Common Vulnerabilities and Exposures (CVE)

CVE-2026-28745

Oct 9, 2026 14:36:22 UTC

Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.

CVE-2026-107797

Oct 9, 2026 14:36:08 UTC

Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject script via the to and tag parameters. Attackers can send crafted links to authenticated users...

CVE-2026-108108

Oct 9, 2026 14:33:31 UTC

PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::chap_verify() returns true when the supplied response does not match. Attackers who know a valid customer or PPPoE us...

CVE-2026-108106

Oct 9, 2026 14:33:29 UTC

Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to S...

CVE-2026-108104

Oct 9, 2026 14:33:28 UTC

Xerial snappy-java from 1.1.7.4 before 1.1.10.10 contains a double release vulnerability in SnappyFramedInputStream that returns pooled buffers twice when replacement allocation fails. Attackers can supply framed data with a large declared ...

CVE-2026-32645

Oct 9, 2026 14:33:04 UTC

Default factory credentials with administrative access are enabled and persist even after configuring other administrator accounts.

CVE-2026-107720

Oct 9, 2026 14:32:14 UTC

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.1, fast-jwt createVerifier accepts an unsigned JWT when key is an empty string or null and algorithms is a non-empty allowlist. Falsy synchronous keys bypass prepareKe...

CVE-2026-39460

Oct 9, 2026 14:30:47 UTC

Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the devi...

CVE-2026-105269

Oct 9, 2026 14:30:43 UTC

Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability. An authenticated user with Network Operator privileges could store untrusted content that is rendered without adequate neutralization. Success...

CVE-2026-84032

Oct 9, 2026 14:30:09 UTC

IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation.

CVE-2026-104115

Oct 9, 2026 14:24:52 UTC

A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. get_fs_locations() in usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, part of the nfs-basic reparse plugin, copies the host ...

CVE-2026-49243

Oct 9, 2026 14:20:04 UTC

Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-contr...

CVE-2026-103065

Oct 9, 2026 14:15:55 UTC

Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.

CVE-2026-108103

Oct 9, 2026 14:08:13 UTC

Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_dropped_dl_traffic_threshold() that allows remote unauthenticated attackers to read past IE buffers via short IEs. Attackers can send PFCP Session Esta...

CVE-2026-108101

Oct 9, 2026 14:08:08 UTC

HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload ...