Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.0 MEDIUM
CVE-2026-75558 — Botslab G980H Dashcams Use of Hard-coded Cryptographic Key

The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected cred…

| Cryptography
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.4 HIGH
CVE-2026-14443 — Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before …

Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read ac…

sannav sannav | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.9 MEDIUM
CVE-2026-14442 — Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a

An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or relat…

sannav sannav | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.9 MEDIUM
CVE-2026-14441 — Logic flaw in SANnav Java cache key handling object comparison handling

A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue has been remediated by upda…

sannav sannav | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-97365 — chonkie-inc littrs lib.rs mount path traversal

A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a manipulation of the argument relative can l…

littrs | Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-97326 — songxinjianqwe Chat chat-server ChatServer.java server-side request forgery

A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sin…

chat | Remote | Server-Side Request Forgery
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.0 MEDIUM
CVE-2026-97325 — YunaiV/zhijiantianya ruoyi-vue-pro OAuth2 Client OAuth2ClientServiceImpl.java validOAuthC…

A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/m…

ruoyi-vue-pro ruoyi-vue-pro | Remote | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-97324 — YunaiV/zhijiantianya ruoyi-vue-pro Demo-order Payment Callback PayDemoOrderController.jav…

A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay…

ruoyi-vue-pro ruoyi-vue-pro | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-96883 — Type confusion in AWS pgcollection allows remote code execution

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgr…

pgcollection | Remote | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.5 HIGH
CVE-2026-93354 — Taskview Community Missing Authentication via OAuth Dynamic Client Registration

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting th…

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.4 CRITICAL
CVE-2026-93291 — Improper certificate validation in Eufy Omni C20

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

Remote | Cryptography
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.8 MEDIUM
CVE-2026-93290 — Use of Hard-coded Credentials in Eufy Omni C20

Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.

| Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.0 CRITICAL
CVE-2026-93289 — OS command injection in Eufy Omni C20, Omni X10 Pro

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

| Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.0 HIGH
CVE-2026-88956 — Botslab G980H Dashcams Missing Authentication for Critical Function

The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password befor…

| Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.0 MEDIUM
CVE-2026-88761 — Botslab G980H Dashcams Use of Weak Credentials

The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within Wi…

| Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-85496 — Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent networ…

| Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-84399 — Botslab G980H Dashcams Incorrect Authorization

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with th…

| Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-82566 — Botslab G980H Dashcams Insufficient session expiration

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replace…

| Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.5 HIGH
CVE-2026-82372 — Improper handling of sensitive data during IPsec policy creation and modification in Broc…

Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals w…

sannav sannav | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.1 HIGH
CVE-2026-82164 — Dell Trusted Device Client Incorrect Permission Assignment Vulnerability

Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially …

| Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
Showing 20 of 14196 Results