CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Sep 9, 2026
Aug 18, 2026
7.6 HIGH· v4
N/A· v3
N/A· v2
@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-level @authentication rule is also present on the same operation type. Wh...Show more
@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-level @authentication rule is also present on the same operation type. When both a type-level @authentication (on Query/Mutation) and a field-level @authentication (on a root custom-resolver field within that type) are declared, only the type-level rule is evaluated and the field-level rule is silently discarded. As a result a stricter per-field requirement — such as an admin-role JWT claim (jwt: { roles_INCLUDES: "admin" }) — is never checked, and any client that satisfies the coarser type-level requirement can invoke the more-restricted field. No token forgery is involved: a legitimately issued, correctly signed non-admin token (e.g. roles: ["user"]) is sufficient.Show less
-
-
Sep 9, 2026
Aug 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowle...Show more
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.Show less
-
-
Sep 9, 2026
Aug 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer pay...Show more
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session.Show less
-
-
Sep 9, 2026
Aug 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets.
1Ibm
1I
Sep 9, 2026
Sep 4, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser.
1Commvault
1Commvault
Sep 9, 2026
Sep 8, 2026
8.3 HIGH· v4
7.5 HIGH· v3
N/A· v2
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
1Commvault
1Commvault
Sep 9, 2026
Sep 8, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
1Commvault
1Commvault
Sep 9, 2026
Sep 8, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
1Commvault
1Commvault
Sep 9, 2026
Sep 8, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
1Commvault
1Commvault
Sep 9, 2026
Aug 11, 2026
8.8 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance rele...Show more
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.Show less
-
-
Sep 9, 2026
Aug 28, 2026
N/A· v4
7.6 HIGH· v3
N/A· v2
In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An...Show more
In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.Show less
-
-
Sep 9, 2026
Aug 28, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve rem...Show more
A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.Show less
-
-
Sep 9, 2026
Aug 28, 2026
N/A· v4
8.3 HIGH· v3
N/A· v2
openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.
-
-
Sep 9, 2026
Aug 28, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.
1Commvault
1Commvault
Sep 9, 2026
Aug 11, 2026
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webse...Show more
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.Show less
-
-
Sep 9, 2026
Sep 1, 2026
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to cause a denial of service via the libavformat/iamf_writer.c component
-
-
Sep 9, 2026
Aug 28, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
-
-
Sep 9, 2026
Aug 28, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.
-
-
Sep 9, 2026
Aug 28, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.
-
-
Sep 9, 2026
Aug 28, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
-
-
Sep 9, 2026
Aug 28, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
1Ibm
1I
Sep 9, 2026
Sep 4, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow.
1Commvault
1Commvault
Sep 9, 2026
Sep 8, 2026
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
-
-
Sep 9, 2026
Aug 7, 2026
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining...Show more
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matching and are decoded only once they reach the handler, restoring the traversal at the filesystem call. An unauthenticated remote attacker can therefore read any file readable by the application process, including the process environment, which exposes the JWT signing secret, the database connection string, and connected provider and billing secrets. Because session tokens are signed with that secret and carry no expiry, this allows forging a non-expiring session as any user, including an administrator, without a password.Show less
-
-
Sep 9, 2026
Aug 6, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on...Show more
An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/lifetime-deal (LTD) redemption codes, an unauthenticated attacker can forge valid redemption tokens or replay existing single-use codes to activate permanent, tier-highest paid subscriptions without a financial transaction.Show less