Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-94185 — nvm alias resolution follows `..` and discloses files outside $NVM_DIR/alias

nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() concatenated the requested name onto that directory and read the result with no…

| Path Traversal
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.8 HIGH
CVE-2026-94129 — BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation o…

| Memory Corruption
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.8 HIGH
CVE-2026-94128 — BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the …

| Memory Corruption
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.5 HIGH
CVE-2026-94110 — QCMS Content Detail Controllers.php self_Tmp sql injection

A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulat…

Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.8 MEDIUM
CVE-2026-94103 — RooCMS Frontend Rendering site_pagePHP.php eval code injection

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend Rendering. Such manipulation of the arg…

Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.0 MEDIUM
CVE-2026-94102 — WuzhiCMS Login index.php redirect

A flaw has been found in WuzhiCMS up to 4.1.0. This affects an unknown function of the file /index.php?m=member&v=Login of the component Login. This manipulation of the argument forward causes open r…

Remote | Misconfiguration
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
9.9 CRITICAL
CVE-2026-94101 — Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argumen…

Remote | Memory Corruption
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
9.9 CRITICAL
CVE-2026-94100 — Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a …

Remote | Memory Corruption
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
9.9 CRITICAL
CVE-2026-94099 — Netcore NBR200V2 Backup Restore restore.cgi command injection

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulatio…

Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
9.1 CRITICAL
CVE-2026-94098 — Netcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injection

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such man…

Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
10.0 CRITICAL
CVE-2026-94097 — Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation o…

Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
9.9 CRITICAL
CVE-2026-94096 — Netcore NBR200V2 LAN IP Configuration network_tools command injection

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler.…

Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
9.9 CRITICAL
CVE-2026-94095 — Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnos…

Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
4.3 MEDIUM
CVE-2026-94094 — OpenClaw Canvas Host Route server.ts createCanvasHostHandler denial of service

A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a man…

Remote | Denial of Service
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-94093 — DLR-RM stable-baselines3 save_util.py VecNormalize.load deserialization

A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94092 — dmlc dgl utils.py _read_torch_data deserialization

A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipulation of the argument path results in deserializat…

Remote | Information Disclosure
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94091 — piskvorky gensim Model Loader utils.py load deserialization

A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument …

Remote | Misconfiguration
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-94090 — JusticeRage Manalyze PE Parser pe.cpp _parse_debug integer underflow

A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug of the file manape/pe.cpp of the component PE Parser. The manipulation of the …

Remote | Memory Corruption
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
10.0 CRITICAL
CVE-2026-94089 — D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulati…

Remote | Memory Corruption
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.5 MEDIUM
CVE-2026-94051 — 0717376 cowork_bench pdf-tools-mcp server.py ControlFlowNode server-side request forgery

A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulnerability is the function ControlFlowNode of the file local_servers/pdf-tools-mc…

Remote | Server-Side Request Forgery
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
Showing 20 of 13766 Results