Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-87752 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting … | Sep 28, 2026 |
| CVE-2026-78424 | HIGH | 8.8 | Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC … | Sep 28, 2026 |
| CVE-2026-19444 | MEDIUM | 6.5 | A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar … | Sep 28, 2026 |
| CVE-2026-12264 | HIGH | 8.8 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution. | Sep 28, 2026 |
| CVE-2026-101054 | MEDIUM | 5.3 | A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file /tmp/wpa_supplicant.conf of the component TCP Service. The … | Sep 28, 2026 |
| CVE-2026-101053 | HIGH | 7.3 | A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa_supplicant.conf of the component TCP Service. Executing … | Sep 28, 2026 |
| CVE-2026-101052 | HIGH | 7.3 | A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component … | Sep 28, 2026 |
| CVE-2026-91006 | UNKNOWN | — | Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) … | Sep 28, 2026 |
| CVE-2026-81867 | UNKNOWN | — | A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an … | Sep 28, 2026 |
| CVE-2026-81375 | UNKNOWN | — | A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker … | Sep 28, 2026 |
| CVE-2026-19759 | UNKNOWN | — | An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google … | Sep 28, 2026 |
| CVE-2026-12269 | HIGH | 8.8 | Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated … | Sep 28, 2026 |
| CVE-2026-12268 | HIGH | 8.8 | ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution. | Sep 28, 2026 |
| CVE-2026-12267 | HIGH | 7.2 | ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution. | Sep 28, 2026 |
| CVE-2026-101040 | MEDIUM | 6.5 | A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown … | Sep 28, 2026 |
| CVE-2026-101039 | CRITICAL | 10.0 | A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to … | Sep 28, 2026 |
| CVE-2026-101038 | CRITICAL | 9.9 | A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based … | Sep 28, 2026 |
| CVE-2026-90979 | UNKNOWN | — | LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the placeholders %u, %dn, and %fqdn (drawn from the … | Sep 28, 2026 |
| CVE-2026-7172 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: parameter 'Nombre Completo' in the endpoint '/administrator/index.php?option=com_virtuemart&page=admin.user_list'. Successful exploitation of this … | Sep 28, 2026 |
| CVE-2026-7171 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: parameter 'Apellido 1' in the endpoint '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'. Successful exploitation of this … | Sep 28, 2026 |
| CVE-2026-7170 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: parameter 'vendor_store_name' in the endpoint '/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID]'. Successful exploitation of this vulnerability … | Sep 28, 2026 |
| CVE-2026-101037 | CRITICAL | 9.9 | A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the component devdiscover Service. The manipulation results in stack-based buffer overflow. … | Sep 28, 2026 |
| CVE-2026-101036 | MEDIUM | 5.3 | A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This impacts the function path.join of the file /src/main/core/createParsedTrack.ts. The manipulation leads to path traversal. The … | Sep 28, 2026 |
| CVE-2026-101035 | MEDIUM | 5.3 | A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library src/lib/nas/encode.cpp of the component nr-gnb. Executing … | Sep 28, 2026 |
| CVE-2026-101018 | MEDIUM | 4.7 | A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the file dayrui/App/Member/Controllers/Admin/Home.php of the component Group Editing. … | Sep 28, 2026 |