Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-90487 — Xuxueli xxl-job JobGroupController.java privileges management

A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupCo…

xxl-job | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
0.0 NA
CVE-2026-90486 — openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgery

A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/l…

| Server-Side Request Forgery
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.1 CRITICAL
CVE-2026-90647 — Kalkitech ASE2000 Improper Certificate Validation Vulnerability

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a net…

Remote | Misconfiguration
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
3.5 LOW
CVE-2026-79300 — SEP sesam Improper Authorization and MFA Bypass Vulnerability

SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active D…

Remote | Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.5 MEDIUM
CVE-2026-90485 — IOBit Uninstaller IOCTL Dispatch IURegistryFilter.sys sub_11838 null pointer dereference

A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation caus…

uninstaller | Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
7.4 HIGH
CVE-2026-90616 — Flatpak Sandbox Escape via Symlink Race Condition

In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulner…

| Path Traversal
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.8 HIGH
CVE-2026-90560 — zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictDecompress

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictiona…

Remote | Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.7 HIGH
CVE-2026-90559 — snappy-java through 1.1.10.8 Out-of-Bounds Write via uncompress

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed siz…

snappy-java | Remote | Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.8 CRITICAL
CVE-2026-90558 — sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets…

sngrep | Remote | Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90557 — Freeciv 3.1.0 through 3.2.5 Out-of-Bounds Read via Savegame

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a ma…

| Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.5 HIGH
CVE-2026-90556 — Freeciv before 3.2.6 Heap Buffer Overflow via worklist_load

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers…

| Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
7.1 HIGH
CVE-2026-90555 — vLLM before 0.28.0 Denial of Service via Audio Header

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC header…

vllm vllm | Remote | Denial of Service
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90554 — vLLM before 0.28.0 Denial of Service via audio extraction

vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _extract_audio_from_v…

vllm vllm | Denial of Service
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.5 HIGH
CVE-2026-90553 — vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers…

vllm vllm | Supply Chain
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-90552 — WWBN AVideo Missing Authorization via Playlists_schedules list.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authen…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90551 — WWBN AVideo Missing Authorization via video_from_program API

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist co…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90550 — WWBN AVideo Missing Authorization via mediaSession.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticate…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90549 — WWBN AVideo Missing Authorization via videosAndroid.json.php Endpoint

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protect…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90548 — WWBN AVideo Missing Authorization in ImageGallery list.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery file…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90547 — WWBN AVideo Missing Authorization via getBookmarks.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to rea…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
Showing 20 of 13190 Results