Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102719 | UNKNOWN | — | Predictable DTLS HelloVerifyRequest Cookie in NetX Secure | Sep 29, 2026 |
| CVE-2026-102718 | UNKNOWN | — | hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses … | Sep 29, 2026 |
| CVE-2026-102716 | UNKNOWN | — | An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests that carry a Session header the parser cannot convert. … | Sep 29, 2026 |
| CVE-2026-102715 | UNKNOWN | — | Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table … | Sep 29, 2026 |
| CVE-2026-102714 | UNKNOWN | — | `_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with … | Sep 29, 2026 |
| CVE-2026-102713 | UNKNOWN | — | The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper … | Sep 29, 2026 |
| CVE-2026-102712 | UNKNOWN | — | On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the … | Sep 29, 2026 |
| CVE-2026-102711 | UNKNOWN | — | Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY … | Sep 29, 2026 |
| CVE-2026-102710 | UNKNOWN | — | Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register … | Sep 29, 2026 |
| CVE-2026-102709 | UNKNOWN | — | Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers … | Sep 29, 2026 |
| CVE-2026-102677 | HIGH | 7.8 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code … | Sep 29, 2026 |
| CVE-2026-102639 | MEDIUM | 6.5 | MobilityDB version 1.3.0 and earlier contains an out-of-bounds read vulnerability in the MEOS binary and library WKB deserialization logic that allows unprivileged database users to … | Sep 29, 2026 |
| CVE-2026-102560 | HIGH | 8.6 | A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could … | Sep 29, 2026 |
| CVE-2026-102559 | HIGH | 8.6 | A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation … | Sep 29, 2026 |
| CVE-2026-102558 | HIGH | 8.6 | A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the … | Sep 29, 2026 |
| CVE-2026-102555 | HIGH | 8.2 | A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained … | Sep 29, 2026 |
| CVE-2026-102242 | UNKNOWN | — | Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated … | Sep 29, 2026 |
| CVE-2026-92232 | UNKNOWN | — | Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The … | Sep 29, 2026 |
| CVE-2026-92231 | UNKNOWN | — | Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method … | Sep 29, 2026 |
| CVE-2026-92227 | UNKNOWN | — | Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie … | Sep 29, 2026 |
| CVE-2026-92226 | UNKNOWN | — | Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows … | Sep 29, 2026 |
| CVE-2026-92225 | UNKNOWN | — | Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user … | Sep 29, 2026 |
| CVE-2026-92224 | UNKNOWN | — | Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape … | Sep 29, 2026 |
| CVE-2026-92223 | UNKNOWN | — | Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized … | Sep 29, 2026 |
| CVE-2026-92222 | UNKNOWN | — | Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly … | Sep 29, 2026 |