Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-71189 LOW 3.5 An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the … Sep 29, 2026
CVE-2026-70356 CRITICAL 9.1 The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web … Sep 29, 2026
CVE-2026-69662 LOW 3.7 The application uses unsafe functions that allow execution of inline scripts and string evaluation functions. Sep 29, 2026
CVE-2026-68954 CRITICAL 9.0 The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability. Sep 29, 2026
CVE-2026-68068 CRITICAL 9.0 The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability. Sep 29, 2026
CVE-2026-63713 CRITICAL 9.0 The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability. Sep 29, 2026
CVE-2026-102771 MEDIUM 4.7 A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the function MailController::templatePut of the file cmf-api/src/admin/controller/MailController.php of … Sep 29, 2026
CVE-2026-102621 LOW 3.3 A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. … Sep 29, 2026
CVE-2026-96587 CRITICAL 10.0 The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the … Sep 29, 2026
CVE-2026-94952 UNKNOWN — A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding … Sep 29, 2026
CVE-2026-94204 HIGH 7.5 The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket … Sep 29, 2026
CVE-2026-93853 UNKNOWN — Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When … Sep 29, 2026
CVE-2026-81842 MEDIUM 4.3 An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the … Sep 29, 2026
CVE-2026-81841 MEDIUM 5.3 Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a … Sep 29, 2026
CVE-2026-102938 UNKNOWN — virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() … Sep 29, 2026
CVE-2026-102937 UNKNOWN — virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe … Sep 29, 2026
CVE-2026-102930 UNKNOWN — virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or … Sep 29, 2026
CVE-2026-102925 HIGH 7.8 virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already … Sep 29, 2026
CVE-2026-102904 MEDIUM 5.4 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI … Sep 29, 2026
CVE-2026-102620 LOW 3.3 A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can … Sep 29, 2026
CVE-2026-102253 HIGH 7.5 iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an … Sep 29, 2026
CVE-2026-96274 HIGH 7.4 In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. … Sep 29, 2026
CVE-2026-94953 UNKNOWN — A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using … Sep 29, 2026
CVE-2026-79538 CRITICAL 9.8 metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts). Sep 29, 2026
CVE-2026-79537 UNKNOWN — metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed … Sep 29, 2026