Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54274
Total
4303
Critical
16132
High
15830
Medium
CVE ID Severity Score Description Published
CVE-2026-22094 UNKNOWN — The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as root using the SSH daemon that is … Sep 29, 2026
CVE-2026-102570 MEDIUM 5.5 ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function where the language_id parameter is concatenated unescaped into the … Sep 29, 2026
CVE-2026-102569 MEDIUM 5.5 ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an … Sep 29, 2026
CVE-2026-102568 MEDIUM 5.5 Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. … Sep 29, 2026
CVE-2026-102567 MEDIUM 6.1 CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious … Sep 29, 2026
CVE-2026-102566 HIGH 7.8 CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can … Sep 29, 2026
CVE-2026-102491 HIGH 7.3 A vulnerability was identified in mahonelau kykms up to 8f130c2d85842d5b44caae78cc46d65e505949f7. The impacted element is the function QueryGenerator.doMultiFieldsOrder of the file QueryGenerator.java of the component SqlInjectionUtil. … Sep 29, 2026
CVE-2026-102371 UNKNOWN — In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro … Sep 29, 2026
CVE-2025-33207 MEDIUM 6.8 NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register … Sep 29, 2026
CVE-2015-20122 HIGH 7.5 Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote … Sep 29, 2026
CVE-2026-97395 UNKNOWN — Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table … Sep 29, 2026
CVE-2026-86450 HIGH 7.5 Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained … Sep 29, 2026
CVE-2026-81569 MEDIUM 4.3 An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can … Sep 29, 2026
CVE-2026-78214 MEDIUM 5.3 An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against … Sep 29, 2026
CVE-2026-71899 UNKNOWN — A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to … Sep 29, 2026
CVE-2026-71898 MEDIUM 4.3 An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that … Sep 29, 2026
CVE-2026-71897 MEDIUM 4.3 An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for … Sep 29, 2026
CVE-2026-4034 UNKNOWN — Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console. Sep 29, 2026
CVE-2026-102521 HIGH 8.6 The decoder in `readFromDataView` in lib0 before 0.2.119 can be tricked into reading more than it should from a buffer. The vulnerability allows reading past … Sep 29, 2026
CVE-2026-102360 HIGH 8.6 A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer read adjacent … Sep 29, 2026
CVE-2026-98164 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, … Sep 29, 2026
CVE-2026-96869 MEDIUM 4.3 Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. Sep 29, 2026
CVE-2026-82973 CRITICAL 9.4 Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to … Sep 29, 2026
CVE-2026-82804 HIGH 8.8 The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user … Sep 29, 2026
CVE-2026-7193 UNKNOWN — A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attacker connected to the same network to … Sep 29, 2026