CVE ID :CVE-2026-97363 Published : Oct. 2, 2026, 10:16 p.m. | 1 hour, 5 minutes ago Description :The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate…
CVE-2026-95102 – Monta monta.app Missing Authentication for Critical Function
CVE ID :CVE-2026-95102 Published : Oct. 2, 2026, 10:16 p.m. | 1 hour, 5 minutes ago Description :WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can…
CVE-2026-94593 – Armatura LLC Armatura One Insertion of Sensitive Information into Log File
CVE ID :CVE-2026-94593 Published : Oct. 2, 2026, 10:16 p.m. | 1 hour, 5 minutes ago Description :Armatura One’s backup and restore routine records the full database connection command, including the superuser password, in…
CVE-2026-94592 – Armatura LLC Armatura One Use of Hard-coded Credentials
CVE ID :CVE-2026-94592 Published : Oct. 2, 2026, 10:16 p.m. | 1 hour, 5 minutes ago Description :Armatura One’s database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation…
CVE-2026-94591 – Armatura LLC Armatura One Use of Hard-coded Cryptographic Key
CVE ID :CVE-2026-94591 Published : Oct. 2, 2026, 10:16 p.m. | 1 hour, 5 minutes ago Description :Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when…
CVE-2026-86345 – 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client’s authentication result
CVE ID :CVE-2026-86345 Published : Oct. 2, 2026, 12:17 a.m. | 1 hour, 2 minutes ago Description :A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a…
CVE-2026-103766 – ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Parameter
CVE ID :CVE-2026-103766 Published : Oct. 2, 2026, 12:16 a.m. | 1 hour, 3 minutes ago Description :ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to…
CVE-2026-103765 – Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server
CVE ID :CVE-2026-103765 Published : Oct. 2, 2026, 12:16 a.m. | 1 hour, 3 minutes ago Description :Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows…
CVE-2026-103764 – Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport
CVE ID :CVE-2026-103764 Published : Oct. 2, 2026, 12:16 a.m. | 1 hour, 3 minutes ago Description :Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to…
CVE-2026-103761 – Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue
CVE ID :CVE-2026-103761 Published : Oct. 1, 2026, 10:53 p.m. | 26 minutes ago Description :Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow…