Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-22094 | UNKNOWN | — | The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as root using the SSH daemon that is … | Sep 29, 2026 |
| CVE-2026-102570 | MEDIUM | 5.5 | ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function where the language_id parameter is concatenated unescaped into the … | Sep 29, 2026 |
| CVE-2026-102569 | MEDIUM | 5.5 | ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an … | Sep 29, 2026 |
| CVE-2026-102568 | MEDIUM | 5.5 | Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. … | Sep 29, 2026 |
| CVE-2026-102567 | MEDIUM | 6.1 | CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious … | Sep 29, 2026 |
| CVE-2026-102566 | HIGH | 7.8 | CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can … | Sep 29, 2026 |
| CVE-2026-102491 | HIGH | 7.3 | A vulnerability was identified in mahonelau kykms up to 8f130c2d85842d5b44caae78cc46d65e505949f7. The impacted element is the function QueryGenerator.doMultiFieldsOrder of the file QueryGenerator.java of the component SqlInjectionUtil. … | Sep 29, 2026 |
| CVE-2026-102371 | UNKNOWN | — | In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro … | Sep 29, 2026 |
| CVE-2025-33207 | MEDIUM | 6.8 | NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register … | Sep 29, 2026 |
| CVE-2015-20122 | HIGH | 7.5 | Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote … | Sep 29, 2026 |
| CVE-2026-97395 | UNKNOWN | — | Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table … | Sep 29, 2026 |
| CVE-2026-86450 | HIGH | 7.5 | Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained … | Sep 29, 2026 |
| CVE-2026-81569 | MEDIUM | 4.3 | An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can … | Sep 29, 2026 |
| CVE-2026-78214 | MEDIUM | 5.3 | An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against … | Sep 29, 2026 |
| CVE-2026-71899 | UNKNOWN | — | A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to … | Sep 29, 2026 |
| CVE-2026-71898 | MEDIUM | 4.3 | An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that … | Sep 29, 2026 |
| CVE-2026-71897 | MEDIUM | 4.3 | An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for … | Sep 29, 2026 |
| CVE-2026-4034 | UNKNOWN | — | Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console. | Sep 29, 2026 |
| CVE-2026-102521 | HIGH | 8.6 | The decoder in `readFromDataView` in lib0 before 0.2.119 can be tricked into reading more than it should from a buffer. The vulnerability allows reading past … | Sep 29, 2026 |
| CVE-2026-102360 | HIGH | 8.6 | A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer read adjacent … | Sep 29, 2026 |
| CVE-2026-98164 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, … | Sep 29, 2026 |
| CVE-2026-96869 | MEDIUM | 4.3 | Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-82973 | CRITICAL | 9.4 | Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to … | Sep 29, 2026 |
| CVE-2026-82804 | HIGH | 8.8 | The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user … | Sep 29, 2026 |
| CVE-2026-7193 | UNKNOWN | — | A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attacker connected to the same network to … | Sep 29, 2026 |