Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41921
Total
3420
Critical
12394
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-80768 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: HID: ft260: fix stack-use-after-return write in I2C read race ft260_i2c_read() points dev->read_buf at a caller-supplied … Sep 04, 2026
CVE-2026-80767 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: HID: sensor: custom: Fix use-after-free in enable_sensor enable_sensor_store() can call set_power_report_state(), which dereferences sensor_inst->power_state and … Sep 04, 2026
CVE-2026-80766 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: fix use-after-free of inrange_timer on remove uclogic_remove() cancels the pen in-range timer and … Sep 04, 2026
CVE-2026-80765 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: HID: hyperv: validate initial device info bounds The Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO messages … Sep 04, 2026
CVE-2026-80764 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix LE list UAF on reset hci_cc_reset() clears the LE accept and resolving … Sep 04, 2026
CVE-2026-80763 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: validate LE Set CIG Parameters response The Command Complete dispatch validates only the … Sep 04, 2026
CVE-2026-80762 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix accept list UAF during suspend hci_update_event_filter_sync() walks hdev->accept_list while sending a synchronous … Sep 04, 2026
CVE-2026-80761 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: zero the sockaddr before returning it in getname iso_sock_getname() fills a struct sockaddr_iso … Sep 04, 2026
CVE-2026-80760 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 mgmt_hci_cmd_sync() checks that the message length agrees with … Sep 04, 2026
CVE-2026-80759 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_aml: validate firmware segment lengths aml_download_firmware() reads two lengths from the firmware header and … Sep 04, 2026
CVE-2026-80758 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: futex: Avoid private hash use-after-free on final put futex_private_hash_put() drops the reference to fph before … Sep 04, 2026
CVE-2026-79419 UNKNOWN A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and … Sep 04, 2026
CVE-2026-79418 UNKNOWN EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during … Sep 04, 2026
CVE-2026-78970 MEDIUM 6.5 JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An authenticated attacker with any valid JWT token can access multiple API … Sep 04, 2026
CVE-2026-78658 MEDIUM 6.5 IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through … Sep 04, 2026
CVE-2026-78543 MEDIUM 5.3 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker … Sep 04, 2026
CVE-2026-77822 HIGH 8.2 IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding. Sep 04, 2026
CVE-2026-75431 CRITICAL 9.1 PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code. Sep 04, 2026
CVE-2026-75429 UNKNOWN PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer Sep 04, 2026
CVE-2026-75171 UNKNOWN An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component. Sep 04, 2026
CVE-2026-75170 UNKNOWN Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to inject arbitrary JavaScript into the … Sep 04, 2026
CVE-2026-75169 UNKNOWN An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with … Sep 04, 2026
CVE-2026-75168 MEDIUM 6.3 An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to … Sep 04, 2026
CVE-2026-75167 UNKNOWN A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged … Sep 04, 2026
CVE-2026-75166 UNKNOWN Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the … Sep 04, 2026