Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26383
Total
1955
Critical
7969
High
8219
Medium
CVE ID Severity Score Description Published
CVE-2026-8363 CRITICAL 9.8 A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources: May 27, 2026
CVE-2026-8362 CRITICAL 9.8 A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome May 27, 2026
CVE-2026-8361 HIGH 7.5 A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome May 27, 2026
CVE-2026-8360 HIGH 7.5 Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server … May 27, 2026
CVE-2026-8359 HIGH 7.5 When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule … May 27, 2026
CVE-2026-49009 LOW 3.1 Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal. May 27, 2026
CVE-2026-48792 MEDIUM 4.4 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/evdev.c silently ignores EACCES errors when opening /dev/input/event* nodes, causing pusb_has_virtual_input_device() to … May 27, 2026
CVE-2026-48066 MEDIUM 5.7 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/log.c contains a process-wide static pointer that is written on every PAM … May 27, 2026
CVE-2026-48065 MEDIUM 6.7 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/conf.c allocates heap memory proportional to n_devices, a count derived from libxml2 … May 27, 2026
CVE-2026-48064 HIGH 8.1 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is configured with deny_remote=false in pam_usb (commonly done … May 27, 2026
CVE-2026-47274 MEDIUM 6.3 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, multiple pam_usb helper tools resolved external binaries through the PATH environment variable … May 27, 2026
CVE-2026-47273 MEDIUM 6.5 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb builds XPath expressions from user-supplied identifiers (PAM username, service name) and … May 27, 2026
CVE-2026-47272 HIGH 7.1 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare() function in src/pad.c only verified that the user-side pad (~/.pamusb/device.pad) … May 27, 2026
CVE-2026-47271 MEDIUM 5.1 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, src/mem.c implemented out-of-memory guards for xmalloc(), xrealloc(), and xstrdup() using assert(data != … May 27, 2026
CVE-2026-47161 UNKNOWN RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'pickle' data. An attacker … May 27, 2026
CVE-2026-45134 HIGH 7.1 LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull … May 27, 2026
CVE-2026-45108 HIGH 8.4 Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, Himmelblau contained an authentication bypass vulnerability … May 27, 2026
CVE-2026-45104 HIGH 7.5 MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFilter/> … May 27, 2026
CVE-2026-45102 CRITICAL 9.9 OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm module as an isolation primitive. This API was not … May 27, 2026
CVE-2026-44888 CRITICAL 9.8 Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplied numeric config values (e.g., SMTP_PORT) … May 27, 2026
CVE-2026-44887 CRITICAL 9.8 Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be … May 27, 2026
CVE-2026-44886 UNKNOWN Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnerable to SQL … May 27, 2026
CVE-2026-44724 HIGH 7.8 systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when … May 27, 2026
CVE-2026-44681 MEDIUM 6.1 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and … May 27, 2026
CVE-2026-44590 CRITICAL 9.3 Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via … May 27, 2026