Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.2 CRITICAL
CVE-2026-97404 — OpenStack Zaqar Authentication Bypass Vulnerability

In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target pr…

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.7 HIGH
CVE-2026-97362 — HFS2 2.4.0 Unauthenticated Denial of Service via Hung Serving Thread

HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted req…

Remote | Denial of Service
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.0 MEDIUM
CVE-2026-97224 — Excalidraw Imported File restore.ts cross site scripting

A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file packages/excalidraw/data/restore.ts of the component Imported File Handler. Performing…

Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.1 HIGH
CVE-2026-90959 — Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enab…

A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to d…

Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.2 CRITICAL
CVE-2026-90481 — PortSwigger Burp Suite Authentication Bypass

In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-88351 — MPack Node API Integer Overflow to Heap-Based Buffer Overflow

An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large eleme…

| Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.1 HIGH
CVE-2026-82094 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.

datastage_on_cloud_pak_for_data | Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-82093 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.

datastage_on_cloud_pak_for_data | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-81552 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.

datastage_on_cloud_pak_for_data | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.6 CRITICAL
CVE-2026-81549 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.

datastage_on_cloud_pak_for_data | Remote | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-81548 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

datastage_on_cloud_pak_for_data | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-81547 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.

datastage_on_cloud_pak_for_data | Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-81545 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

datastage_on_cloud_pak_for_data | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.8 HIGH
CVE-2026-81539 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

datastage_on_cloud_pak_for_data | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.6 HIGH
CVE-2026-77874 — IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements,…

enterprise_build_of_quarkus | Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.9 MEDIUM
CVE-2026-77825 — IBM ContextForge MCP Gateway is affected by path traversal

IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()…

contextforge_mcp_gateway | Remote | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.9 MEDIUM
CVE-2026-77707 — TLS Certificate Validation Disabled for Keycloak Connections in HAVELSAN's Liman Render E…

Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75.

Remote | Cryptography
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.9 MEDIUM
CVE-2026-77703 — SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine

Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75.

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
2.9 LOW
CVE-2026-73064 — Mbed TLS TLS 1.3 Entropy Source Failure Stream Injection Vulnerability

In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 serv…

mbed_tls | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.2 MEDIUM
CVE-2026-6544 — Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surfac…

concert | Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
Showing 20 of 14338 Results