Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-97230 — IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes P…

IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file.…

| Supply Chain
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-97636 — Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypa…

Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can s…

| Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.7 HIGH
CVE-2026-87722 — Regular Expression Denial of Service (ReDoS) in Search Query Predicates and REST Filter E…

Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, RegexRefPredicate, RegexPathPredicate, and sibling predicates) and REST regex f…

Remote | Denial of Service
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.7 HIGH
CVE-2026-87721 — Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Cod…

Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.…

Remote | Denial of Service
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.6 HIGH
CVE-2026-87720 — Incorrect Authorization via Stale ProjectCache Eviction and Repeated .git Suffixes in Ger…

Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction logic (ProjectCacheImpl) in Gerrit Code Review versions 2.16.0 through 3.12.9, 3…

Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-85491 — Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route…

Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone. Catalyst::Seal …

| Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-97368 — chillzhuang SpringBlade user-auth-info Endpoint UserServiceImpl.java UserServiceImpl.user…

A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/s…

Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-97366 — jhen0409 react-native-debugger Open in Editor window.js openDevTools os command injection

A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Ha…

Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.6 CRITICAL
CVE-2026-95699 — MrSteam iSteamX Improper Isolation or Compartmentalization

Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to sta…

Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.0 MEDIUM
CVE-2026-93353 — copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers

copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume bounda…

copyparty | Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-88388 — Espruino Stack-Based Buffer Overflow

Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply JavaScript input t…

| Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-88387 — LibRaw Incorrect Numeric Conversion Denial of Service Vulnerability

LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can suppl…

| Denial of Service
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-88386 — libsndfile Memory Misalignment Denial of Service

libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to cast an unaligned destination …

| Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.9 MEDIUM
CVE-2026-87118 — Botslab G980H Dashcams Out-of-bounds Write

The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit craft…

| Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.9 MEDIUM
CVE-2026-84403 — Botslab G980H Dashcams Missing Authentication for Critical Function

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenti…

| Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.1 MEDIUM
CVE-2026-82716 — Botslab G980H Dashcams Insertion of Sensitive Information into Log File

The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible …

| Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.1 HIGH
CVE-2026-82708 — Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files …

| Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.1 HIGH
CVE-2026-82585 — Botslab G980H Dashcams Cleartext Transmission of Sensitive Information

The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network coul…

| Cryptography
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.2 CRITICAL
CVE-2026-81630 — Botslab G980H Dashcams Insufficient Verification of Data Authenticity

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integr…

Remote | Cryptography
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.0 HIGH
CVE-2026-79959 — Botslab G980H Dashcams Use of Hard-coded Credentials

The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could …

| Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
Showing 20 of 14200 Results