Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-105798 — SimpleChat: Stored XSS via group document filename in inline onclick handler

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.261.029, POST /api/group_documents/upload stores an attacker-contr…

| Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-105797 — SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary process spa…

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /…

| Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-105796 — Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP gen…

Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, al…

kiota | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-105795 — Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests

Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI de…

kiota | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.6 CRITICAL
CVE-2026-91140 — OS command injection in Progress Software Autonomous REST Connector GenAI Agents

An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attac…

Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.3 MEDIUM
CVE-2026-87975 — Privilege abuse in model formsets with editable primary keys

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.forms.models.BaseModelFormSet.save_existing_objects()` used the presence of a primary key on a sub…

django | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.9 MEDIUM
CVE-2026-87890 — Potential request forgery via spatial lookup byte values

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` v…

django | Remote | Server-Side Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.8 HIGH
CVE-2026-85523 — OS Command Injection in Felisify Informatics' SambaBox

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Felisify Information Technologies Industry and Trade Inc. SambaBox allows OS Command Inject…

Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.9 MEDIUM
CVE-2026-84429 — Potential denial-of-service vulnerability in HTTP header parsing

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to q…

django | Remote | Denial of Service
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.3 MEDIUM
CVE-2026-82924 — PII Enumeration via Missing Rate Limiting in Pusula Communication's Expert Mail

Improper Control of Interaction Frequency vulnerability in Pusula Communication, IT, and Internet Industry and Trade Co. Ltd. Expert Mail allows Brute Force. This issue affects Expert Mail: through …

Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-77178 — Oracle VM VirtualBox PCNet Network Device Out-of-Bounds Write Vulnerability

Oracle VM VirtualBox before 7.2.8 allows guest OS users to cause an out-of-bounds write in the host OS in pcnetReceiveNoSync in DevPCNet.cpp in the PCNet (Am79C970A) network device model.

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.9 MEDIUM
CVE-2026-77050 — Potential denial-of-service vulnerability in get_supported_language_variant()

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service a…

django | Remote | Denial of Service
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.1 MEDIUM
CVE-2026-34498 — Johnson Controls Illustra Standard OS Command Injection Vulnerability

Improper input validation vulnerability in Johnson Controls Illustra Standard - L4L China on Windows allows OS Command Injection. This issue affects Illustra Standard - L4L China: before 6.0.0.66394.

illustra_standard_-_l4l_china | Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.1 MEDIUM
CVE-2026-12380 — Reflected XSS in Akıllı Ticaret's E-Commerce Pack

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akıllı Ticaret Software Technologies Ltd. Co. E-Commerce Pack allows Reflected XSS. This issue a…

Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.9 MEDIUM
CVE-2026-106041 — Mooncake Store through 0.3.13.post1 Missing Authorization via NotifyOffloadSuccess RPC

Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSucces…

mooncake | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.8 HIGH
CVE-2026-106040 — Mooncake Store through 0.3.13.post1 Missing Authorization via EvictDiskReplica RPC

Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictD…

mooncake | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.9 MEDIUM
CVE-2026-106039 — Mooncake Store through 0.3.13.post1 Missing Authorization in Replication Task RPC

Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_r…

mooncake | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.8 HIGH
CVE-2026-106038 — Mooncake Store through 0.3.13.post1 Unauthenticated Object Deletion via Remove RPCs

Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object via Remove, RemoveByRegex, RemoveAll and Ba…

mooncake | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.8 CRITICAL
CVE-2026-106037 — Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call…

mooncake | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.3 MEDIUM
CVE-2026-106026 — tftp-hpa 5.4 before 6.0 Out-of-Bounds Read via tftpd Remap Jump Rule

tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send …

tftp-hpa tftp-hpa | Remote | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 14909 Results