Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

132 CVEs · published 2026-09-24 to 2026-09-24, Medium severity

CVEs (132)

Showing 1–25 of 132

CVE ID Severity Patch CVSS Published ↓ Description
CVE-2026-97368 MEDIUM 6.3 2026-09-24 A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/ja…
CVE-2026-97366 MEDIUM 6.3 2026-09-24 A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the …
CVE-2026-93353 MEDIUM 5.3 2026-09-24 copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outs…
CVE-2026-87118 MEDIUM 5.7 2026-09-24 The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent networ…
CVE-2026-84403 MEDIUM 6.2 2026-09-24 The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT cha…
CVE-2026-82716 MEDIUM 4.6 2026-09-24 The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. Th…
CVE-2026-82708 MEDIUM 6.5 2026-09-24 The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a craft…
CVE-2026-82585 MEDIUM 6.5 2026-09-24 The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the…
CVE-2026-79959 MEDIUM 6.8 2026-09-24 The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical …
CVE-2026-75558 MEDIUM 5.3 2026-09-24 The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who…
CVE-2026-97365 MEDIUM 6.3 2026-09-24 A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a manipulation of …
CVE-2026-97325 MEDIUM 4.3 2026-09-24 A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the fil…
CVE-2026-93290 MEDIUM 5.5 2026-09-24 Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.
CVE-2026-88956 MEDIUM 6.8 2026-09-24 The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does n…
CVE-2026-88761 MEDIUM 5.3 2026-09-24 The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthe…
CVE-2026-48543 MEDIUM 5.4 2026-09-24 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' …
CVE-2026-48542 MEDIUM 5.4 2026-09-24 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' …
CVE-2026-48541 MEDIUM 5.4 2026-09-24 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' …
CVE-2026-48540 MEDIUM 5.4 2026-09-24 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' …
CVE-2026-97323 MEDIUM 6.3 2026-09-24 A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/…
CVE-2026-97322 MEDIUM 4.3 2026-09-24 A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yuda…
CVE-2026-97321 MEDIUM 6.3 2026-09-24 A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yuda…
CVE-2026-97320 MEDIUM 6.3 2026-09-24 A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowled…
CVE-2026-96748 MEDIUM 6.5 2026-09-24 PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a…
CVE-2026-96747 MEDIUM 5.0 2026-09-24 The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path r…