Common Vulnerabilities and Exposures (CVE)

CVE-2026-104076

Oct 9, 2026 11:54:48 UTC

TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing authentication vulnerability that allows remote unauthenticated attackers to read sensitive device information and modify device configuration v...

CVE-2026-19498

Oct 9, 2026 11:54:14 UTC

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.

CVE-2026-78406

Oct 9, 2026 11:53:45 UTC

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

CVE-2026-62036

Oct 9, 2026 11:53:29 UTC

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in AREOI All Bootstrap Blocks all-bootstrap-blocks allows Retrieve Embedded Sensitive Data.This issue affects All Bootstrap Blocks: from n/a through 1....

CVE-2026-12109

Oct 9, 2026 11:52:32 UTC

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow an attacker with administrative privileges and access to the local management interface to execute arbitrary code due to an unbo...

CVE-2026-82334

Oct 9, 2026 11:52:11 UTC

IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol parser. A remote attacker could send a specially crafted TDS LOGIN7 packet containing invalid offset or length values...

CVE-2026-102368

Oct 9, 2026 11:51:35 UTC

Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware.  Successful ...

CVE-2026-79842

Oct 9, 2026 11:51:12 UTC

An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713

CVE-2026-107318

Oct 9, 2026 11:50:42 UTC

@fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. In versions prior to 12.7.0, all of the built-in HTTPS transports override the secure default and set rejectUnauthorized to false, so the pr...

CVE-2026-107778

Oct 9, 2026 11:50:03 UTC

MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer dereference in make_cred_list() in rd_cred.c that allows authenticated Kerberos clients to crash services by sending mismatched KRB-CRED arrays. Attackers can send forwarded crede...

CVE-2026-106435

Oct 9, 2026 11:49:28 UTC

The MongoDB Python Driver's binary accelerator can read outside a buffer when an application decodes malformed BSON containing a truncated regular-expression element without a trailing NUL byte. An actor who can supply BSON to the documente...

CVE-2026-107395

Oct 9, 2026 11:49:03 UTC

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, an authenticated user can misuse the legacy session export API to retrieve details for a restricted session wi...

CVE-2026-107390

Oct 9, 2026 11:47:21 UTC

music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the MP4 parser accepts an attacker-controlled 64-bit extended atom size, converts it to a JavaScript Number, and uses the resulting payload length for at...

CVE-2026-84250

Oct 9, 2026 11:46:20 UTC

IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain ro...

CVE-2026-39779

Oct 9, 2026 11:45:43 UTC

Missing Authorization vulnerability in Asgaros Asgaros Forum asgaros-forum allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asgaros Forum: from n/a through 3.4.0.