Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.6 CRITICAL
CVE-2026-87911 — Read-only enforcement bypass enabling operating system command execution in the SQL valid…

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operat…

Remote | Injection
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-79323 — Magefan Blog GraphQL Information Disclosure

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog comm…

| Information Disclosure
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-79322 — Mageplaza Blog for Magento SQL Injection

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands …

| Injection
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
4.3 MEDIUM
CVE-2026-61907 — Cyrus IMAP JMAP Snooze Access Control Bypass

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause inse…

cyrus_imap | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
9.6 CRITICAL
CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin…

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escal…

Remote | Cross-Site Scripting
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-52482 — SJRC F11 SJ-GPS-PRO Information Disclosure Vulnerability

An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service spawns /app/sh_for_telnet

| Information Disclosure
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.5 MEDIUM
CVE-2026-39020 — Wings3D Denial of Service Vulnerability

An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file

| Denial of Service
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.5 MEDIUM
CVE-2025-51619 — Thesycon DPC Latency Checker Kernel Memory Corruption Denial of Service

A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause a denial-of-service (BSOD) condition on Windows systems. The driver exposes an…

| Memory Corruption
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-73789 — Unauthenticated Insecure Parameter Manipulation allows Data Tampering In CPPM Web Interfa…

A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation …

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
6.5 MEDIUM
CVE-2026-73788 — Privilege Escalation in ClearPass OnGuard Agent

A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.2 HIGH
CVE-2026-73787 — Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web Interface

A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execu…

Remote | Path Traversal
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.5 HIGH
CVE-2026-73786 — Unauthenticated Network-Based Denial of Service in CPPM systems

A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attack…

Remote | Denial of Service
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.2 HIGH
CVE-2026-73769 — Authenticated Remote Code Execution in CPPM Web Interface

A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an …

Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.6 HIGH
CVE-2026-8044 — [Product/Vendor Name] Argument Injection Vulnerability

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when ma…

Remote | Injection
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
9.2 CRITICAL
CVE-2026-87930 — MaxSite CMS through 109.6 PHP Object Injection via ci_session

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies…

cms | Remote | Information Disclosure
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-87929 — MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge adminis…

cms | Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-87928 — MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page

MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML co…

cms | Remote | Cross-Site Scripting
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.8 HIGH
CVE-2026-87927 — MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supply…

cms | Remote | Path Traversal
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
3.0 LOW
CVE-2026-87876 — Cups: openprinting cups: remaining case-insensitive username matching in scheduler side p…

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of us…

Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
4.3 MEDIUM
CVE-2026-87875 — Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-…

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNM…

Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
Showing 20 of 13992 Results