Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-74849 — Remote code execution vulnerability

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

manageengine_adselfservice_plus | Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.6 MEDIUM
CVE-2026-95623 — Improper SSRF Protection via HTTP Redirects in tauri-plugin-http

The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwe…

| Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.3 MEDIUM
CVE-2026-92882 — Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET…

Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may vie…

Remote | Information Disclosure
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.3 MEDIUM
CVE-2026-90990 — Livestatus injection via monitoring filter values

Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypa…

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.2 HIGH
CVE-2026-87119 — mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing …

Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorizati…

mpp | Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.1 HIGH
CVE-2026-89420 — Session voucher adding no new funds is accepted without a charge in mpp, serving paid res…

Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3…

mpp | Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-95270 — dgtlmoon changedetection.io Hash Comparison flask_app.py check_password timing discrepancy

A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. Thi…

| Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.4 MEDIUM
CVE-2026-63279 — Out of bounds read in PICT image import

LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was …

| Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.7 MEDIUM
CVE-2026-63278 — Package URLs can be used to exfiltrate arbitrary INI file values and environment variables

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such li…

| Information Disclosure
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.4 MEDIUM
CVE-2026-63276 — Stack buffer overflow in CFF to Type 1 font conversion

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that …

| Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.4 MEDIUM
CVE-2026-63275 — Stack buffer overflow in CFF font hint handling

LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a gl…

| Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.4 MEDIUM
CVE-2026-63274 — Heap buffer overflow in PDF import stream handling

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked again…

| Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.4 MEDIUM
CVE-2026-63273 — Heap buffer overflow in PDF import encryption handling

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionar…

| Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.4 MEDIUM
CVE-2026-63272 — Heap buffer overflow in WMF text record import

LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advanc…

| Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.6 HIGH
CVE-2026-94117 — WordPress HashBar – WordPress Notification Bar plugin <= 2.0.3 - SQL Injection vulnerabil…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects Has…

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.7 HIGH
CVE-2026-90882 — Reflected arbitrary origins with credentials, allowing cross-origin reads of authenticate…

The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on…

Remote | Cross-Site Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.8 HIGH
CVE-2026-25265 — Creation of Temporary File with Insecure Permissions in Qualcomm Software Center

Privilege escalation due to weak configuration while temporary file handling.

| Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.8 HIGH
CVE-2026-25264 — Uncontrolled Search Path Element in Qualcomm Software Center

Privilege escalation due to weak configuration during package extraction process.

| Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.9 MEDIUM
CVE-2026-25262 — Write-what-where Condition in Primary Bootloader

Memory corruption while processing a crafted ELF file in the Primary Bootloader.

| Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.8 HIGH
CVE-2026-25255 — Exposed function in Qualcomm Package Manager and Qualcomm Software Center.

Exposed dangerous function lead to privilege escalation via gRPC server.

| Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
Showing 20 of 13858 Results