Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-85382 | MEDIUM | 4.3 | A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Impacted is the function htmlspecialchars_decode of the file App/Home/View/Default/Chapter/oneChapter.tpl of the component Chapter Content Output. Performing a … | Sep 04, 2026 |
| CVE-2026-45200 | UNKNOWN | — | Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause … | Sep 04, 2026 |
| CVE-2026-45197 | UNKNOWN | — | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside … | Sep 04, 2026 |
| CVE-2026-85381 | MEDIUM | 5.3 | A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Home/Controller/ChapterController.class.php of the component Chapter Controller. … | Sep 04, 2026 |
| CVE-2026-85380 | HIGH | 7.3 | A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function catchimage of the file Public/ueditor/php/controller.php of the component UEditor. This manipulation … | Sep 04, 2026 |
| CVE-2026-85379 | HIGH | 7.3 | A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects the function ChapterModel::searchChapter of the file App/Home/Controller/ChapterController.class.php of the component Query Builder. The … | Sep 04, 2026 |
| CVE-2026-67402 | UNKNOWN | — | An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker … | Sep 04, 2026 |
| CVE-2026-67398 | UNKNOWN | — | Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from … | Sep 04, 2026 |
| CVE-2026-67397 | UNKNOWN | — | Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root. | Sep 04, 2026 |
| CVE-2026-49509 | MEDIUM | 4.4 | Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overread Buffers. This issue affects Escargot: 25648aef19187b3f87f4d9420b8d761453ad4630. | Sep 04, 2026 |
| CVE-2026-85456 | MEDIUM | 5.5 | MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directory. … | Sep 03, 2026 |
| CVE-2026-85455 | HIGH | 8.2 | MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a … | Sep 03, 2026 |
| CVE-2026-85454 | MEDIUM | 6.1 | MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers … | Sep 03, 2026 |
| CVE-2026-85453 | MEDIUM | 6.1 | MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set … | Sep 03, 2026 |
| CVE-2026-85452 | HIGH | 8.8 | MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using … | Sep 03, 2026 |
| CVE-2026-85451 | HIGH | 7.1 | MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable … | Sep 03, 2026 |
| CVE-2026-85450 | HIGH | 7.5 | MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can … | Sep 03, 2026 |
| CVE-2026-85449 | HIGH | 7.5 | MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct … | Sep 03, 2026 |
| CVE-2026-85448 | HIGH | 7.5 | MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publisher can supply unbounded distinct … | Sep 03, 2026 |
| CVE-2026-85447 | HIGH | 7.5 | MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits. Attackers can register long-lived pipeways with many variables to … | Sep 03, 2026 |
| CVE-2026-85446 | HIGH | 7.5 | MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. … | Sep 03, 2026 |
| CVE-2026-85445 | HIGH | 7.5 | MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without validation. Attackers … | Sep 03, 2026 |
| CVE-2026-85444 | HIGH | 7.5 | MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length. Attackers … | Sep 03, 2026 |
| CVE-2026-85443 | HIGH | 7.5 | MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol … | Sep 03, 2026 |
| CVE-2026-85442 | HIGH | 7.5 | MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers to trigger unbounded buffer allocation by sending crafted wire packets. … | Sep 03, 2026 |