Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41921
Total
3420
Critical
12394
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-80768 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: HID: ft260: fix stack-use-after-return write in I2C read race ft260_i2c_read() points dev->read_buf at a caller-supplied … | Sep 04, 2026 |
| CVE-2026-80767 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: HID: sensor: custom: Fix use-after-free in enable_sensor enable_sensor_store() can call set_power_report_state(), which dereferences sensor_inst->power_state and … | Sep 04, 2026 |
| CVE-2026-80766 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: fix use-after-free of inrange_timer on remove uclogic_remove() cancels the pen in-range timer and … | Sep 04, 2026 |
| CVE-2026-80765 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: HID: hyperv: validate initial device info bounds The Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO messages … | Sep 04, 2026 |
| CVE-2026-80764 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix LE list UAF on reset hci_cc_reset() clears the LE accept and resolving … | Sep 04, 2026 |
| CVE-2026-80763 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: validate LE Set CIG Parameters response The Command Complete dispatch validates only the … | Sep 04, 2026 |
| CVE-2026-80762 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix accept list UAF during suspend hci_update_event_filter_sync() walks hdev->accept_list while sending a synchronous … | Sep 04, 2026 |
| CVE-2026-80761 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: zero the sockaddr before returning it in getname iso_sock_getname() fills a struct sockaddr_iso … | Sep 04, 2026 |
| CVE-2026-80760 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 mgmt_hci_cmd_sync() checks that the message length agrees with … | Sep 04, 2026 |
| CVE-2026-80759 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_aml: validate firmware segment lengths aml_download_firmware() reads two lengths from the firmware header and … | Sep 04, 2026 |
| CVE-2026-80758 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: futex: Avoid private hash use-after-free on final put futex_private_hash_put() drops the reference to fph before … | Sep 04, 2026 |
| CVE-2026-79419 | UNKNOWN | — | A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and … | Sep 04, 2026 |
| CVE-2026-79418 | UNKNOWN | — | EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during … | Sep 04, 2026 |
| CVE-2026-78970 | MEDIUM | 6.5 | JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An authenticated attacker with any valid JWT token can access multiple API … | Sep 04, 2026 |
| CVE-2026-78658 | MEDIUM | 6.5 | IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through … | Sep 04, 2026 |
| CVE-2026-78543 | MEDIUM | 5.3 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker … | Sep 04, 2026 |
| CVE-2026-77822 | HIGH | 8.2 | IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding. | Sep 04, 2026 |
| CVE-2026-75431 | CRITICAL | 9.1 | PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code. | Sep 04, 2026 |
| CVE-2026-75429 | UNKNOWN | — | PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer | Sep 04, 2026 |
| CVE-2026-75171 | UNKNOWN | — | An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component. | Sep 04, 2026 |
| CVE-2026-75170 | UNKNOWN | — | Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to inject arbitrary JavaScript into the … | Sep 04, 2026 |
| CVE-2026-75169 | UNKNOWN | — | An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with … | Sep 04, 2026 |
| CVE-2026-75168 | MEDIUM | 6.3 | An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to … | Sep 04, 2026 |
| CVE-2026-75167 | UNKNOWN | — | A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged … | Sep 04, 2026 |
| CVE-2026-75166 | UNKNOWN | — | Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the … | Sep 04, 2026 |