | HIGH | 7.5 | An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection … | Sep 16, 2026 |
| CVE-2026-73177 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. … | Sep 16, 2026 |
| CVE-2026-61598 | UNKNOWN | — | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.mixins.model_binding.ModelBindingMixin` provides a default `update_model` event handler and is … | Sep 16, 2026 |
| CVE-2026-61590 | HIGH | 7.4 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a … | Sep 16, 2026 |
| CVE-2026-56719 | MEDIUM | 6.5 | MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the … | Sep 16, 2026 |
| CVE-2026-19941 | MEDIUM | 5.9 | An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same … | Sep 16, 2026 |
| CVE-2026-19667 | HIGH | 7.5 | If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache … | Sep 16, 2026 |
| CVE-2026-19662 | MEDIUM | 5.9 | An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a … | Sep 16, 2026 |
| CVE-2026-92361 | MEDIUM | 4.3 | A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such … | Sep 16, 2026 |
| CVE-2026-92360 | MEDIUM | 6.3 | A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application … | Sep 16, 2026 |
| CVE-2026-92359 | LOW | 3.1 | A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. … | Sep 16, 2026 |
| CVE-2026-88817 | UNKNOWN | — | An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. … | Sep 16, 2026 |
| CVE-2026-73176 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface … | Sep 16, 2026 |
| CVE-2026-73175 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows … | Sep 16, 2026 |
| CVE-2026-73174 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that … | Sep 16, 2026 |
| CVE-2026-73173 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that … | Sep 16, 2026 |
| CVE-2026-73172 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service … | Sep 16, 2026 |
| CVE-2026-73171 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 … | Sep 16, 2026 |
| CVE-2026-73170 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in … | Sep 16, 2026 |
| CVE-2026-73169 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech … | Sep 16, 2026 |