Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-75350 — EIPStackGroup OpENer Buffer Overflow

EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in the GetAttributeList() implementation for the EtherNet/IP Get_Attribute_List service. This allows a remote attacker to …

Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-108096 — Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Catego…

Improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer in AWS Amplify API Category before 3.1.2 might allow an authenticated remote user to read records own…

Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.7 MEDIUM
CVE-2026-107841 — pacioli: A submit consent marker licensed cancellation of caller-named pre-existing docum…

pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation …

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-107840 — yopass Prometheus metrics middleware allows remote memory exhaustion through unbounded me…

yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value …

Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-107839 — ageLANServer: Unbounded JSON Array Allocation in AoE3 Cloud `getFileURL` Endpoint Leads t…

ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology games. Prior to version 1.15.2, the AoE3 POST /game/cloud/getFile…

Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-107838 — RIOT: nanocoap_fileserver ignores response initialization failure, leading to reachable a…

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers i…

riot | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.2 HIGH
CVE-2026-107837 — RIOT: Out-of-Bounds Read in RIOT OS 6LoWPAN SFF Fragment Handling

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, _receive() in sys/net/gnrc/network_layer/sixlowpan/…

riot | Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.1 HIGH
CVE-2026-107836 — RIOT: nanoCoAP Block2 client slice handling underflows on inconsistent server-controlled …

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slic…

riot | Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.0 MEDIUM
CVE-2026-107835 — OWASP Coraza WAF: Cookie Parser Confusion

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control chara…

coraza | Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-107834 — OWASP Coraza WAF: Resource exhaustion via deferred file handle accumulation in multipart …

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() fo…

coraza | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.9 MEDIUM
CVE-2026-107833 — OWASP Coraza WAF: Unbounded recursion in JSON response body processor causes CPU exhausti…

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit va…

coraza | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.5 HIGH
CVE-2026-107826 — OWASP Coraza WAF: JSON body processor: argument-limit truncation reopens an unbounded-dep…

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after re…

coraza | Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
4.0 MEDIUM
CVE-2026-107825 — OWASP Coraza WAF: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failur…

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by …

coraza | Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
9.3 CRITICAL
CVE-2026-107824 — x64dbg-MCP Server exposes debugger operations to unauthenticated network clients

x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.1, x64dbg-MCP Server exposes all MCP debugger tools o…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
7.2 HIGH
CVE-2026-107823 — MariaDB: privilege escalation via incorrect view frm parsing

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the MariaDB view FRM parser did not safely encode embedded newl…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
6.4 MEDIUM
CVE-2026-107822 — MariaDB: database privilege escalation via user / role name collision in the acl cache

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB's ACL cache could generate the same database-privilege …

Remote | Authorization
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.0 HIGH
CVE-2026-107821 — MariaDB: insufficient validation of binary frm data when opening a table

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB insufficiently validated counts, offsets, lengths, and …

Remote | Memory Corruption
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.3 MEDIUM
CVE-2026-107820 — x64dbg-MCP Server vulnerable to pre-authentication denial of service through Content-Leng…

x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.2, src/core/mcp_server.zig parses an unbounded Conten…

Remote | Denial of Service
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
5.9 MEDIUM
CVE-2026-107819 — MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verifi…

MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 until 3.4.10, the MariaDB Connector/C libmariadb Zero-Configuration SSL authen…

Remote | Authentication
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
8.4 HIGH
CVE-2026-107818 — MariaDB: environment injection via wsrep bootstrap in the mariadb.service file

MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster dur…

Remote | Misconfiguration
Oct 09, 2026 Oct 09, 2026
Oct 09, 2026
Oct 09, 2026
Showing 20 of 14144 Results