Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102335 | HIGH | 7.1 | Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers … | Sep 28, 2026 |
| CVE-2026-102334 | HIGH | 7.4 | Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login … | Sep 28, 2026 |
| CVE-2026-102333 | MEDIUM | 6.1 | httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded … | Sep 28, 2026 |
| CVE-2026-102332 | MEDIUM | 6.1 | Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label … | Sep 28, 2026 |
| CVE-2026-101262 | CRITICAL | 9.1 | A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip … | Sep 28, 2026 |
| CVE-2026-101261 | CRITICAL | 9.1 | A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument … | Sep 28, 2026 |
| CVE-2026-101260 | CRITICAL | 9.1 | A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of … | Sep 28, 2026 |
| CVE-2026-102297 | MEDIUM | 4.3 | ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API … | Sep 28, 2026 |
| CVE-2026-102296 | MEDIUM | 6.5 | ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized … | Sep 28, 2026 |
| CVE-2026-102281 | HIGH | 7.5 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its … | Sep 28, 2026 |
| CVE-2026-101205 | MEDIUM | 6.3 | A vulnerability was determined in FastStone Image Viewer up to 8.3. This impacts an unknown function of the component PCX Decoder. This manipulation causes out-of-bounds … | Sep 28, 2026 |
| CVE-2026-101204 | MEDIUM | 6.3 | A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe of the component TGA Image … | Sep 28, 2026 |
| CVE-2026-101203 | MEDIUM | 6.3 | A vulnerability has been found in FastStone Image Viewer up to 8.3. The impacted element is an unknown function of the component 1bpp RLE Decoder. … | Sep 28, 2026 |
| CVE-2026-101202 | MEDIUM | 6.3 | A flaw has been found in FastStone Image Viewer up to 8.3. The affected element is an unknown function of the component TGA Image Handler. … | Sep 28, 2026 |
| CVE-2026-101188 | HIGH | 8.3 | A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak … | Sep 28, 2026 |
| CVE-2026-101093 | MEDIUM | 5.4 | Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious … | Sep 28, 2026 |
| CVE-2026-101092 | MEDIUM | 5.3 | SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can … | Sep 28, 2026 |
| CVE-2026-101091 | HIGH | 7.1 | SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with … | Sep 28, 2026 |
| CVE-2024-58386 | MEDIUM | 6.5 | ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authenticated users to read arbitrary files. The path parameter … | Sep 28, 2026 |
| CVE-2024-42002 | HIGH | 8.4 | A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal … | Sep 28, 2026 |
| CVE-2026-97027 | LOW | 3.6 | Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. … | Sep 28, 2026 |
| CVE-2026-97026 | LOW | 3.9 | Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could … | Sep 28, 2026 |
| CVE-2026-97025 | LOW | 3.2 | Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to … | Sep 28, 2026 |
| CVE-2026-91096 | UNKNOWN | — | In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before … | Sep 28, 2026 |
| CVE-2026-91095 | UNKNOWN | — | In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed … | Sep 28, 2026 |