Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

98 CVEs · published 2026-09-24 to 2026-09-24, High severity

CVEs (98)

Showing 1–25 of 98

CVE ID Severity Patch CVSS Published ↓ Description
CVE-2026-81630 HIGH 8.1 2026-09-24 The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connect…
CVE-2026-97326 HIGH 7.3 2026-09-24 A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-…
CVE-2026-97324 HIGH 7.3 2026-09-24 A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/…
CVE-2026-96883 HIGH Patched 8.8 2026-09-24 pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute a…
CVE-2026-93354 HIGH Patched 8.1 2026-09-24 Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over use…
CVE-2026-93289 HIGH 7.5 2026-09-24 The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.
CVE-2026-85496 HIGH 8.8 2026-09-24 The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated at…
CVE-2026-84399 HIGH 8.8 2026-09-24 The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an au…
CVE-2026-82566 HIGH 8.8 2026-09-24 The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has…
CVE-2026-82164 HIGH 7.1 2026-09-24 Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with loca…
CVE-2026-77967 HIGH 8.1 2026-09-24 The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unau…
CVE-2026-96749 HIGH 8.4 2026-09-24 An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusua…
CVE-2026-89325 HIGH Patched 7.8 2026-09-24 An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYST…
CVE-2026-82157 HIGH 8.3 2026-09-24 Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent netwo…
CVE-2026-81473 HIGH 8.1 2026-09-24 Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially …
CVE-2026-81455 HIGH 8.6 2026-09-24 Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with rem…
CVE-2026-77294 HIGH Patched 8.1 2026-09-24 TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM…
CVE-2026-77293 HIGH Patched 7.1 2026-09-24 TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against t…
CVE-2026-61825 HIGH Patched 8.7 2026-09-24 code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulner…
CVE-2026-61823 HIGH Patched 7.3 2026-09-24 code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulner…
CVE-2026-57440 HIGH 7.5 2026-09-24 The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing servi…
CVE-2026-48070 HIGH Patched 7.1 2026-09-24 Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reu…
CVE-2026-13248 HIGH 8.8 2026-09-24 An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD4…
CVE-2026-95985 HIGH Patched 8.8 2026-09-24 The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a use…
CVE-2026-85057 HIGH Patched 8.7 2026-09-24 ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without r…