Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54274
Total
4303
Critical
16132
High
15830
Medium
CVE ID Severity Score Description Published
CVE-2026-102719 UNKNOWN — Predictable DTLS HelloVerifyRequest Cookie in NetX Secure Sep 29, 2026
CVE-2026-102718 UNKNOWN — hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses … Sep 29, 2026
CVE-2026-102716 UNKNOWN — An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests that carry a Session header the parser cannot convert. … Sep 29, 2026
CVE-2026-102715 UNKNOWN — Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table … Sep 29, 2026
CVE-2026-102714 UNKNOWN — `_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with … Sep 29, 2026
CVE-2026-102713 UNKNOWN — The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper … Sep 29, 2026
CVE-2026-102712 UNKNOWN — On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the … Sep 29, 2026
CVE-2026-102711 UNKNOWN — Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY … Sep 29, 2026
CVE-2026-102710 UNKNOWN — Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`. A user-mode, memory-protected module can register … Sep 29, 2026
CVE-2026-102709 UNKNOWN — Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers … Sep 29, 2026
CVE-2026-102677 HIGH 7.8 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code … Sep 29, 2026
CVE-2026-102639 MEDIUM 6.5 MobilityDB version 1.3.0 and earlier contains an out-of-bounds read vulnerability in the MEOS binary and library WKB deserialization logic that allows unprivileged database users to … Sep 29, 2026
CVE-2026-102560 HIGH 8.6 A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could … Sep 29, 2026
CVE-2026-102559 HIGH 8.6 A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation … Sep 29, 2026
CVE-2026-102558 HIGH 8.6 A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the … Sep 29, 2026
CVE-2026-102555 HIGH 8.2 A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained … Sep 29, 2026
CVE-2026-102242 UNKNOWN — Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated … Sep 29, 2026
CVE-2026-92232 UNKNOWN — Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The … Sep 29, 2026
CVE-2026-92231 UNKNOWN — Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method … Sep 29, 2026
CVE-2026-92227 UNKNOWN — Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie … Sep 29, 2026
CVE-2026-92226 UNKNOWN — Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows … Sep 29, 2026
CVE-2026-92225 UNKNOWN — Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user … Sep 29, 2026
CVE-2026-92224 UNKNOWN — Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape … Sep 29, 2026
CVE-2026-92223 UNKNOWN — Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized … Sep 29, 2026
CVE-2026-92222 UNKNOWN — Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly … Sep 29, 2026