Search
98 CVEs · published 2026-09-24 to 2026-09-24, High severity
CVEs (98)
Showing 1–25 of 98
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-81630 | HIGH | 8.1 | 2026-09-24 | The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connect… | |
| CVE-2026-97326 | HIGH | 7.3 | 2026-09-24 | A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-… | |
| CVE-2026-97324 | HIGH | 7.3 | 2026-09-24 | A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/… | |
| CVE-2026-96883 | HIGH | Patched | 8.8 | 2026-09-24 | pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute a… |
| CVE-2026-93354 | HIGH | Patched | 8.1 | 2026-09-24 | Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over use… |
| CVE-2026-93289 | HIGH | 7.5 | 2026-09-24 | The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process. | |
| CVE-2026-85496 | HIGH | 8.8 | 2026-09-24 | The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated at… | |
| CVE-2026-84399 | HIGH | 8.8 | 2026-09-24 | The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an au… | |
| CVE-2026-82566 | HIGH | 8.8 | 2026-09-24 | The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has… | |
| CVE-2026-82164 | HIGH | 7.1 | 2026-09-24 | Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with loca… | |
| CVE-2026-77967 | HIGH | 8.1 | 2026-09-24 | The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unau… | |
| CVE-2026-96749 | HIGH | 8.4 | 2026-09-24 | An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusua… | |
| CVE-2026-89325 | HIGH | Patched | 7.8 | 2026-09-24 | An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYST… |
| CVE-2026-82157 | HIGH | 8.3 | 2026-09-24 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent netwo… | |
| CVE-2026-81473 | HIGH | 8.1 | 2026-09-24 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially … | |
| CVE-2026-81455 | HIGH | 8.6 | 2026-09-24 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with rem… | |
| CVE-2026-77294 | HIGH | Patched | 8.1 | 2026-09-24 | TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM… |
| CVE-2026-77293 | HIGH | Patched | 7.1 | 2026-09-24 | TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against t… |
| CVE-2026-61825 | HIGH | Patched | 8.7 | 2026-09-24 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulner… |
| CVE-2026-61823 | HIGH | Patched | 7.3 | 2026-09-24 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulner… |
| CVE-2026-57440 | HIGH | 7.5 | 2026-09-24 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing servi… | |
| CVE-2026-48070 | HIGH | Patched | 7.1 | 2026-09-24 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reu… |
| CVE-2026-13248 | HIGH | 8.8 | 2026-09-24 | An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD4… | |
| CVE-2026-95985 | HIGH | Patched | 8.8 | 2026-09-24 | The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a use… |
| CVE-2026-85057 | HIGH | Patched | 8.7 | 2026-09-24 | ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without r… |