Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-68950 — Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups

The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.

| Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.4 CRITICAL
CVE-2026-68491 — Arbitrary File Overwrite via Symlink Vulnerability

An insufficient check allowed for the overwrite of arbitrary files via a symlink.

Remote | Path Traversal
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.8 HIGH
CVE-2026-68070 — Missing Authentication for Critical Function in Digital Watchdog VMAX DVR and NVR Product…

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

| Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.6 CRITICAL
CVE-2026-66890 — Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

| Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.6 CRITICAL
CVE-2026-66887 — Missing Authorization in Digital Watchdog VMAX DVR and NVR Product Lineups

The affected products are missing authorization on state-changing CGIs and session checks are not performed.

| Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.6 HIGH
CVE-2026-66372 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in Digital Watchdog VMAX DVR an…

The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.

| Cryptography
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.6 CRITICAL
CVE-2026-61568 — @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web p…

Remote | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.6 CRITICAL
CVE-2026-61559 — @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the se…

Remote | Server-Side Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-61554 — emp3r0r has an unauthenticated HTTP Polling DoS

emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentica…

emp3r0r | Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.2 HIGH
CVE-2026-54544 — Fireshare has unauthenticated SSRF via missing login_required on webhook test endpoints

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated …

fireshare | Remote | Server-Side Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.8 CRITICAL
CVE-2026-54337 — Fireshare has Unauthenticated Argument Injection to Arbitrary File Write/Overwrite

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. …

fireshare | Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.1 HIGH
CVE-2026-19655 — On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) …

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with mat…

eos | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
2.0 LOW
CVE-2026-18426 — Concrete CMS 9.0.0 to 9.5.2 Express Form block missing authorization allows an authentica…

Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the …

Remote | Cross-Site Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92240 — Out-of-bounds read in IMAP response parser

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachab…

thunderbird | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92239 — Buffer overrun in IMAP

A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.

thunderbird | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92238 — Ambiguous parsing of mail headers

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.

thunderbird | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.8 CRITICAL
CVE-2026-89040 — Tencent Mass Service Engine in Cluster (MSEC) path traversal

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads…

Remote | Path Traversal
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.9 MEDIUM
CVE-2026-89027 — miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrato…

Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-88975 — Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAM…

Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing…

Remote | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.7 MEDIUM
CVE-2026-88922 — Go-getter vulnerable to a privilege escalation issue in its archive decompression handling

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to b…

| Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
Showing 20 of 14268 Results