Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.3 LOW
CVE-2026-86418 — MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized U…

Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-or…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.3 HIGH
CVE-2026-61409 — Dell Secure Connect Gateway OS Command Injection Vulnerability

Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. …

Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.3 MEDIUM
CVE-2026-86417 — MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized U…

Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the no…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.8 HIGH
CVE-2026-86404 — Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging…

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via i…

Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
4.0 MEDIUM
CVE-2026-86301 — code-projects Hospital Information System Patient Management editPatient.php cross site s…

A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Suc…

hospital_information_system | Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86300 — Tenda AC9 Web Management R7WebsSecurityHandler improper authentication

A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be in…

ac9 | Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.9 CRITICAL
CVE-2026-86299 — Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of …

re7000 | Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.9 MEDIUM
CVE-2026-78325 — XSS in Standard Notes on Android via Malicious Google Keep and Evernote HTML Import

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a…

| Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.4 MEDIUM
CVE-2026-2390 — Powerkit <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy Loa…

The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This is due to the 'content_pro…

Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
0.0 NA
CVE-2026-86303 — 92181 markdown md.c lds out-of-bounds

A vulnerability was determined in 92181 markdown up to 058cab0cb7fb245a0ccc6b8446963ff8d573558f. Affected by this issue is the function lds of the file md.c. Executing a manipulation can lead to out-…

| Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.1 HIGH
CVE-2026-86408 — MISP Missing Authorization in Cryptographic Key View Exposes Signing Keys from Protected …

Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directl…

Remote | Cryptography
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.1 HIGH
CVE-2026-79678 — Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environ…

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is e…

enterprise_linux enterprise_linux | Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.8 CRITICAL
CVE-2026-76578 — Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials v…

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP clie…

enterprise_linux enterprise_linux | Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
0.0 NA
CVE-2026-86302 — code-projects Hospital Information System SQL Database Backup File his.sql information di…

A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup Fi…

hospital_information_system | Information Disclosure
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.1 MEDIUM
CVE-2026-86351 — MISP User Homepage Validation Allows Authenticated Open Redirect via Protocol-Relative URL

Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacke…

Remote | Misconfiguration
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86298 — SourceCodester Class and Exam Timetabling System delete_subject.php sql injection

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument…

class_and_exam_timetabling_system | Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.2 HIGH
CVE-2026-86297 — D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Pa…

Remote | Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
10.0 CRITICAL
CVE-2026-86296 — D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-bas…

Remote | Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.3 HIGH
CVE-2026-86295 — D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname result…

Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.0 MEDIUM
CVE-2026-86294 — SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php c…

A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update…

Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
Showing 20 of 12379 Results