Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-102335 — Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config

Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can …

nginx-proxy-manager | Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.1 CRITICAL
CVE-2026-102334 — Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection

Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-forc…

nginx-proxy-manager | Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.1 MEDIUM
CVE-2026-102333 — httpdbg before 2.2.1 Stored Cross-Site Scripting via javascript URL

httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascr…

Remote | Cross-Site Scripting
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.1 MEDIUM
CVE-2026-102332 — Dozzle before 11.1.2 Path Traversal via Log ZIP Download

Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use path traversal se…

Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.1 CRITICAL
CVE-2026-101262 — Ziroom ZHOME A0101 set_online_client command injection

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command in…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.1 CRITICAL
CVE-2026-101261 — Ziroom ZHOME A0101 firstSetup_wifi command injection

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command in…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.1 CRITICAL
CVE-2026-101260 — Ziroom ZHOME A0101 firstLogin command injection

A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of the argument first…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-101264 — Ziroom ZHOME A0101 set_passwd command injection

A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injecti…

| Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-101263 — Ziroom ZHOME A0101 set_online_client command injection

A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command i…

| Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-102297 — ZoneMinder before 1.38.4 Incorrect Authorization in frames API index

ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame r…

Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.3 HIGH
CVE-2026-102296 — ZoneMinder before 1.38.4 Buffer Overflow via HTTP Camera Response

ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers …

Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-102281 — Nest: Remote process termination via a deeply nested microservice message pattern

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice…

nest | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-101205 — FastStone Image Viewer PCX Decoder out-of-bounds

A vulnerability was determined in FastStone Image Viewer up to 8.3. This impacts an unknown function of the component PCX Decoder. This manipulation causes out-of-bounds read. The attack may be initi…

image_viewer | Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-101204 — FastStone Image Viewer TGA Image FSViewer.exe out-of-bounds

A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe of the component TGA Image Handler. The manipulation results in out-of-bounds …

image_viewer | Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-101203 — FastStone Image Viewer 1bpp RLE Decoder out-of-bounds write

A vulnerability has been found in FastStone Image Viewer up to 8.3. The impacted element is an unknown function of the component 1bpp RLE Decoder. The manipulation leads to out-of-bounds write. The a…

image_viewer | Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-101202 — FastStone Image Viewer TGA Image out-of-bounds write

A flaw has been found in FastStone Image Viewer up to 8.3. The affected element is an unknown function of the component TGA Image Handler. Executing a manipulation can lead to out-of-bounds write. It…

image_viewer | Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.3 HIGH
CVE-2026-101188 — Netcore POWER13 ubus routerd.passwd_set password recovery

A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak password recover…

Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.4 MEDIUM
CVE-2026-101093 — Cotonti through 1.0.0 Cross-Site Request Forgery via User Group Deletion

Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious link…

Remote | Cross-Site Request Forgery
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.9 MEDIUM
CVE-2026-101092 — SiYuan before v3.8.4 Information Disclosure via getCurrentAttrViewImages

SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish readers to retrieve image asset paths from unauthorized databases. Attackers can…

Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.1 HIGH
CVE-2026-101091 — SiYuan before v3.8.4 SQL Injection via Block Query Embed

SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL state…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
Showing 20 of 14257 Results