Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-101070 | MEDIUM | 5.3 | A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the … | Sep 28, 2026 |
| CVE-2026-86330 | HIGH | 7.2 | An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in … | Sep 28, 2026 |
| CVE-2026-82936 | UNKNOWN | — | mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit … | Sep 28, 2026 |
| CVE-2026-82935 | UNKNOWN | — | mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly … | Sep 28, 2026 |
| CVE-2026-82933 | UNKNOWN | — | mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An … | Sep 28, 2026 |
| CVE-2026-82932 | UNKNOWN | — | mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed … | Sep 28, 2026 |
| CVE-2026-82930 | UNKNOWN | — | mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker … | Sep 28, 2026 |
| CVE-2026-82929 | UNKNOWN | — | mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys … | Sep 28, 2026 |
| CVE-2026-82928 | UNKNOWN | — | mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key … | Sep 28, 2026 |
| CVE-2026-82326 | MEDIUM | 4.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes. This issue … | Sep 28, 2026 |
| CVE-2026-82323 | HIGH | 8.1 | Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows Exploitation of Trusted Identifiers. This issue affects Enocta Platform: through 2026-09-28. | Sep 28, 2026 |
| CVE-2026-59563 | MEDIUM | 4.6 | Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP … | Sep 28, 2026 |
| CVE-2026-52749 | UNKNOWN | — | The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session … | Sep 28, 2026 |
| CVE-2026-52748 | UNKNOWN | — | The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration … | Sep 28, 2026 |
| CVE-2026-18825 | UNKNOWN | — | An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated … | Sep 28, 2026 |
| CVE-2026-12265 | HIGH | 8.8 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations. | Sep 28, 2026 |
| CVE-2026-101292 | HIGH | 8.2 | Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol … | Sep 28, 2026 |
| CVE-2026-101069 | MEDIUM | 6.5 | A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing … | Sep 28, 2026 |
| CVE-2026-101068 | MEDIUM | 6.5 | A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection … | Sep 28, 2026 |
| CVE-2026-101067 | HIGH | 7.3 | A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation … | Sep 28, 2026 |
| CVE-2026-101066 | HIGH | 7.3 | A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link … | Sep 28, 2026 |
| CVE-2026-101055 | MEDIUM | 5.3 | A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET_STATUS of the component TCP Service. … | Sep 28, 2026 |
| CVE-2026-94194 | UNKNOWN | — | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client … | Sep 28, 2026 |
| CVE-2026-92103 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 … | Sep 28, 2026 |
| CVE-2026-91043 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause … | Sep 28, 2026 |