Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56890
Total
4508
Critical
16896
High
16708
Medium
CVE ID Severity Score Description Published
CVE-2026-73167 UNKNOWN — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface … Sep 16, 2026
CVE-2026-73166 UNKNOWN — Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware … Sep 16, 2026
CVE-2026-73165 UNKNOWN — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface … Sep 16, 2026
CVE-2026-73164 UNKNOWN — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface … Sep 16, 2026
CVE-2026-73163 UNKNOWN — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface … Sep 16, 2026
CVE-2026-19535 UNKNOWN — Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that … Sep 16, 2026
CVE-2026-92465 HIGH 7.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects … Sep 16, 2026
CVE-2026-92463 MEDIUM 6.5 yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list … Sep 16, 2026
CVE-2026-92462 MEDIUM 6.5 yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps. Attackers … Sep 16, 2026
CVE-2026-92461 MEDIUM 4.3 yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers … Sep 16, 2026
CVE-2026-92460 MEDIUM 6.5 yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can … Sep 16, 2026
CVE-2026-92459 MEDIUM 6.5 yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission … Sep 16, 2026
CVE-2026-92458 MEDIUM 4.3 yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can … Sep 16, 2026
CVE-2026-92457 MEDIUM 6.5 yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call … Sep 16, 2026
CVE-2026-92456 HIGH 7.1 yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide … Sep 16, 2026
CVE-2026-92455 MEDIUM 4.3 yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email … Sep 16, 2026
CVE-2026-58147 UNKNOWN — WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements … Sep 16, 2026
CVE-2026-58146 UNKNOWN — WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST … Sep 16, 2026
CVE-2026-40857 UNKNOWN — WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value … Sep 16, 2026
CVE-2026-40856 UNKNOWN — WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It … Sep 16, 2026
CVE-2026-40855 UNKNOWN — WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting … Sep 16, 2026
CVE-2026-40854 UNKNOWN — WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by … Sep 16, 2026
CVE-2026-92357 MEDIUM 4.3 A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of … Sep 16, 2026
CVE-2026-92356 MEDIUM 4.3 A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a … Sep 16, 2026
CVE-2026-90049 CRITICAL 9.3 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() skb_zerocopy() copies frags from @from into … Sep 16, 2026