Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-103042 — LightLLM through 1.2.0 Unauthenticated Memory Exhaustion via NCCL Control Channel set_val…

LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker …

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.8 CRITICAL
CVE-2026-103041 — LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service

LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to expo…

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.8 CRITICAL
CVE-2026-103040 — LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Ser…

LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with…

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.1 CRITICAL
CVE-2026-102792 — Ziroom ZHOME A0101 set_syslog command injection

A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results i…

zhome_a0101 | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.4 MEDIUM
CVE-2026-102342 — SVG Stored Cross-Site Scripting

The following SVG will produce a link with a `javascript` scheme. If the user clicks this link, they will run it. ```svg <svg xmlns="http://www.w3.org/2000/svg"> <a> <set attributeName="href" …

ammonia | Remote | Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.7 HIGH
CVE-2026-91191 — Lantronix G520 Series Cellular Gateway Improper Verification of Cryptographic Signature

The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verificati…

Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.7 HIGH
CVE-2026-84409 — Lantronix G520 Series Cellular Gateway Cross-site Scripting

The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently retur…

Remote | Information Disclosure
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.1 HIGH
CVE-2026-74225 — U-Boot before 2026.10-rc5 Out-of-Bounds Write via DHCPv6

U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network…

u-boot | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.8 HIGH
CVE-2026-74222 — U-Boot before 2026.10-rc5 Use-After-Free in lwIP wget Receive Callback

U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection …

u-boot | Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.8 HIGH
CVE-2026-74221 — U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK

U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replie…

u-boot | Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.8 HIGH
CVE-2026-74220 — U-Boot before 2026.10-rc5 Buffer Overflow via NFS READ Reply

U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. A malicious …

u-boot | Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.0 CRITICAL
CVE-2026-72510 — Toptech TMS7 and TopHAT SQL Injection

The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.0 CRITICAL
CVE-2026-72507 — Toptech TMS7 and TopHAT SQL Injection

The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.8 MEDIUM
CVE-2026-71974 — U-Boot before 2026.10-rc3 Out-of-Bounds Write via Android Bootmeth Partition Read

U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supp…

u-boot | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.2 MEDIUM
CVE-2026-71973 — U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Allocation

U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image …

u-boot | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.0 MEDIUM
CVE-2026-71972 — U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder

U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP ima…

u-boot | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.8 HIGH
CVE-2026-71971 — U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly

U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment …

u-boot | Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
10.0 CRITICAL
CVE-2026-71379 — Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties

The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.5 HIGH
CVE-2026-71302 — Toptech TMS7 and TopHAT Session Fixation

The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim auth…

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.8 MEDIUM
CVE-2026-71189 — Toptech TMS7 and TopHAT Cross-site Scripting

An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's…

Remote | Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14694 Results