CVE ID :CVE-2026-86345 Published : Oct. 2, 2026, 12:17 a.m. | 1 hour, 2 minutes ago Description :A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a…
CVE-2026-103766 – ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Parameter
CVE ID :CVE-2026-103766 Published : Oct. 2, 2026, 12:16 a.m. | 1 hour, 3 minutes ago Description :ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to…
CVE-2026-103765 – Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server
CVE ID :CVE-2026-103765 Published : Oct. 2, 2026, 12:16 a.m. | 1 hour, 3 minutes ago Description :Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows…
CVE-2026-103764 – Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport
CVE ID :CVE-2026-103764 Published : Oct. 2, 2026, 12:16 a.m. | 1 hour, 3 minutes ago Description :Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to…
CVE-2026-103761 – Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue
CVE ID :CVE-2026-103761 Published : Oct. 1, 2026, 10:53 p.m. | 26 minutes ago Description :Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow…
CVE-2026-103760 – Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write
CVE ID :CVE-2026-103760 Published : Oct. 1, 2026, 10:53 p.m. | 26 minutes ago Description :Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block…
CVE-2026-71452 – Johnson Controls EasyIO FS32 OS Command Injection
CVE ID :CVE-2026-71452 Published : Oct. 1, 2026, 10:17 p.m. | 1 hour, 2 minutes ago Description :– OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects…
CVE-2026-71449 – Johnson Controls EasyIO FS32 Hard-coded Cryptographic Key Vulnerability
CVE ID :CVE-2026-71449 Published : Oct. 1, 2026, 10:17 p.m. | 1 hour, 2 minutes ago Description :: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive…
CVE-2026-18397 – SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability
CVE ID :CVE-2026-18397 Published : Oct. 1, 2026, 10:17 p.m. | 1 hour, 2 minutes ago Description :This vulnerability enables unauthenticated remote code execution (RCE) on a victim’s machine by exploiting a combination of…
CVE-2026-103591 – DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/file
CVE ID :CVE-2026-103591 Published : Sept. 30, 2026, 11:16 p.m. | 1 hour, 23 minutes ago Description :DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via…