Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-15892 — Heap memory leak in mcumgr settings-management handlers on access-hook rejection leads to…

The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_na…

zephyr zephyr | Denial of Service
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-15891 — NULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gateway

The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&clien…

zephyr zephyr | Denial of Service
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
0.0 NA
CVE-2026-90602 — Anil-matcha Open-Generative-AI Studio Components ImageStudio.js renderHistory cross site …

A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Co…

| Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
0.0 NA
CVE-2026-90601 — getzep graphiti REST API main.py improper authentication

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper aut…

graphiti | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.0 MEDIUM
CVE-2026-90599 — Rizwan17 inventory-management-system process.php cross-site request forgery

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulati…

inventory-management-system | Remote | Cross-Site Request Forgery
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90598 — jaygajera17 E-commerce-project-springBoot UserController.java UserController.updateUser a…

A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file Us…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90597 — itsourcecode Sales and Inventory System sup_edit1.php sql injection

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argum…

sales_and_inventory_system | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.9 MEDIUM
CVE-2026-90596 — embedded-graphics image_raw.rs new/bytes_per_row integer overflow

A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer ov…

Remote | Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
2.9 LOW
CVE-2026-52297 — FFmpeg MOV Parsing Out-of-Bounds Read

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

| Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
2.9 LOW
CVE-2026-52296 — FFmpeg WMA Out-of-Bounds Read

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

| Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
3.1 LOW
CVE-2026-35867 — LB-LINK AC1900_AZ2 Command Injection Vulnerability

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed…

ac1900_firmware | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
0.0 NA
CVE-2026-90600 — itsourcecode Sales and Inventory System inv_edit1.php sql injection

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql inje…

Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90595 — wxiaoqi Spring-Cloud-Platform OnlineController.java OnlineController.getOnlineInfo author…

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/Onlin…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90594 — wxiaoqi Spring-Cloud-Platform Permission Service PermissionService.java PermissionService…

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.j…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90593 — embedded-graphics image_raw.rs draw_sub_image integer overflow

A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width …

Remote | Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.5 MEDIUM
CVE-2026-90584 — TooTallNate Java-WebSocket Fragmentation Draft_6455.java processFrameContinuousAndNonFin …

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentati…

Remote | Denial of Service
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.3 MEDIUM
CVE-2026-89050 — Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via …

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing user…

Remote | Misconfiguration
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-88802 — MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion

The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanentl…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.8 HIGH
CVE-2026-88793 — YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server

The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escap…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.8 HIGH
CVE-2026-85129 — Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import

The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the ac…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
Showing 20 of 13125 Results