Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54227
Total
4299
Critical
16114
High
15798
Medium
CVE ID Severity Score Description Published
CVE-2026-105051 LOW 1.9 Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel). Oct 02, 2026
CVE-2026-105050 UNKNOWN — PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in … Oct 02, 2026
CVE-2026-105049 MEDIUM 5.8 Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public … Oct 02, 2026
CVE-2026-105048 MEDIUM 4.0 The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses). Oct 02, 2026
CVE-2026-97363 HIGH 7.5 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service … Oct 02, 2026
CVE-2026-97212 HIGH 7.3 The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results … Oct 02, 2026
CVE-2026-95102 CRITICAL 9.4 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to … Oct 02, 2026
CVE-2026-94594 MEDIUM 4.0 Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this … Oct 02, 2026
CVE-2026-94593 HIGH 7.8 Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the … Oct 02, 2026
CVE-2026-94592 HIGH 8.4 Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per … Oct 02, 2026
CVE-2026-94591 HIGH 8.4 Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and … Oct 02, 2026
CVE-2026-93474 MEDIUM 6.5 Charging station authentication identifiers are publicly accessible via web-based mapping platforms. Oct 02, 2026
CVE-2026-105046 MEDIUM 4.3 Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints. Oct 02, 2026
CVE-2026-105043 LOW 3.6 MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code … Oct 02, 2026
CVE-2026-104887 UNKNOWN — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78409. Reason: This candidate is a duplicate of CVE-2026-78409. Notes: All CVE users … Oct 02, 2026
CVE-2026-104886 UNKNOWN — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78410. Reason: This candidate is a duplicate of CVE-2026-78410. Notes: All CVE users … Oct 02, 2026
CVE-2026-82045 MEDIUM 6.5 UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query … Oct 02, 2026
CVE-2026-82044 HIGH 7.7 UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated … Oct 02, 2026
CVE-2026-82043 MEDIUM 5.3 UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST … Oct 02, 2026
CVE-2026-82042 CRITICAL 9.8 UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching … Oct 02, 2026
CVE-2026-82041 CRITICAL 9.9 UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist … Oct 02, 2026
CVE-2026-75937 UNKNOWN — A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on … Oct 02, 2026
CVE-2026-104874 MEDIUM 5.3 Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl … Oct 02, 2026
CVE-2026-104055 UNKNOWN — The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the … Oct 02, 2026
CVE-2026-82040 MEDIUM 5.0 UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl() that allows authenticated attackers to make the server send requests to arbitrary internal or … Oct 02, 2026