Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54256
Total
4300
Critical
16127
High
15827
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-79536 | UNKNOWN | — | bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via … | Sep 29, 2026 |
| CVE-2026-79535 | UNKNOWN | — | mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a caller-supplied value into … | Sep 29, 2026 |
| CVE-2026-79534 | UNKNOWN | — | mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, … | Sep 29, 2026 |
| CVE-2026-79417 | UNKNOWN | — | Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU … | Sep 29, 2026 |
| CVE-2026-79403 | UNKNOWN | — | An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint | Sep 29, 2026 |
| CVE-2026-79348 | MEDIUM | 4.3 | KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware … | Sep 29, 2026 |
| CVE-2026-76738 | LOW | 2.7 | A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause … | Sep 29, 2026 |
| CVE-2026-76737 | LOW | 3.0 | An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access … | Sep 29, 2026 |
| CVE-2026-76736 | LOW | 3.3 | A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to … | Sep 29, 2026 |
| CVE-2026-76735 | MEDIUM | 4.1 | A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with … | Sep 29, 2026 |
| CVE-2026-76734 | MEDIUM | 4.8 | A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service … | Sep 29, 2026 |
| CVE-2026-76733 | MEDIUM | 4.9 | A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a … | Sep 29, 2026 |
| CVE-2026-76732 | MEDIUM | 6.4 | A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local … | Sep 29, 2026 |
| CVE-2026-76731 | MEDIUM | 6.5 | An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful … | Sep 29, 2026 |
| CVE-2026-76730 | MEDIUM | 6.5 | An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing … | Sep 29, 2026 |
| CVE-2026-76729 | MEDIUM | 6.6 | A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause … | Sep 29, 2026 |
| CVE-2026-76728 | HIGH | 7.2 | A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side … | Sep 29, 2026 |
| CVE-2026-76727 | HIGH | 7.2 | Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform … | Sep 29, 2026 |
| CVE-2026-76726 | HIGH | 8.1 | An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if … | Sep 29, 2026 |
| CVE-2026-76725 | CRITICAL | 9.6 | A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing … | Sep 29, 2026 |
| CVE-2026-76724 | CRITICAL | 9.6 | A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command … | Sep 29, 2026 |
| CVE-2026-76723 | CRITICAL | 9.6 | Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code … | Sep 29, 2026 |
| CVE-2026-76722 | CRITICAL | 9.8 | Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary … | Sep 29, 2026 |
| CVE-2026-76721 | CRITICAL | 9.8 | Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on … | Sep 29, 2026 |
| CVE-2026-67993 | UNKNOWN | — | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback. | Sep 29, 2026 |