Common Vulnerabilities and Exposures (CVE)

CVE-2026-73976

Oct 1, 2026 17:58:15 UTC

djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queri...

CVE-2026-17176

Oct 1, 2026 17:55:21 UTC

An OS command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may...

CVE-2026-19730

Oct 1, 2026 17:54:56 UTC

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default ...

CVE-2026-77387

Oct 1, 2026 17:50:39 UTC

geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without t...

CVE-2026-102294

Oct 1, 2026 17:48:24 UTC

TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 Gateway value is improperly incorporated into a system command, allowing an authenticated administrator to execute ...

CVE-2026-102369

Oct 1, 2026 17:42:25 UTC

Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to obtain ...

CVE-2026-78578

Oct 1, 2026 17:42:05 UTC

Tapo C120 v1 and C200 v5 do not enforce authentication for do method HTTPS onboarding connect actions after initial setup.  An unauthenticated adjacent attacker can submit unauthorized wireless configuration parameters, causing the camera t...

CVE-2026-78577

Oct 1, 2026 17:41:49 UTC

Tapo C120 v1 and C200 V5 contain a vulnerability in the HTTPS onboarding scan function due to missing authentication. After initial setup, an unauthenticated attacker on the same local network can invoke the scan action and retrieve nearby ...

CVE-2026-9032

Oct 1, 2026 17:41:31 UTC

Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser.  The interface is reachable without authentication after initial setup and does not validate that a password field is present for ce...

CVE-2026-48710

Oct 1, 2026 17:41:26 UTC

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `req...

CVE-2026-104018

Oct 1, 2026 17:41:04 UTC

An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 all versions up to 26.09. when configured to enforce per-user command privileges. Under certain shell operations, a command may be ...

CVE-2026-96658

Oct 1, 2026 17:37:51 UTC

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an atta...

CVE-2026-103923

Oct 1, 2026 17:37:47 UTC

KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for the renderer options object, the trust setting, default and processor setting me...

CVE-2026-8037

Oct 1, 2026 17:36:58 UTC

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpo...

CVE-2026-68496

Oct 1, 2026 17:36:57 UTC

The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongF...