Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.7 MEDIUM
CVE-2026-101061 — utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass

utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable p…

python-utcp | Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.4 HIGH
CVE-2026-101060 — python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects

python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-…

python-utcp | Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101059 — utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass

utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim regis…

python-utcp | Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101058 — python-utcp before 1.1.12 SSRF via Remote HTTP Manual

python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface when that manual is discovered f…

python-utcp | Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.1 LOW
CVE-2026-101057 — utcp-mcp before 1.1.3 SSRF via unvalidated MCP server URL

utcp-mcp (the MCP plugin of python-utcp) through 1.1.2 connects to the HTTP and WebSocket MCP server URLs given in a call template's mcpServers configuration without the ensure_secure_url validation …

python-utcp | Remote | Misconfiguration
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.9 MEDIUM
CVE-2026-101056 — Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint

Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to …

Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.1 LOW
CVE-2026-101051 — Cloudreve before 4.16.1 Path Traversal via Remote Download

Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers can ex…

Remote | Path Traversal
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
5.4 MEDIUM
CVE-2026-101048 — Cloudreve before 4.17.0 SSRF via Admin.Read OAuth scope

Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) without requiring the Admin.Write OAuth scope, unli…

Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.9 MEDIUM
CVE-2026-101047 — Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLs

Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Appl…

fleet | Remote | Information Disclosure
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.1 LOW
CVE-2026-101046 — Fleet before 4.89.0 SQL Injection via ORDER BY Activity Endpoints

Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities). The deprecated cursor-pagination…

fleet | Remote | Injection
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.9 HIGH
CVE-2026-101045 — Fleet Homebrew Cask OS Command Injection via Metadata

Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some in…

fleet | Remote | Injection
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101044 — pacquet before 12.0.0-alpha.5 Path Traversal via lockfile alias

pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lockfile before u…

Remote | Path Traversal
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.3 HIGH
CVE-2026-101043 — pnpm 11.0.0 before 11.11.0 Environment Variable Exfiltration via Proxy Settings

pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.y…

Remote | Misconfiguration
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-100873 — mathurvishal CloudClassroom-PHP-Project cross-site request forgery

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function. The manipulation results in cross-…

| Cross-Site Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.8 HIGH
CVE-2026-88778 — TCP Initial Sequence Number (ISN) prediction

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS,…

Remote | Information Disclosure
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.8 HIGH
CVE-2026-88777 — Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of…

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.…

Remote | Memory Corruption
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.8 HIGH
CVE-2026-88776 — Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of…

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1…

Remote | Memory Corruption
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.8 HIGH
CVE-2026-88775 — Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of…

Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS …

Remote | Memory Corruption
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.0 HIGH
CVE-2026-88774 — Feature policy bypass due to improper HTTP URL based expression usage

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gatew…

Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.3 CRITICAL
CVE-2026-88773 — HTTP Request Smuggling

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before…

Remote | Misconfiguration
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
Showing 20 of 14199 Results