Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-87110 — Ops Manager Uncontrolled Resource Consumption in Monitoring Endpoints

An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform costly work without rate limiting. This can temporarily slow other tra…

ops_manager | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.0 MEDIUM
CVE-2026-87109 — Ops Manager Sensitive MFA Enrollment Information Exposure in User Listings

An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This…

ops_manager | Remote | Information Disclosure
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
3.1 LOW
CVE-2026-87108 — Ops Manager Improper Authorization in Daily Host Monitoring Retrieval

An authenticated Ops Manager user with a read-only project role can retrieve a daily host monitoring record associated with a different project when they possess the required record identifier. Insuf…

ops_manager | Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.8 HIGH
CVE-2026-107914 — Backdrop CMS Configuration Export Information Disclosure

Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an exp…

backdrop | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.7 HIGH
CVE-2026-107911 — Type confusion in FalkorDB GRAPH.QUERY via the --bolt argument

A type confusion vulnerability in the _read_flags function (src/commands/cmd_dispatcher.c) in FalkorDB before 4.20.0 allows a remote authenticated attacker who can run GRAPH.QUERY to cause a denial o…

falkordb | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.2 CRITICAL
CVE-2026-107910 — Authentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handling

An improper authentication vulnerability in the is_authenticated function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to execute graph queries without cre…

falkordb | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.1 CRITICAL
CVE-2026-107909 — Pre-authentication heap out-of-bounds write in FalkorDB Bolt WebSocket frame handling via…

A heap-based out-of-bounds write in the ws_read_frame function (src/bolt/ws.c) and the buffer_apply_mask function (src/bolt/buffer.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacke…

falkordb | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.8 CRITICAL
CVE-2026-107908 — Pre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET me…

A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly exe…

falkordb | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.2 CRITICAL
CVE-2026-7827 — Stack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in cr…

A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.4 allows a remote attacker who can …

falkordb | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.1 CRITICAL
CVE-2026-7826 — Heap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDB

A heap-based out-of-bounds read in the BufferSerializerIOv2_ReadBuffer function (src/serializers/serializer_io.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication co…

falkordb | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.8 CRITICAL
CVE-2026-5759 — Double free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code executi…

A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a re…

falkordb | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
3.3 LOW
CVE-2026-107890 — CUPS NULL Pointer Dereference Vulnerability

OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation requests. IPP parsing creates unnamed separator attributes with IPP_TAG_ZERO, but…

cups | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.5 MEDIUM
CVE-2026-107889 — Keycloak-services: keycloak-services: stored xss on login page via kcsanitize bypass

A flaw was found in the login theme rendering component of Keycloak. The issue occurs because the security filter responsible for cleaning user input can be bypassed, allowing a realm administrator t…

single_sign-on build_of_keycloak | Remote | Cross-Site Scripting
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.1 MEDIUM
CVE-2026-107888 — OpenPrinting CUPS NULL Pointer Dereference

OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted. Tempora…

cups | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
2.3 LOW
CVE-2026-107886 — OpenPrinting CUPS Printer Class Management Double-Free Vulnerability

OpenPrinting CUPS before 2.4.20 contains a double-free in printer-class management. When CUPS-Add-Modify-Class replaces an existing class member list, add_class() frees pclass->printers without clear…

cups | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
3.3 LOW
CVE-2026-107885 — OpenPrinting CUPS Resource Exhaustion Vulnerability

OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs …

cups | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
0.0 NA
CVE-2026-97032 — HTTP/2 server crash due to HPACK encoder race in net/http

HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronizat…

net | Race Condition
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-97031 — Reject malformed ECH outer extension references in crypto/tls

Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifyin…

go | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-97030 — Recognize yield as regexp preceder keyword in html/template

A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non…

go | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
10.0 CRITICAL
CVE-2026-96207 — Microsoft Partner Center Elevation of Privilege Vulnerability

Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 14131 Results