Total
396563 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-75340 | 2026-09-09 | N/A | 9.1 CRITICAL | ||
| The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF). | |||||
| CVE-2026-75339 | 2026-09-09 | N/A | 8.8 HIGH | ||
| The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them. | |||||
| CVE-2026-68005 | 2026-09-09 | N/A | 7.5 HIGH | ||
| An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_request() function | |||||
| CVE-2026-67919 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components | |||||
| CVE-2026-51106 | 2026-09-09 | N/A | 9.3 CRITICAL | ||
| An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component | |||||
| CVE-2026-52370 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL. | |||||
| CVE-2026-78741 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature. | |||||
| CVE-2026-52103 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message. | |||||
| CVE-2026-75328 | 2026-09-09 | N/A | 7.5 HIGH | ||
| In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability: | |||||
| CVE-2026-67865 | 2026-09-09 | N/A | 7.5 HIGH | ||
| S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denial of service | |||||
| CVE-2026-75325 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. | |||||
| CVE-2026-67918 | 2026-09-09 | N/A | 7.5 HIGH | ||
| Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint | |||||
| CVE-2026-50980 | 2026-09-09 | N/A | 6.1 MEDIUM | ||
| Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record | |||||
| CVE-2026-68004 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_app_security.cpp, and SRS RTMP listener components | |||||
| CVE-2026-82090 | 2026-09-09 | N/A | N/A | ||
| Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods. | |||||
| CVE-2026-75165 | 2026-09-09 | N/A | 6.5 MEDIUM | ||
| An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information. | |||||
| CVE-2025-63822 | 2026-09-09 | N/A | 8.1 HIGH | ||
| SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data. | |||||
| CVE-2025-70962 | 2026-09-09 | N/A | 7.5 HIGH | ||
| Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage. | |||||
| CVE-2026-71624 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components | |||||
| CVE-2026-52102 | 2026-09-09 | N/A | 9.8 CRITICAL | ||
| An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters. | |||||
