Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-88097 — Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

None

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-61670 — microsandbox: Secret values exposed in world-readable process arguments

microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs serializes NetworkConfig secret values into the --network-config argument and pa…

| Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-68928 — Acode: Exported TerminalService (bundled terminal plugin) lets any installed app execute …

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.x…

| Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-85271 — Open edX Platform: Stored CSS Injection in Email Digest Notifications via Unsanitized Thr…

Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawood.1, the add_additional_attributes_to_notifications function in openedx/core/d…

| Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
2.3 LOW
CVE-2026-93894 — Vinyl Cache Workspace Buffer Overflow

In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to …

varnish_cache vinyl_cache | Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-85272 — Open edX Platform: Path traversal via prefix-bypass in safe_extractall Path Validation

Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate safe_ex…

| Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-71855 — Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 and IPv6 flow as equ…

suricata | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-71418 — Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs ret…

suricata | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-57223 — Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escala…

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and parameter-update …

suricata | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-63446 — Suricata app-layer: passed flows can retain transactions, causing resource exhaustion

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-…

suricata | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-63447 — Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue alloca…

suricata | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-63448 — Suricata smb: some SMB flows can cause resource exhaustion

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-completed transactions…

suricata | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-57229 — Suricata smtp/mime: incomplete state reset allows detection bypass

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fu…

suricata | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-57225 — Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-context-json.c assumes that a configured JSO…

suricata | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.3 MEDIUM
CVE-2026-93873 — Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controll…

Remote | Cross-Site Request Forgery
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.7 HIGH
CVE-2026-93872 — Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instan…

Remote | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.4 MEDIUM
CVE-2026-93871 — Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary …

Remote | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.3 MEDIUM
CVE-2026-93870 — Cotonti through 1.0.0 Cross-Site Request Forgery in the Ratings Plugin AJAX Handler

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers can craft malicious pages …

Remote | Cross-Site Request Forgery
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.1 MEDIUM
CVE-2026-93869 — Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attacker…

Remote | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.2 CRITICAL
CVE-2026-93868 — Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Un…

Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
Showing 20 of 14461 Results