Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-100892 — aligungr UERANSIM nr-gnb handler.cpp ULInformationTransfer memory corruption

A vulnerability was found in aligungr UERANSIM up to 3.3.0. This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.cpp of the component nr-gnb. Performing a manipulation of t…

ueransim | Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-100891 — Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opendma…

A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of t…

opendmarc opendmarc | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.5 MEDIUM
CVE-2026-100890 — Trusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv6_explode nu…

A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the com…

opendmarc opendmarc | Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-100895 — Trusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer dere…

A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. …

| Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-100894 — mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection

A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The m…

| Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-100893 — Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request…

A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse E…

| Server-Side Request Forgery
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-100889 — Trusted Domain Project OpenDKIM Decoder util.c dkim_qp_decode off-by-one

A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-o…

opendkim | Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-100888 — Trusted Domain Project OpenDKIM DKIM Signature Header Selection dkim-canon.c dkim_canon_s…

A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature He…

opendkim | Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-100887 — amirsanni Mini-Inventory-and-Sales-Management-System Database Query Builder DB_query_buil…

A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file D…

Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
2.5 LOW
CVE-2026-96284 — Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci sym…

A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when impor…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
10.0 CRITICAL
CVE-2026-100886 — Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication

A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads…

t8232 t8108 t8116 t8108p | Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.5 HIGH
CVE-2026-100885 — Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization

A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-se…

laravel-crm | Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
4.3 MEDIUM
CVE-2026-100884 — Krayin laravel-crm attachment-download Endpoint acl.php resource injection

A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachme…

laravel-crm | Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.5 MEDIUM
CVE-2026-100883 — Krayin laravel-crm acl.php access control

A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to imprope…

laravel-crm | Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.3 LOW
CVE-2026-96283 — Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongo…

By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to s…

enterprise_linux enterprise_linux | Denial of Service
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.1 LOW
CVE-2026-96282 — Flatpak: flatpak: extension metadata path traversal file existence oracle

A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications us…

enterprise_linux flatpak enterprise_linux | Remote | Path Traversal
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.3 LOW
CVE-2026-100882 — Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting

A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the compone…

laravel-crm | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
2.6 LOW
CVE-2026-100881 — zhistaredu StarTraining application.yml cross site scripting

A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enable…

startraining | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.2 MEDIUM
CVE-2026-96281 — Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system ap…

On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper Rem…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.5 HIGH
CVE-2026-96280 — Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent ope…

enterprise_linux flatpak enterprise_linux | Remote | Memory Corruption
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
Showing 20 of 14029 Results