Common Vulnerabilities and Exposures (CVE)

CVE-2026-95843

Sep 23, 2026 17:58:06 UTC

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} structure...

CVE-2026-93307

Sep 23, 2026 17:53:54 UTC

A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack ca...

CVE-2026-93739

Sep 23, 2026 17:50:46 UTC

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be perfor...

CVE-2026-95958

Sep 23, 2026 17:49:25 UTC

A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing a manipulation of the argument BlockSize results in integer ...

CVE-2026-96757

Sep 23, 2026 17:48:29 UTC

orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications that...

CVE-2026-95927

Sep 23, 2026 17:47:52 UTC

A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument test_id leads to ...

CVE-2026-19267

Sep 23, 2026 17:47:30 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cau...

CVE-2026-18505

Sep 23, 2026 17:46:14 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to red...

CVE-2026-88840

Sep 23, 2026 17:45:34 UTC

BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.

CVE-2026-88839

Sep 23, 2026 17:45:33 UTC

BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.

CVE-2026-88837

Sep 23, 2026 17:45:31 UTC

BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.

CVE-2026-88835

Sep 23, 2026 17:45:27 UTC

BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.

CVE-2026-88831

Sep 23, 2026 17:45:23 UTC

BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.

CVE-2026-16118

Sep 23, 2026 17:45:04 UTC

A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data loc...

CVE-2026-86867

Sep 23, 2026 17:44:52 UTC

Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pages/...