Vulnerabilities
Vulnerable Software
Security Vulnerabilities
NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
CVSS Score
7.8
EPSS Score
0.004
Published
2026-09-22
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bulk reactions endpoint which allows an authenticated user to cause excessive database load via a crafted request to {{POST /api/v4/posts/ids/reactions}}.. Mattermost Advisory ID: MMSA-2026-00771
CVSS Score
4.3
EPSS Score
0.004
Published
2026-09-22
CVE-2026-93616
Known exploited
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
CVSS Score
9.8
EPSS Score
0.197
Published
2026-09-22
Privilege escalation due to weak configuration during package extraction process.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-09-22
Privilege escalation due to weak configuration while temporary file handling.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-09-22
Improper authorization leads to Remote Code Execution via SocketIO interface.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-09-22
Exposed dangerous function lead to privilege escalation via gRPC server.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-09-22
Memory corruption while processing a crafted ELF file in the Primary Bootloader.
CVSS Score
6.9
EPSS Score
0.001
Published
2026-09-22
CVE-2026-93952
Known exploited
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.
CVSS Score
9.5
EPSS Score
0.011
Published
2026-09-22
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of varying lengths, causing the decode worker to terminate and become unavailable until restarted.
CVSS Score
8.7
EPSS Score
0.006
Published
2026-09-21


Contact Us

Shodan ® - All rights reserved