Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54256
Total
4300
Critical
16127
High
15827
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-71189 | LOW | 3.5 | An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the … | Sep 29, 2026 |
| CVE-2026-70356 | CRITICAL | 9.1 | The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web … | Sep 29, 2026 |
| CVE-2026-69662 | LOW | 3.7 | The application uses unsafe functions that allow execution of inline scripts and string evaluation functions. | Sep 29, 2026 |
| CVE-2026-68954 | CRITICAL | 9.0 | The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability. | Sep 29, 2026 |
| CVE-2026-68068 | CRITICAL | 9.0 | The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability. | Sep 29, 2026 |
| CVE-2026-63713 | CRITICAL | 9.0 | The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability. | Sep 29, 2026 |
| CVE-2026-102771 | MEDIUM | 4.7 | A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the function MailController::templatePut of the file cmf-api/src/admin/controller/MailController.php of … | Sep 29, 2026 |
| CVE-2026-102621 | LOW | 3.3 | A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. … | Sep 29, 2026 |
| CVE-2026-96587 | CRITICAL | 10.0 | The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the … | Sep 29, 2026 |
| CVE-2026-94952 | UNKNOWN | — | A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding … | Sep 29, 2026 |
| CVE-2026-94204 | HIGH | 7.5 | The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket … | Sep 29, 2026 |
| CVE-2026-93853 | UNKNOWN | — | Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When … | Sep 29, 2026 |
| CVE-2026-81842 | MEDIUM | 4.3 | An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the … | Sep 29, 2026 |
| CVE-2026-81841 | MEDIUM | 5.3 | Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a … | Sep 29, 2026 |
| CVE-2026-102938 | UNKNOWN | — | virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() … | Sep 29, 2026 |
| CVE-2026-102937 | UNKNOWN | — | virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe … | Sep 29, 2026 |
| CVE-2026-102930 | UNKNOWN | — | virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or … | Sep 29, 2026 |
| CVE-2026-102925 | HIGH | 7.8 | virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already … | Sep 29, 2026 |
| CVE-2026-102904 | MEDIUM | 5.4 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI … | Sep 29, 2026 |
| CVE-2026-102620 | LOW | 3.3 | A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can … | Sep 29, 2026 |
| CVE-2026-102253 | HIGH | 7.5 | iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an … | Sep 29, 2026 |
| CVE-2026-96274 | HIGH | 7.4 | In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. … | Sep 29, 2026 |
| CVE-2026-94953 | UNKNOWN | — | A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using … | Sep 29, 2026 |
| CVE-2026-79538 | CRITICAL | 9.8 | metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts). | Sep 29, 2026 |
| CVE-2026-79537 | UNKNOWN | — | metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed … | Sep 29, 2026 |