Search
564 CVEs · published 2026-09-24 to 2026-09-24
EOL hidden · Show all products
CVEs (564, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 564 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-97387 | NONE | — | 2026-09-24 | Rejected reason: This CVE is a duplicate of another CVE. | |
| CVE-2026-97230 | NONE | — | 2026-09-24 | IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script s… | |
| CVE-2026-97636 | NONE | Patched | — | 2026-09-24 | Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag auth… |
| CVE-2026-87722 | NONE | Patched | — | 2026-09-24 | Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, RegexRefPredicate, RegexPathPredicate, and sibling p… |
| CVE-2026-87721 | NONE | Patched | — | 2026-09-24 | Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.… |
| CVE-2026-87720 | NONE | Patched | — | 2026-09-24 | Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction logic (ProjectCacheImpl) in Gerrit Code Review versio… |
| CVE-2026-85491 | NONE | Patched | — | 2026-09-24 | Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request p… |
| CVE-2026-97368 | MEDIUM | 6.3 | 2026-09-24 | A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/ja… | |
| CVE-2026-97366 | MEDIUM | 6.3 | 2026-09-24 | A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the … | |
| CVE-2026-95699 | CRITICAL | 9.6 | 2026-09-24 | Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data an… | |
| CVE-2026-93353 | MEDIUM | 5.3 | 2026-09-24 | copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outs… | |
| CVE-2026-88388 | NONE | — | 2026-09-24 | Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker ca… | |
| CVE-2026-88387 | NONE | — | 2026-09-24 | LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, … | |
| CVE-2026-88386 | NONE | — | 2026-09-24 | libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to cas… | |
| CVE-2026-87118 | MEDIUM | 5.7 | 2026-09-24 | The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent networ… | |
| CVE-2026-84403 | MEDIUM | 6.2 | 2026-09-24 | The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT cha… | |
| CVE-2026-82716 | MEDIUM | 4.6 | 2026-09-24 | The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. Th… | |
| CVE-2026-82708 | MEDIUM | 6.5 | 2026-09-24 | The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a craft… | |
| CVE-2026-82585 | MEDIUM | 6.5 | 2026-09-24 | The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the… | |
| CVE-2026-81630 | HIGH | 8.1 | 2026-09-24 | The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connect… | |
| CVE-2026-79959 | MEDIUM | 6.8 | 2026-09-24 | The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical … | |
| CVE-2026-75558 | MEDIUM | 5.3 | 2026-09-24 | The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who… | |
| CVE-2026-14443 | NONE | Patched | — | 2026-09-24 | Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system log… |
| CVE-2026-14442 | NONE | — | 2026-09-24 | An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled… | |
| CVE-2026-14441 | NONE | — | 2026-09-24 | A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue … |