Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-82566 — Botslab G980H Dashcams Insufficient session expiration

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replace…

| Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.5 HIGH
CVE-2026-82372 — Improper handling of sensitive data during IPsec policy creation and modification in Broc…

Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals w…

sannav sannav | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.1 HIGH
CVE-2026-82164 — Dell Trusted Device Client Incorrect Permission Assignment Vulnerability

Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially …

| Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.6 HIGH
CVE-2026-77967 — Botslab G980H Dashcams Authentication Bypass by Capture-replay

The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with a…

| Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.4 MEDIUM
CVE-2026-48543 — Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.j…

Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.4 MEDIUM
CVE-2026-48542 — Krayin CRM 2.2.6 Stored Template Injection XSS via Product Name Field

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.j…

Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.4 MEDIUM
CVE-2026-48541 — Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.j…

Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.4 MEDIUM
CVE-2026-48540 — Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.j…

Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-97323 — YunaiV/zhijiantianya ruoyi-vue-pro File Upload MpMaterialServiceImpl.java getOriginalFile…

A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/…

ruoyi-vue-pro ruoyi-vue-pro | Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.0 MEDIUM
CVE-2026-97322 — YunaiV/zhijiantianya ruoyi-vue-pro File Upload FileController.java cross site scripting

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/a…

ruoyi-vue-pro ruoyi-vue-pro | Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-97321 — YunaiV/zhijiantianya ruoyi-vue-pro GoView Data Endpoint GoViewDataServiceImpl.java GoView…

A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yudao-module-report/src/main/ja…

ruoyi-vue-pro ruoyi-vue-pro | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-97320 — YunaiV/zhijiantianya ruoyi-vue-pro AI Knowledge AiKnowledgeDocumentServiceImpl.java AiKno…

A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java …

ruoyi-vue-pro ruoyi-vue-pro | Remote | Server-Side Request Forgery
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.4 HIGH
CVE-2026-96749 — Heap out-of-bounds write via signed size overflow in BSON document encoding

An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-…

python_driver | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.3 HIGH
CVE-2026-96748 — Connection redirection via percent-encoded delimiter injection in connection string hosts

PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by…

python_driver | Remote | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.3 MEDIUM
CVE-2026-96747 — Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encryp…

The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A…

python_driver | Remote | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.8 HIGH
CVE-2026-89325 — Rapid7 Insight Agent: Uncontrolled search path element in InsightVM assessment content le…

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable…

insight_agent | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.3 CRITICAL
CVE-2026-86860 — Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform

ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, t…

Remote | Authorization
Sep 24, 2026 Sep 25, 2026
Sep 24, 2026
Sep 25, 2026
8.7 HIGH
CVE-2026-86859 — Unauthenticated Arbitrary Record Disclosure in ServiceNow AI Platform

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access d…

Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.7 HIGH
CVE-2026-86858 — Unauthenticated Privilege Escalation via GraphQL in ServiceNow AI Platform

ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstanc…

Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.4 HIGH
CVE-2026-86857 — Authorization Bypass in ServiceNow AI Platform

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access dat…

Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
Showing 20 of 14199 Results