Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-91085 — Apache Karaf: config:install missing ACL entry allows privilege escalation to admin

Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles…

karaf | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.3 CRITICAL
CVE-2026-96431 — Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type

Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute…

agentflow | Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-91048 — Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege es…

The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenti…

karaf | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-91012 — Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalati…

org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from call…

karaf | Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.7 HIGH
CVE-2026-96430 — Flowring Agentflow 4.0 - Exposed Dangerous Method or Function

Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands v…

agentflow | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.9 CRITICAL
CVE-2026-84154 — Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPE…

A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the s…

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.7 HIGH
CVE-2026-101169 — Octopus Server Insecure Deserialization Remote Code Execution

In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of …

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.3 CRITICAL
CVE-2026-96429 — Flowring Agentflow 4.0 - SQL Injection

SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter.

agentflow | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.3 CRITICAL
CVE-2026-96428 — Flowring Agentflow 4.0 - SQL Injection

SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words paramet…

agentflow | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.7 HIGH
CVE-2026-86158 — Missing Authentication in the local .NET backend of Progress Telerik Fiddler Everywhere

Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the…

| Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.6 MEDIUM
CVE-2026-86157 — Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere

Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade …

| Information Disclosure
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.5 HIGH
CVE-2026-102293 — realjerrytang tacomall api-admin Backend ApiMaApplication.java OrgStaffServiceImpl.add im…

A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation…

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.0 MEDIUM
CVE-2026-102292 — coolbeans1212 MateisHomePage-Website users.php cross site scripting

A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected by this issue is some unknown functionality of the file users.php. This manipula…

Remote | Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.0 MEDIUM
CVE-2026-102290 — CodeCanyon Rocket LMS Student Profile Image Upload cross site scripting

A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Student Profile Image Upload. Executing a manipulation can lead to cross site scri…

Remote | Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.0 MEDIUM
CVE-2026-102264 — mwasikz robo-cafe-rms Edit Profile Feature update-account.php cross site scripting

A vulnerability was found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The impacted element is an unknown function of the file frontend/update-account.php of the component…

Remote | Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.8 MEDIUM
CVE-2026-102263 — mwasikz robo-cafe-rms manage-food.php unrestricted upload

A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown function of the file manage-food.php. Such manipulation lead…

Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.5 MEDIUM
CVE-2026-102261 — owen2345 Camaleon CMS Media Crop media_controller.rb crop authorization

A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop Handler. This …

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.7 MEDIUM
CVE-2026-97029 — Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group

Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. …

enterprise_linux enterprise_linux | Remote | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.1 HIGH
CVE-2026-97024 — Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory …

A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine…

enterprise_linux enterprise_linux | Remote | Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.2 CRITICAL
CVE-2026-102422 — shell-quote `quote()` command injection via a line terminator in a token after a `{ comme…

shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line …

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14293 Results