Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.4 CRITICAL
CVE-2026-77179 — Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-f…

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a sy…

sandboxes | Path Traversal
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.1 HIGH
CVE-2026-16141 — OpenBMC IPMI Authentication Bypass via Default userKey and Stale Challenge Value

OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication obje…

Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.8 HIGH
CVE-2026-16140 — OpenBMC IPMI Privilege Escalation via Retargeted RAKP 1

OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining t…

Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-91835 — OpenClaw ClawScan File Classifier static_scanner.go IsBinaryFile interpretation conflict

A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The ma…

| Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.7 HIGH
CVE-2026-89025 — Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send…

Remote | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-46495 — OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-contr…

| Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-48722 — Nextflow: Incorrect default permissions in the nextflow auth login command

Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqer…

| Information Disclosure
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-49254 — Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1…

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/router.go registers GET /api/v1/oauth and GET /api/v1/oauth/:id without jwt.Middl…

| Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-54637 — Dragonfly scheduler v1 gRPC unauthenticated SSRF via attacker-controlled PeerHost in Down…

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduler's default unauthenticated v1 gRPC flow accepts attacker-controlled PeerHost.I…

| Server-Side Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.3 MEDIUM
CVE-2026-92082 — Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on…

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic a…

| Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-90650 — MotoPress Hotel Booking <= 6.2.4 - Unauthenticated Stored Cross-Site Scripting via Stripe…

The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient …

| Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92079 — Mitigation bypass in the Widget: Win32 component

Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

firefox | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92078 — Denial-of-service in the Security component

Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

firefox | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92077 — Denial-of-service in the SVG component

Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

firefox | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92076 — Incorrect boundary conditions in the Networking component

Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

firefox | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92075 — Mitigation bypass in the Networking component

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

firefox | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92074 — Mitigation bypass in the Popup Blocker component

Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

firefox | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.8 HIGH
CVE-2026-92073 — Privilege escalation in the Enterprise Policies component

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

firefox | Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92072 — Incorrect boundary conditions in the Safe Browsing component

Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

firefox | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92071 — Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

firefox | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
Showing 20 of 13095 Results