Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.0 MEDIUM
CVE-2026-104002 — Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)

A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.  To …

Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.2 HIGH
CVE-2026-96780 — figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used…

figlet.js is a FIG driver written in JavaScript that aims to implement the FIGfont specification. Prior to 1.11.3, text() and textSync() can enter an unbounded loop when whitespaceBreak is enabled an…

Remote | Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-71451 — Johnson Controls EasyIO FS32 OS Command Injection

- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.

easyio_fs32 | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.5 HIGH
CVE-2026-55396 — Unencrypted UDP Control Traffic in Teledyne FLIR Robots running Aware2

Cleartext transmission without a cryptographic integrity check in operator control unit to robot UDP traffic in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows ad…

| Cryptography
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.4 CRITICAL
CVE-2026-55395 — Hardcoded Passwords in Teledyne FLIR Robots running Aware2

Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne F…

| Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-55394 — Unencrypted 802.11 Network in Teledyne FLIR Robots running Aware2

Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne F…

| Cryptography
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
10.0 CRITICAL
CVE-2026-55393 — Local File Inclusion in Teledyne FLIR Robots running Aware2

Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security …

Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.9 MEDIUM
CVE-2026-27874 — Johnson Controls EasyIO FS32 Hard-coded Credentials Vulnerability

: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.

easyio_fs32 | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.1 MEDIUM
CVE-2026-104183 — stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so a…

| Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.2 MEDIUM
CVE-2026-104182 — stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every inp…

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stre…

| Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.4 MEDIUM
CVE-2026-104181 — Filament: Multi-factor authentication (app) management actions do not require password re…

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently …

filament | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-104020 — Uncontrolled recursion in the Ion reader in Amazon Ion Python

Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, vi…

Remote | Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.4 HIGH
CVE-2026-102514 — Out-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea arch…

Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and earlier allows an attacker who convinces a victim …

peazip | Memory Corruption
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.4 MEDIUM
CVE-2026-102370 — Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC…

Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader.  Although the debug traces are physically severed during…

kasa_ec70 kasa_ec71 | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.8 MEDIUM
CVE-2026-93832 — Motorola System Application Unauthorized Permission Revocation Vulnerability

A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.

setup_app | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-82358 — RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass

RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when proces…

| Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-82357 — RT-Labs AB C-Open CANopen NULL pointer dereference

RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for o…

| Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-71542 — GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/compo…

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripti…

getsimple_cms | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-71426 — GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store a…

getsimple_cms | Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-70650 — GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output dec…

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnera…

getsimple_cms | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 14882 Results