Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54256
Total
4300
Critical
16127
High
15827
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-103109 | HIGH | 7.7 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to … | Sep 30, 2026 |
| CVE-2026-103108 | HIGH | 7.5 | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to … | Sep 30, 2026 |
| CVE-2026-103106 | HIGH | 7.8 | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker … | Sep 30, 2026 |
| CVE-2026-103105 | HIGH | 8.8 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local … | Sep 30, 2026 |
| CVE-2026-103104 | HIGH | 7.5 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to … | Sep 30, 2026 |
| CVE-2026-103102 | HIGH | 8.6 | Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting … | Sep 30, 2026 |
| CVE-2026-103101 | HIGH | 8.6 | Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a … | Sep 30, 2026 |
| CVE-2026-103100 | HIGH | 7.5 | Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting … | Sep 30, 2026 |
| CVE-2026-103099 | HIGH | 7.5 | Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting … | Sep 30, 2026 |
| CVE-2026-102909 | HIGH | 7.3 | A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument … | Sep 30, 2026 |
| CVE-2026-102908 | HIGH | 7.3 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of … | Sep 30, 2026 |
| CVE-2026-102906 | MEDIUM | 6.3 | A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove … | Sep 30, 2026 |
| CVE-2026-102874 | HIGH | 7.3 | A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of … | Sep 30, 2026 |
| CVE-2026-81310 | MEDIUM | 6.6 | Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed … | Sep 30, 2026 |
| CVE-2026-78229 | MEDIUM | 6.7 | Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product … | Sep 30, 2026 |
| CVE-2026-103088 | HIGH | 7.5 | Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the … | Sep 30, 2026 |
| CVE-2026-103087 | UNKNOWN | — | Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service … | Sep 30, 2026 |
| CVE-2026-102847 | MEDIUM | 4.3 | A flaw has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. The affected element is the function kirim of the file application/modules/web/controllers/buku_tamu.php of the component … | Sep 30, 2026 |
| CVE-2026-102846 | MEDIUM | 4.7 | A vulnerability was detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Impacted is the function sistem.php::simpan of the file application/modules/admin/controllers/sistem.php of the component Configuration Handler. The … | Sep 30, 2026 |
| CVE-2026-102845 | MEDIUM | 5.3 | A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component … | Sep 30, 2026 |
| CVE-2026-102844 | LOW | 2.7 | A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects the function detail of the file application/modules/admin/controllers/laporan_data_pasien.php. Executing a manipulation of … | Sep 30, 2026 |
| CVE-2026-102843 | MEDIUM | 4.7 | A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. … | Sep 30, 2026 |
| CVE-2026-51936 | UNKNOWN | — | Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It … | Sep 30, 2026 |
| CVE-2026-103057 | MEDIUM | 4.3 | AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary … | Sep 30, 2026 |
| CVE-2026-103056 | CRITICAL | 9.0 | AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped … | Sep 30, 2026 |