Search
132 CVEs · published 2026-09-24 to 2026-09-24, Medium severity
CVEs (132)
Showing 1–25 of 132
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-97368 | MEDIUM | 6.3 | 2026-09-24 | A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/ja… | |
| CVE-2026-97366 | MEDIUM | 6.3 | 2026-09-24 | A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the … | |
| CVE-2026-93353 | MEDIUM | 5.3 | 2026-09-24 | copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outs… | |
| CVE-2026-87118 | MEDIUM | 5.7 | 2026-09-24 | The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent networ… | |
| CVE-2026-84403 | MEDIUM | 6.2 | 2026-09-24 | The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT cha… | |
| CVE-2026-82716 | MEDIUM | 4.6 | 2026-09-24 | The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. Th… | |
| CVE-2026-82708 | MEDIUM | 6.5 | 2026-09-24 | The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a craft… | |
| CVE-2026-82585 | MEDIUM | 6.5 | 2026-09-24 | The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the… | |
| CVE-2026-79959 | MEDIUM | 6.8 | 2026-09-24 | The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical … | |
| CVE-2026-75558 | MEDIUM | 5.3 | 2026-09-24 | The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who… | |
| CVE-2026-97365 | MEDIUM | 6.3 | 2026-09-24 | A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a manipulation of … | |
| CVE-2026-97325 | MEDIUM | 4.3 | 2026-09-24 | A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the fil… | |
| CVE-2026-93290 | MEDIUM | 5.5 | 2026-09-24 | Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data. | |
| CVE-2026-88956 | MEDIUM | 6.8 | 2026-09-24 | The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does n… | |
| CVE-2026-88761 | MEDIUM | 5.3 | 2026-09-24 | The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthe… | |
| CVE-2026-48543 | MEDIUM | 5.4 | 2026-09-24 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' … | |
| CVE-2026-48542 | MEDIUM | 5.4 | 2026-09-24 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' … | |
| CVE-2026-48541 | MEDIUM | 5.4 | 2026-09-24 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' … | |
| CVE-2026-48540 | MEDIUM | 5.4 | 2026-09-24 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' … | |
| CVE-2026-97323 | MEDIUM | 6.3 | 2026-09-24 | A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/… | |
| CVE-2026-97322 | MEDIUM | 4.3 | 2026-09-24 | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yuda… | |
| CVE-2026-97321 | MEDIUM | 6.3 | 2026-09-24 | A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yuda… | |
| CVE-2026-97320 | MEDIUM | 6.3 | 2026-09-24 | A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowled… | |
| CVE-2026-96748 | MEDIUM | 6.5 | 2026-09-24 | PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a… | |
| CVE-2026-96747 | MEDIUM | 5.0 | 2026-09-24 | The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path r… |