Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41870
Total
3419
Critical
12379
High
12272
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-67277 | UNKNOWN | — | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 … | Sep 05, 2026 |
| CVE-2026-67276 | UNKNOWN | — | RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and … | Sep 05, 2026 |
| CVE-2026-86207 | UNKNOWN | — | An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs | Sep 05, 2026 |
| CVE-2026-6554 | MEDIUM | 5.5 | libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does … | Sep 05, 2026 |
| CVE-2026-6244 | MEDIUM | 5.5 | libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use … | Sep 05, 2026 |
| CVE-2026-31912 | MEDIUM | 5.5 | libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction … | Sep 05, 2026 |
| CVE-2026-31911 | MEDIUM | 5.5 | libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program … | Sep 05, 2026 |
| CVE-2026-18313 | MEDIUM | 4.3 | rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it … | Sep 05, 2026 |
| CVE-2026-18238 | MEDIUM | 5.0 | The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message … | Sep 05, 2026 |
| CVE-2026-0799 | HIGH | 8.7 | In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, … | Sep 05, 2026 |
| CVE-2026-82752 | UNKNOWN | — | Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose … | Sep 05, 2026 |
| CVE-2026-86197 | UNKNOWN | — | Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. … | Sep 05, 2026 |
| CVE-2026-86196 | UNKNOWN | — | Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset … | Sep 05, 2026 |
| CVE-2026-86195 | UNKNOWN | — | grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip … | Sep 05, 2026 |
| CVE-2026-86194 | UNKNOWN | — | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined … | Sep 05, 2026 |
| CVE-2026-86193 | UNKNOWN | — | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write … | Sep 05, 2026 |
| CVE-2026-86192 | MEDIUM | 6.5 | SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows … | Sep 05, 2026 |
| CVE-2026-86191 | MEDIUM | 4.3 | SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without … | Sep 05, 2026 |
| CVE-2026-86190 | CRITICAL | 9.1 | WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers … | Sep 05, 2026 |
| CVE-2026-86189 | CRITICAL | 9.8 | WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in … | Sep 05, 2026 |
| CVE-2026-86188 | HIGH | 7.2 | AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback … | Sep 05, 2026 |
| CVE-2026-86187 | MEDIUM | 5.9 | WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can … | Sep 05, 2026 |
| CVE-2026-86186 | MEDIUM | 6.5 | AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force … | Sep 05, 2026 |
| CVE-2026-86185 | HIGH | 8.0 | Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position … | Sep 05, 2026 |
| CVE-2026-86184 | CRITICAL | 9.8 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when … | Sep 05, 2026 |