Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-87975 — Privilege abuse in model formsets with editable primary keys

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.forms.models.BaseModelFormSet.save_existing_objects()` used the presence of a primary key on a sub…

django | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.3 MEDIUM
CVE-2026-106026 — tftp-hpa 5.4 before 6.0 Out-of-Bounds Read via tftpd Remap Jump Rule

tftp-hpa 5.4 before 6.0 contains an out-of-bounds read vulnerability in rewrite_string() in tftpd/remap.c that walks heap memory during jump label searches. Unauthenticated remote attackers can send …

tftp-hpa | Remote | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.4 MEDIUM
CVE-2026-105842 — lrzsz before 0.13.0 Heap Buffer Overflow via lrz procheader() Pathname

lrzsz before 0.13.0 contains a heap-based buffer overflow vulnerability in procheader() of the lrz receive utility when copying overlong sender-supplied filenames into Pathname. Malicious ZMODEM send…

Remote | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.7 HIGH
CVE-2026-105841 — lrzsz before 0.13.0 OS Command Injection via lrz Pipe Mode

lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows remote senders to execute commands by supplying crafted filenames. When lrz runs …

Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.7 HIGH
CVE-2026-105840 — lrzsz before 0.13.0 Path Traversal via lrz Restricted Mode checkpath()

lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted mode that allows malicious ZMODEM senders to write files outside the current directory using absolu…

Remote | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.5 HIGH
CVE-2026-105839 — libmikmod before 3.3.14 Heap Buffer Overflow via OKT Loader OKT_doPBOD

libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKT_doPBOD() that allows attackers to cause heap buffer overflow via crafted track counts. Attackers can supply an OKT mod…

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.8 MEDIUM
CVE-2026-105838 — libmikmod before 3.3.14 Heap Out-of-Bounds Read via IT Module Loader

libmikmod before 3.3.14 contains a heap out-of-bounds read vulnerability in the Impulse Tracker loader load_it.c that allows attackers to read adjacent heap memory via oversized patterns. Attackers c…

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.5 HIGH
CVE-2026-105837 — libmikmod before 3.3.14 Heap Buffer Overflow via DSM Loader Integer Overflow

libmikmod before 3.3.14 contains an integer overflow vulnerability in DSM_Load() in load_dsm.c that allows attackers to trigger heap buffer overflow via crafted track counts. Attackers can supply a D…

| Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-87890 — Potential request forgery via spatial lookup byte values

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups allows an attacker who can supply `bytes` v…

django | Server-Side Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-84429 — Potential denial-of-service vulnerability in HTTP header parsing

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due to q…

django | Denial of Service
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-77050 — Potential denial-of-service vulnerability in get_supported_language_variant()

An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service a…

django | Denial of Service
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.3 MEDIUM
CVE-2026-82924 — PII Enumeration via Missing Rate Limiting in Pusula Communication's Expert Mail

Improper Control of Interaction Frequency vulnerability in Pusula Communication, IT, and Internet Industry and Trade Co. Ltd. Expert Mail allows Brute Force. This issue affects Expert Mail: through …

Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-105920 — Kusalkasilva Learning-Management-System Student Registration Endpoint student_signup.php …

A vulnerability was determined in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The impacted element is an unknown function of the file student_signup.php of…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.3 MEDIUM
CVE-2025-15591 — Cross-Site Scripting (XSS) vulnerability identified in OpenText™ Content Management

Cross-site Scripting (XSS) in the Forums feature of OpenText Content Management Content Server could allow a bad actor to inject malicious code into a Forums web page.

Remote | Cross-Site Scripting
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.2 CRITICAL
CVE-2026-82531 — Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache

Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it nu…

smarty | Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-106016 — Mitigation bypass in the File Handling component

Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 157.0.1.

firefox | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.5 HIGH
CVE-2026-105919 — Kusalkasilva Learning-Management-System Administrator Login Endpoint login.php mysql_quer…

A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The affected element is the function mysql_query of the file admin/login.php of th…

learning-management-system | Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.4 MEDIUM
CVE-2026-105836 — QloApps through 1.7.0 Authorization Bypass via ajaxProcessBulkUpdateRooms

QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::ajaxProcessBulkUpdateRooms that allows hotel-restricted back-office employees to modify rooms of other…

qloapps | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.1 CRITICAL
CVE-2026-105835 — PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint

PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor authentication codes. Attackers who know …

planka | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.1 HIGH
CVE-2026-105834 — Rundeck before 6.2.0 Arbitrary File Read via File Resource Model Source

Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file to any a…

rundeck | Remote | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 14890 Results