Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82712 | HIGH | 8.8 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations … | Sep 04, 2026 |
| CVE-2026-79426 | UNKNOWN | — | An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request. | Sep 04, 2026 |
| CVE-2026-79423 | UNKNOWN | — | An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request. | Sep 04, 2026 |
| CVE-2026-77847 | MEDIUM | 6.5 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information … | Sep 04, 2026 |
| CVE-2026-75439 | UNKNOWN | — | An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component | Sep 04, 2026 |
| CVE-2026-75438 | UNKNOWN | — | Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function | Sep 04, 2026 |
| CVE-2026-53769 | MEDIUM | 6.5 | Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint … | Sep 04, 2026 |
| CVE-2026-50894 | UNKNOWN | — | easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary … | Sep 04, 2026 |
| CVE-2025-67066 | UNKNOWN | — | SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path | Sep 04, 2026 |
| CVE-2022-26961 | UNKNOWN | — | Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. … | Sep 04, 2026 |
| CVE-2026-85786 | HIGH | 7.5 | Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed … | Sep 04, 2026 |
| CVE-2026-85643 | MEDIUM | 4.7 | A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the … | Sep 04, 2026 |
| CVE-2026-79391 | UNKNOWN | — | No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a … | Sep 04, 2026 |
| CVE-2026-79390 | UNKNOWN | — | Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker with … | Sep 04, 2026 |
| CVE-2026-79389 | UNKNOWN | — | Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, including … | Sep 04, 2026 |
| CVE-2026-71626 | UNKNOWN | — | An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components | Sep 04, 2026 |
| CVE-2026-71625 | UNKNOWN | — | An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component | Sep 04, 2026 |
| CVE-2026-71624 | UNKNOWN | — | An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components | Sep 04, 2026 |
| CVE-2026-71622 | UNKNOWN | — | SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component | Sep 04, 2026 |
| CVE-2026-63464 | HIGH | 7.7 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: … | Sep 04, 2026 |
| CVE-2026-61699 | HIGH | 8.1 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded … | Sep 04, 2026 |
| CVE-2026-55513 | MEDIUM | 5.4 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores … | Sep 04, 2026 |
| CVE-2026-55512 | MEDIUM | 5.3 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is … | Sep 04, 2026 |
| CVE-2026-53932 | HIGH | 8.0 | laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue … | Sep 04, 2026 |
| CVE-2026-53604 | UNKNOWN | — | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into … | Sep 04, 2026 |