Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-101860 | HIGH | 8.8 | A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component … | Sep 29, 2026 |
| CVE-2026-101859 | MEDIUM | 5.4 | A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the … | Sep 29, 2026 |
| CVE-2026-101858 | MEDIUM | 4.7 | A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. … | Sep 29, 2026 |
| CVE-2026-101354 | CRITICAL | 9.6 | A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation … | Sep 29, 2026 |
| CVE-2026-102374 | MEDIUM | 6.1 | GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers … | Sep 29, 2026 |
| CVE-2026-102373 | MEDIUM | 6.5 | GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs … | Sep 29, 2026 |
| CVE-2026-102372 | MEDIUM | 6.1 | GestSup versions before 3.2.62 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthenticated attackers to store arbitrary JavaScript in ticket … | Sep 29, 2026 |
| CVE-2026-101281 | HIGH | 7.3 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c … | Sep 29, 2026 |
| CVE-2026-101280 | HIGH | 7.3 | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation … | Sep 29, 2026 |
| CVE-2026-101279 | MEDIUM | 6.5 | A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the … | Sep 29, 2026 |
| CVE-2026-101278 | MEDIUM | 4.3 | A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the … | Sep 29, 2026 |
| CVE-2026-18747 | MEDIUM | 6.8 | The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC … | Sep 29, 2026 |
| CVE-2026-18746 | MEDIUM | 5.9 | parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then … | Sep 29, 2026 |
| CVE-2026-18417 | MEDIUM | 6.5 | The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), … | Sep 29, 2026 |
| CVE-2026-102367 | MEDIUM | 5.4 | mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. … | Sep 29, 2026 |
| CVE-2026-102366 | MEDIUM | 4.4 | mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with … | Sep 29, 2026 |
| CVE-2026-102365 | MEDIUM | 6.5 | mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info … | Sep 29, 2026 |
| CVE-2026-102364 | MEDIUM | 5.4 | mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. … | Sep 29, 2026 |
| CVE-2026-102363 | LOW | 3.7 | mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an … | Sep 29, 2026 |
| CVE-2026-102362 | MEDIUM | 5.3 | mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by supplying the … | Sep 29, 2026 |
| CVE-2026-102361 | CRITICAL | 9.1 | mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can … | Sep 29, 2026 |
| CVE-2026-101277 | MEDIUM | 6.5 | A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0. The impacted element is the function dkim_process_set of the file dkim.c … | Sep 29, 2026 |
| CVE-2026-101265 | LOW | 3.1 | A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the component Básico Page. Such manipulation leads to … | Sep 29, 2026 |
| CVE-2026-101264 | CRITICAL | 9.1 | A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes … | Sep 29, 2026 |
| CVE-2026-101263 | CRITICAL | 9.1 | A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac … | Sep 29, 2026 |