Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-55251 — NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requi…

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_…

Remote | Supply Chain
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-54049 — Sakai Conversations has a Stored XSS Issue

Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML …

sakai | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-53964 — Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side …

Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.1 CRITICAL
CVE-2026-53953 — GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. W…

getsimple_cms | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.4 CRITICAL
CVE-2026-14984 — Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2

Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic agains…

| Cryptography
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-14983 — Missing Authentication in Teledyne FLIR Robots running Aware2

Missing authentication in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to achieve denial of service against Teledyne FLIR PackBot robots …

| Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.8 CRITICAL
CVE-2026-104286 — Fortinet FortiMail Path Traversal Vulnerability

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8…

fortimail | Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-103484 — pgvector buffer overflow in IVFFlat index build

IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.

pgvector | Memory Corruption
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-102671 — Joyland AI WebView accepts invalid SSL certificates

The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-102670 — Joyland AI enables HTTP

Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.

| Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-102669 — Joyland AI hostname checking disabled

Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-102668 — Joyland AI accepts TLS certificates without validation

The Joyland AI app accepts any TLS certificates from any server without validation.

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.0 CRITICAL
CVE-2026-102667 — Joyland AI WebView command injection

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitr…

| Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-102666 — Joyland AI hard-coded credentials for push notifications

The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content …

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.3 CRITICAL
CVE-2026-102628 — Cadmos LTI exposure of sensitive information via debug mode

The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GE…

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.9 MEDIUM
CVE-2026-100251 — Wormhole.app SSRF

Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to …

Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.7 HIGH
CVE-2026-8618 — Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x…

A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fix…

| Memory Corruption
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.7 HIGH
CVE-2026-84682 — TDDPv2 setProductVer Command Injection in Archer AX90

A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1. An unauthenticated adjacent-network attacker can exploit the setProductVer command handler to execute…

| Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.6 HIGH
CVE-2026-55232 — Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() in editor oE…

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's SSRF guard resolves a host with an IPv4-only function and nev…

vvveb | Remote | Server-Side Request Forgery
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-55231 — Vvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrary file read …

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel use…

vvveb | Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 14905 Results