Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-71971 — U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly

U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment …

u-boot | Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
10.0 CRITICAL
CVE-2026-71379 — Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties

The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.5 HIGH
CVE-2026-71302 — Toptech TMS7 and TopHAT Session Fixation

The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim auth…

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.8 MEDIUM
CVE-2026-71189 — Toptech TMS7 and TopHAT Cross-site Scripting

An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's…

Remote | Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.4 CRITICAL
CVE-2026-70356 — Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type

The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.

Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
3.7 LOW
CVE-2026-69662 — Toptech TMS7 and TopHAT Eval Injection

The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.

| Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.0 CRITICAL
CVE-2026-68954 — Toptech TMS7 and TopHAT SQL Injection

The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.0 CRITICAL
CVE-2026-68068 — Toptech TMS7 and TopHAT SQL Injection

The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.0 CRITICAL
CVE-2026-63713 — Toptech TMS7 and TopHAT SQL Injection

The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability.

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.8 MEDIUM
CVE-2026-102771 — Naichen ThinkCMF Email Template MailController.php templatePut special elements in templa…

A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the function MailController::templatePut of the file cmf-api/src/admin/controller/MailController.…

thinkcmf | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
3.3 LOW
CVE-2026-102621 — Freedesktop Poppler SplashClip.cc clipToPath integer overflow

A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The…

poppler | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
10.0 CRITICAL
CVE-2026-96587 — Use of Hard-coded Credentials in Viidure Dashcam Android Application

The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the abili…

Remote | Cryptography
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-94952 — TOTOLINK N150RT Stack-Based Buffer Overflow

A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-fo…

Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.7 HIGH
CVE-2026-94204 — Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Applicat…

The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shar…

Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.2 HIGH
CVE-2026-93853 — Barman snapshot backup deletion trusts unverified backup catalog metadata

Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, eit…

| Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.3 MEDIUM
CVE-2026-81842 — Library panel can be moved into a folder without library panel create permission

An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Plat…

grafana | Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.3 MEDIUM
CVE-2026-81841 — Paused shared dashboard access tokens still expose data source configuration

Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, wi…

grafana | Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.8 MEDIUM
CVE-2026-102938 — virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allow…

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_va…

virtualenv | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.3 HIGH
CVE-2026-102937 — virtualenv: Command injection via --prompt in activate.bat (batch activator)

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set "VAR=v…

virtualenv | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.7 HIGH
CVE-2026-102930 — virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option…

virtualenv | Remote | Supply Chain
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14689 Results