Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-18145 — Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution

A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potenti…

fireware_os | Remote | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-18105 — Fireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of Service

An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools …

fireware_os | Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.2 HIGH
CVE-2026-13224 — Fireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File Read

A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted m…

fireware_os | Remote | Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.5 HIGH
CVE-2026-13046 — Fireware OS Deserialization of Untrusted Data in samld Allows Remote Code Execution

A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on th…

fireware_os | Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-103051 — Stored i18n XSSs in CentralNotice

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS. This issue affec…

| Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-103050 — Stored i18n XSS in MassMessage

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS. This issue affects…

| Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-103049 — XSS in Cargo's Special:CargoQuery page due to unsanitized table headers

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo extension allows Reflected XSS. This issue affects Me…

cargo | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-103048 — Open Redirect in Special:Book

URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - Collection extension allows Fake the Source of Data. This issue affects Mediawiki - Collecti…

| Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.1 CRITICAL
CVE-2026-102794 — Ziroom ZHOME A0101 ping command injection

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command inject…

zhome_a0101 | Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.1 CRITICAL
CVE-2026-102793 — Ziroom ZHOME A0101 set_time_zone command injection

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonena…

zhome_a0101 | Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.5 HIGH
CVE-2026-102599 — Engine.IO Denial of Service Vulnerability

### Impact A denial-of-service vulnerability exists in Engine.IO / Socket.IO servers that allow transport upgrades. The Engine.IO protocol revision is negotiated during the initial handshake and st…

engine.io | Remote | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-103047 — XSS through i18n message in CentralAuth

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects…

| Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-103046 — WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS. This issue affects Medi…

| Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-103045 — XSS in Refreshed skin

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Refreshed skin allows Stored XSS. This issue affects Mediaw…

| Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-103044 — EasyTimeline should not serve image maps as application/xml

XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: be…

| Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.7 HIGH
CVE-2026-103043 — anchorme through 3.0.8 Regular Expression Denial of Service

anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input s…

anchorme | Remote | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.7 HIGH
CVE-2026-103042 — LightLLM through 1.2.0 Unauthenticated Memory Exhaustion via NCCL Control Channel set_val…

LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker …

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.8 CRITICAL
CVE-2026-103041 — LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service

LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to expo…

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.8 CRITICAL
CVE-2026-103040 — LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Ser…

LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with…

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.1 CRITICAL
CVE-2026-102792 — Ziroom ZHOME A0101 set_syslog command injection

A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results i…

zhome_a0101 | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14722 Results