Common Vulnerabilities and Exposures (CVE)

CVE-2026-102720

Sep 29, 2026 17:46:23 UTC

A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received message. The option walk keeps a pointer and an offset in step, and the only bound check uses the...

CVE-2026-12345

Sep 29, 2026 17:46:01 UTC

The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or...

CVE-2026-57443

Sep 29, 2026 17:45:46 UTC

SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpo...

CVE-2026-102719

Sep 29, 2026 17:45:21 UTC

Predictable DTLS HelloVerifyRequest Cookie in NetX Secure

CVE-2026-102718

Sep 29, 2026 17:44:43 UTC

hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP p...

CVE-2026-102716

Sep 29, 2026 17:43:55 UTC

An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests that carry a Session header the parser cannot convert. The Session branch returns the raw NetX error code instead of an RTSP status code...

CVE-2026-102677

Sep 29, 2026 17:43:26 UTC

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched...

CVE-2026-90917

Sep 29, 2026 17:43:17 UTC

Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories.

CVE-2026-102715

Sep 29, 2026 17:42:35 UTC

Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, ...

CVE-2026-71483

Sep 29, 2026 17:42:24 UTC

Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and...

CVE-2026-102714

Sep 29, 2026 17:41:28 UTC

`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is no...

CVE-2026-102713

Sep 29, 2026 17:40:40 UTC

The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not against the protocol maximum of 4 + N...

CVE-2026-102712

Sep 29, 2026 17:39:31 UTC

On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated peer drives an OOB source...

CVE-2026-100418

Sep 29, 2026 17:39:22 UTC

Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and i...

CVE-2026-102711

Sep 29, 2026 17:38:22 UTC

Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image le...