Common Vulnerabilities and Exposures (CVE)

CVE-2026-93965

Sep 20, 2026 05:45:10 UTC

A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of the argument endpoint_or_command causes ...

CVE-2026-93964

Sep 20, 2026 05:30:17 UTC

A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results...

CVE-2026-93963

Sep 20, 2026 05:15:07 UTC

A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the argument DEPTID leads to sql injection. The atta...

CVE-2026-93962

Sep 20, 2026 05:00:11 UTC

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead ...

CVE-2026-93961

Sep 20, 2026 04:45:09 UTC

A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api/UserController.java of the component UserController. Perfor...

CVE-2026-88097

Sep 20, 2026 03:55:51 UTC

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

CVE-2026-86553

Sep 20, 2026 03:17:20 UTC

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /a...

CVE-2026-86552

Sep 20, 2026 03:01:00 UTC

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary...

CVE-2026-93960

Sep 20, 2026 03:00:19 UTC

A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of the component OAuth Scope Handler. Such manipulation of the argument ID leads to mi...

CVE-2026-93959

Sep 20, 2026 02:30:14 UTC

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Course...

CVE-2026-86551

Sep 20, 2026 01:55:32 UTC

The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.

CVE-2026-94084

Sep 20, 2026 01:20:20 UTC

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

CVE-2026-94083

Sep 20, 2026 01:18:05 UTC

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This r...

CVE-2026-93958

Sep 20, 2026 01:15:12 UTC

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can ...

CVE-2026-93957

Sep 20, 2026 01:00:10 UTC

A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleFilter of the file src/SearchEngine.php of the component Filter Matching. The manipulation leads to incorrect comparison....