Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56890
Total
4508
Critical
16896
High
16708
Medium
CVE ID Severity Score Description Published
CVE-2026-89028 HIGH 7.5 MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by … Sep 16, 2026
CVE-2026-85104 UNKNOWN — In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation parameters. Sep 16, 2026
CVE-2026-81736 HIGH 7.5 If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will … Sep 16, 2026
CVE-2026-81563 HIGH 7.5 A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens … Sep 16, 2026
CVE-2026-78301 MEDIUM 5.8 A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a … Sep 16, 2026
CVE-2026-77692 HIGH 7.5 An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection … Sep 16, 2026
CVE-2026-73177 UNKNOWN — Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. … Sep 16, 2026
CVE-2026-61598 UNKNOWN — djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.mixins.model_binding.ModelBindingMixin` provides a default `update_model` event handler and is … Sep 16, 2026
CVE-2026-61590 HIGH 7.4 djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a … Sep 16, 2026
CVE-2026-56719 MEDIUM 6.5 MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the … Sep 16, 2026
CVE-2026-19941 MEDIUM 5.9 An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same … Sep 16, 2026
CVE-2026-19667 HIGH 7.5 If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache … Sep 16, 2026
CVE-2026-19662 MEDIUM 5.9 An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a … Sep 16, 2026
CVE-2026-92361 MEDIUM 4.3 A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such … Sep 16, 2026
CVE-2026-92360 MEDIUM 6.3 A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application … Sep 16, 2026
CVE-2026-92359 LOW 3.1 A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. … Sep 16, 2026
CVE-2026-88817 UNKNOWN — An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. … Sep 16, 2026
CVE-2026-73176 UNKNOWN — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface … Sep 16, 2026
CVE-2026-73175 UNKNOWN — Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows … Sep 16, 2026
CVE-2026-73174 UNKNOWN — Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that … Sep 16, 2026
CVE-2026-73173 UNKNOWN — Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that … Sep 16, 2026
CVE-2026-73172 UNKNOWN — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service … Sep 16, 2026
CVE-2026-73171 UNKNOWN — Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 … Sep 16, 2026
CVE-2026-73170 UNKNOWN — Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in … Sep 16, 2026
CVE-2026-73169 UNKNOWN — Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech … Sep 16, 2026