Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-88273 — GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.5 CRITICAL
CVE-2026-44950 — fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies wi…

Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.2 HIGH
CVE-2026-88272 — GV-LPC2011/LPC2211 - Stored Administrator-Username Command Injection

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.8 HIGH
CVE-2026-88271 — GV-LPC2011/LPC2211 - SSVR Guest Configuration Overwrite and Administrative Credential Tak…

GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.

Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-88270 — GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of S…

GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.

Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-88269 — GV-LPC2011/LPC2211 - SSVR Guest Configuration and Credential Disclosure

GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.

Remote | Information Disclosure
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-88268 — GV-LPC2011/LPC2211 - SSVR Fragment-Reassembly Stack Overflow Denial of Service

GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.

Remote | Memory Corruption
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-88770 — Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-f…

A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account…

single_sign-on build_of_keycloak | Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.9 MEDIUM
CVE-2026-88763 — Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial …

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processe…

service_interconnect | Remote | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-80354 — Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named sec…

Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the o…

| Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-80352 — Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author app…

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject …

| Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-80351 — Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven conf…

| Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.8 CRITICAL
CVE-2026-7188 — SQLi in Armiya Information Technologies' Access Control System

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue …

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.2 CRITICAL
CVE-2026-59679 — fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with …

Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-82925 — Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature

The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which mak…

| Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-82582 — SHIRASAGI Authorization Bypass Vulnerability

An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature.

| Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.4 MEDIUM
CVE-2026-81635 — SHIRASAGI Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an arbitrary script in the web browser of a user who accesses a website using the affected product.

| Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-81431 — Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via U…

The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-…

| Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-78361 — zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Opti…

The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which opti…

| Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-77771 — miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an i…

| Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Showing 20 of 13986 Results