Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-92255 — Netcore NR255-V 1.5.130703 Out-of-Bounds Read in filter_arp_put_file.cgi via String API M…

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffe…

Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.8 HIGH
CVE-2026-92248 — Gimp: integer overflow when generating a thumbnail preview for a psd file

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication …

enterprise_linux enterprise_linux | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.9 MEDIUM
CVE-2026-92114 — a2ui-project a2ui Basic Catalog safe_regex.ts redos

A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functions/safe_regex.ts of the component Basic …

Remote | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.1 HIGH

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle G…

Remote
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.0 HIGH

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle Graa…

Remote
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.1 HIGH

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle G…

Remote
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.3 MEDIUM
CVE-2026-82567 — mySCADA myPRO Manager Missing Authorization

The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not requi…

mypro | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.3 CRITICAL
CVE-2026-81855 — Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key

A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.

Remote | Cryptography
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.5 CRITICAL
CVE-2026-78225 — Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key

A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.

Remote | Cryptography
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.2 MEDIUM
CVE-2026-76873 — Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP and ARP Hostname Fields

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields. A LAN-based attac…

| Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.4 MEDIUM
CVE-2026-76872 — Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP/ACL Management Pages

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_…

Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.1 HIGH
CVE-2026-76871 — Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via VPN Read Handlers

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. At…

Remote | Information Disclosure
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.1 HIGH
CVE-2026-76870 — Netcore NR255-V 1.5.130703 Out-of-Bounds Read in mtd_write Firmware Upload Validation

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated fir…

Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.6 HIGH
CVE-2026-76869 — Netcore NR255-V 1.5.130703 Stack-Based Buffer Overflow in reboot_timer_set.cgi

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscanf token parsing. Attackers can exploit this flaw by submitting crafted input …

Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.9 MEDIUM
CVE-2026-76868 — Netcore NR255-V 1.5.130703 NULL Pointer Dereference in route_policy_add.cgi via Missing e…

Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port parameter. Attackers can send requests lacking the exit_port…

Remote | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.4 MEDIUM
CVE-2026-76867 — Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in Route/NAT Configuration CGI Han…

Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show…

Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.6 HIGH
CVE-2026-76866 — Netcore NR255-V 1.5.130703 OS Command Argument Injection via Unquoted DDNS Parameters

Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument inje…

Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.9 MEDIUM
CVE-2026-76865 — Netcore NR255-V 1.5.130703 NULL Pointer Dereference via Unchecked atoi() in QoS Setter Ha…

Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c due to unchecked atoi() results. An at…

Remote | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
4.8 MEDIUM
CVE-2026-76864 — Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via Unescaped QoS Rule Names

NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_xianz_show_cgi, qos_filter_add_cgi, and qos_filter_show_cgi handlers. An attack…

Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.3 MEDIUM
CVE-2026-76863 — Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via QoS Bandwidth Plan Routes

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticate…

Remote | Information Disclosure
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
Showing 20 of 14357 Results