Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54256
Total
4300
Critical
16127
High
15827
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102793 | CRITICAL | 9.1 | A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument … | Sep 30, 2026 |
| CVE-2026-15278 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 29, 2026 |
| CVE-2026-103047 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects … | Sep 29, 2026 |
| CVE-2026-103046 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS. This issue affects MediaWiki … | Sep 29, 2026 |
| CVE-2026-103045 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Refreshed skin allows Stored XSS. This issue affects … | Sep 29, 2026 |
| CVE-2026-103044 | UNKNOWN | — | XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: … | Sep 29, 2026 |
| CVE-2026-103043 | HIGH | 7.5 | anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially … | Sep 29, 2026 |
| CVE-2026-103042 | HIGH | 7.5 | LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker … | Sep 29, 2026 |
| CVE-2026-103041 | CRITICAL | 9.8 | LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to … | Sep 29, 2026 |
| CVE-2026-103040 | CRITICAL | 9.8 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC … | Sep 29, 2026 |
| CVE-2026-102792 | CRITICAL | 9.1 | A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results … | Sep 29, 2026 |
| CVE-2026-91191 | HIGH | 7.5 | The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables … | Sep 29, 2026 |
| CVE-2026-84409 | HIGH | 7.5 | The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management … | Sep 29, 2026 |
| CVE-2026-74225 | HIGH | 7.1 | U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local … | Sep 29, 2026 |
| CVE-2026-74222 | HIGH | 8.2 | U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the … | Sep 29, 2026 |
| CVE-2026-74221 | HIGH | 8.2 | U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK … | Sep 29, 2026 |
| CVE-2026-74220 | HIGH | 8.2 | U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. … | Sep 29, 2026 |
| CVE-2026-72510 | CRITICAL | 9.0 | The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection. | Sep 29, 2026 |
| CVE-2026-72507 | CRITICAL | 9.0 | The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability. | Sep 29, 2026 |
| CVE-2026-71974 | MEDIUM | 4.8 | U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply … | Sep 29, 2026 |
| CVE-2026-71973 | MEDIUM | 5.2 | U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with … | Sep 29, 2026 |
| CVE-2026-71972 | MEDIUM | 5.9 | U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory … | Sep 29, 2026 |
| CVE-2026-71971 | HIGH | 8.2 | U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment … | Sep 29, 2026 |
| CVE-2026-71379 | CRITICAL | 10.0 | The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request. | Sep 29, 2026 |
| CVE-2026-71302 | HIGH | 7.1 | The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and … | Sep 29, 2026 |