Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-103109 HIGH 7.7 Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to … Sep 30, 2026
CVE-2026-103108 HIGH 7.5 Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to … Sep 30, 2026
CVE-2026-103106 HIGH 7.8 Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker … Sep 30, 2026
CVE-2026-103105 HIGH 8.8 Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local … Sep 30, 2026
CVE-2026-103104 HIGH 7.5 Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to … Sep 30, 2026
CVE-2026-103102 HIGH 8.6 Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting … Sep 30, 2026
CVE-2026-103101 HIGH 8.6 Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a … Sep 30, 2026
CVE-2026-103100 HIGH 7.5 Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting … Sep 30, 2026
CVE-2026-103099 HIGH 7.5 Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting … Sep 30, 2026
CVE-2026-102909 HIGH 7.3 A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument … Sep 30, 2026
CVE-2026-102908 HIGH 7.3 A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of … Sep 30, 2026
CVE-2026-102906 MEDIUM 6.3 A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove … Sep 30, 2026
CVE-2026-102874 HIGH 7.3 A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of … Sep 30, 2026
CVE-2026-81310 MEDIUM 6.6 Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed … Sep 30, 2026
CVE-2026-78229 MEDIUM 6.7 Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product … Sep 30, 2026
CVE-2026-103088 HIGH 7.5 Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the … Sep 30, 2026
CVE-2026-103087 UNKNOWN — Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service … Sep 30, 2026
CVE-2026-102847 MEDIUM 4.3 A flaw has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. The affected element is the function kirim of the file application/modules/web/controllers/buku_tamu.php of the component … Sep 30, 2026
CVE-2026-102846 MEDIUM 4.7 A vulnerability was detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Impacted is the function sistem.php::simpan of the file application/modules/admin/controllers/sistem.php of the component Configuration Handler. The … Sep 30, 2026
CVE-2026-102845 MEDIUM 5.3 A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component … Sep 30, 2026
CVE-2026-102844 LOW 2.7 A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects the function detail of the file application/modules/admin/controllers/laporan_data_pasien.php. Executing a manipulation of … Sep 30, 2026
CVE-2026-102843 MEDIUM 4.7 A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. … Sep 30, 2026
CVE-2026-51936 UNKNOWN — Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It … Sep 30, 2026
CVE-2026-103057 MEDIUM 4.3 AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary … Sep 30, 2026
CVE-2026-103056 CRITICAL 9.0 AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped … Sep 30, 2026