Search
565 CVEs · published 2026-09-24 to 2026-09-24
CVEs (565, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 565 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-97365 | MEDIUM | 6.3 | 2026-09-24 | A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a manipulation of … | |
| CVE-2026-97326 | HIGH | 7.3 | 2026-09-24 | A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-… | |
| CVE-2026-97325 | MEDIUM | 4.3 | 2026-09-24 | A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the fil… | |
| CVE-2026-97324 | HIGH | 7.3 | 2026-09-24 | A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/… | |
| CVE-2026-96883 | HIGH | Patched | 8.8 | 2026-09-24 | pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute a… |
| CVE-2026-93354 | HIGH | Patched | 8.1 | 2026-09-24 | Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over use… |
| CVE-2026-93291 | CRITICAL | 9.4 | 2026-09-24 | Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code. | |
| CVE-2026-93290 | MEDIUM | 5.5 | 2026-09-24 | Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data. | |
| CVE-2026-93289 | HIGH | 7.5 | 2026-09-24 | The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process. | |
| CVE-2026-88956 | MEDIUM | 6.8 | 2026-09-24 | The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does n… | |
| CVE-2026-88761 | MEDIUM | 5.3 | 2026-09-24 | The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthe… | |
| CVE-2026-85496 | HIGH | 8.8 | 2026-09-24 | The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated at… | |
| CVE-2026-84399 | HIGH | 8.8 | 2026-09-24 | The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an au… | |
| CVE-2026-82566 | HIGH | 8.8 | 2026-09-24 | The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has… | |
| CVE-2026-82372 | NONE | Patched | — | 2026-09-24 | Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in appl… |
| CVE-2026-82164 | HIGH | 7.1 | 2026-09-24 | Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with loca… | |
| CVE-2026-77967 | HIGH | 8.1 | 2026-09-24 | The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unau… | |
| CVE-2026-48543 | MEDIUM | 5.4 | 2026-09-24 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' … | |
| CVE-2026-48542 | MEDIUM | 5.4 | 2026-09-24 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' … | |
| CVE-2026-48541 | MEDIUM | 5.4 | 2026-09-24 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' … | |
| CVE-2026-48540 | MEDIUM | 5.4 | 2026-09-24 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' … | |
| CVE-2026-97323 | MEDIUM | 6.3 | 2026-09-24 | A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/… | |
| CVE-2026-97322 | MEDIUM | 4.3 | 2026-09-24 | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yuda… | |
| CVE-2026-97321 | MEDIUM | 6.3 | 2026-09-24 | A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yuda… | |
| CVE-2026-97320 | MEDIUM | 6.3 | 2026-09-24 | A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowled… |