CVE ID :CVE-2026-102361 Published : Sept. 29, 2026, 12:17 a.m. | 13 minutes ago Description :mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to…
CVE-2026-101264 – Ziroom ZHOME A0101 set_passwd command injection
CVE ID :CVE-2026-101264 Published : Sept. 29, 2026, 12:17 a.m. | 13 minutes ago Description :A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd….
CVE-2026-101263 – Ziroom ZHOME A0101 set_online_client command injection
CVE ID :CVE-2026-101263 Published : Sept. 29, 2026, 12:17 a.m. | 13 minutes ago Description :A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file…
CVE-2026-102334 – Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection
CVE ID :CVE-2026-102334 Published : Sept. 28, 2026, 11:17 p.m. | 1 hour, 13 minutes ago Description :Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password…
CVE-2026-101262 – Ziroom ZHOME A0101 set_online_client command injection
CVE ID :CVE-2026-101262 Published : Sept. 28, 2026, 11:17 p.m. | 1 hour, 13 minutes ago Description :A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the…
CVE-2026-100886 – Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication
CVE ID :CVE-2026-100886 Published : Sept. 27, 2026, 11:16 p.m. | 1 hour, 8 minutes ago Description :A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an…
CVE-2026-101090 – Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri
CVE ID :CVE-2026-101090 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional…
CVE-2026-101084 – obot before v0.21.1 Authorization Bypass via /mcp-connect
CVE ID :CVE-2026-101084 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated…
CVE-2026-101065 – Obot Quickstart Docker Deployment Unauthenticated Admin Access
CVE ID :CVE-2026-101065 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the…
CVE-2026-101064 – Obot before v0.23.0 Server-Side Request Forgery via MCP
CVE ID :CVE-2026-101064 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged…