Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-82929 — Use of Shared Cryptographic Key in mH-DEVELOPER

mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH …

Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.7 HIGH
CVE-2026-82928 — Undocumented access path in mH-DEVELOPER

mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts a…

| Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
4.1 MEDIUM
CVE-2026-82326 — HTML Injection in Enocta Educational's Enocta Platform

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes. This …

Remote | Cross-Site Scripting
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.1 HIGH
CVE-2026-82323 — Improper Authorization in Enocta Educational's Enocta Platform

Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows Exploitation of Trusted Identifiers. This issue affects Enocta Platform:…

Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
4.6 MEDIUM
CVE-2026-59563 — HMAC Confirmation Token Unbinding in zscaler-mcp-server

Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated f…

Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-52749 — Improper Authentication in Kaon AR2140X

The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without provi…

| Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.1 HIGH
CVE-2026-52748 — Missing authentication for backup functionality in Kaon AR2140X

The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup …

| Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-18825 — Origin validation error in the connect-xcors npm package

An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.

Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.8 HIGH
CVE-2026-12265 — Missing Authorization on HA Failover Config allows Complete Data Destruction

Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.

Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.2 HIGH
CVE-2026-101292 — Artemis-core-client: unsafe reflection in apache activemq artemis federation message dese…

Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newIn…

Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-101069 — dbgate Export databaseConnections.js exportModelSql path traversal

A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executin…

Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-101068 — dbgate Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData path traversal

A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpo…

Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-101067 — dbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversal

A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipu…

Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-101066 — dbgate Archive Link Creation archive.js createLink path traversal

A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This …

Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.5 MEDIUM
CVE-2026-101055 — Thinkware U3000 TCP Service GET_STATUS information disclosure

A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET_STATUS of the component TCP Service. The manipulation of the argument wifi_inf…

Remote | Information Disclosure
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-101070 — dbgate Files Endpoint runners.js files path traversal

A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the component Files Endpo…

| Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-86595 — SQLi in Iron Mountain's enVision

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.2 CRITICAL
CVE-2026-73642 — Path Traversal in Dayforce Payroll

Dayforce Payroll is vulnerable to Path Traversal  in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute local…

Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.1 MEDIUM
CVE-2026-73641 — Multiple Reflected XSS in Dayforce Payroll

Dayforce Payroll is vulnerable to Reflected XSS in multiple endpoints. An attacker can prepare a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's bro…

Remote | Cross-Site Scripting
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.3 CRITICAL
CVE-2026-73640 — Time-based SQL Injection in Dayforce Payroll

Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an …

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
Showing 20 of 14129 Results