Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54298
Total
4306
Critical
16144
High
15836
Medium
CVE ID Severity Score Description Published
CVE-2026-101891 UNKNOWN — An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to … Sep 28, 2026
CVE-2026-101098 MEDIUM 4.3 A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of … Sep 28, 2026
CVE-2026-101083 MEDIUM 5.3 A security vulnerability has been detected in PMWeb v7.x/v8.x/v2025.x. Impacted is an unknown function in the library encryptionhelper.dll. Such manipulation leads to information disclosure. The … Sep 28, 2026
CVE-2026-101082 MEDIUM 5.3 A weakness has been identified in PMWeb 7.x/8.x/2025.x. This issue affects some unknown processing of the file downloader.aspx. This manipulation of the argument FullFileName/FileName causes … Sep 28, 2026
CVE-2026-101081 CRITICAL 9.1 A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration … Sep 28, 2026
CVE-2026-97399 LOW 3.7 The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, … Sep 28, 2026
CVE-2026-93348 HIGH 8.1 Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the … Sep 28, 2026
CVE-2026-91154 UNKNOWN — Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, … Sep 28, 2026
CVE-2026-88808 HIGH 8.8 A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the … Sep 28, 2026
CVE-2026-88805 HIGH 8.1 Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE … Sep 28, 2026
CVE-2026-88804 CRITICAL 9.6 An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in … Sep 28, 2026
CVE-2026-12342 CRITICAL 9.6 This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of … Sep 28, 2026
CVE-2026-101861 MEDIUM 4.1 Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing … Sep 28, 2026
CVE-2026-101080 MEDIUM 4.8 A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The … Sep 28, 2026
CVE-2026-101079 LOW 2.8 A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function isSecurityDefenseSkill of the file dist/scanner/analyzers/context.js. Performing a manipulation … Sep 28, 2026
CVE-2026-101078 MEDIUM 6.3 A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. … Sep 28, 2026
CVE-2026-101077 CRITICAL 10.0 A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The … Sep 28, 2026
CVE-2026-101076 CRITICAL 10.0 A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of … Sep 28, 2026
CVE-2026-96538 UNKNOWN — WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These … Sep 28, 2026
CVE-2026-93540 MEDIUM 6.5 A privilege mismatch was found in Fleet. When a bundle requested namespace labels or annotations through the namespaceLabels and namespaceAnnotations options, the resulting namespace metadata … Sep 28, 2026
CVE-2026-93539 MEDIUM 5.4 A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted … Sep 28, 2026
CVE-2026-93538 HIGH 7.1 A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the … Sep 28, 2026
CVE-2026-80359 MEDIUM 6.8 Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU … Sep 28, 2026
CVE-2026-80358 MEDIUM 5.1 Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU … Sep 28, 2026
CVE-2026-80357 HIGH 7.0 Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU … Sep 28, 2026