Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-93652 — Integer Overflow or Wraparound in µD3TN

Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93568 — Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended…

HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.3 MEDIUM
CVE-2025-13882 — Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager.

IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 c…

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93576 — Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-v…

Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.3 MEDIUM
CVE-2025-1350 — Multiple vulnerabilities in IBM Controller

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browse…

controller | Remote | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.7 MEDIUM
CVE-2026-16515 — ICMPv6 error messages sent for multicast-destined packets and non-unique source addresses…

net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 error with an ICMPv6 error). It did not check wheth…

zephyr zephyr | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.3 MEDIUM
CVE-2026-16514 — Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved

gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop…

zephyr zephyr | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
3.1 LOW
CVE-2026-16512 — Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames

gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at…

zephyr zephyr | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.9 MEDIUM
CVE-2024-56344 — IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vulnerabilities

IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Trans…

cognos_analytics | Remote | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.2 MEDIUM
CVE-2026-85511 — Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth2

A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encodin…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.2 HIGH
CVE-2026-93569 — Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :a…

HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.8 HIGH
CVE-2026-77929 — ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint

ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the …

Remote | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93567 — Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http…

HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.1 HIGH
CVE-2026-93660 — SQLBot through 1.10.1 Improper Access Control via Dashboard Update

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers…

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.3 CRITICAL
CVE-2026-93659 — Concrete CMS Community Store before 2.7.8 Stored XSS

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.3 HIGH
CVE-2026-93658 — uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the pri…

coreutils | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-93657 — hickory-resolver before 0.26.2 DNSSEC Validation Bypass

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successfu…

Remote | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.1 HIGH
CVE-2026-77928 — ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endpoint

ClipBucket v5 through 5.5.3 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypas…

Remote | Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
3.2 LOW
CVE-2026-93676 — Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/…

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals …

enterprise_linux enterprise_linux | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.9 MEDIUM
CVE-2026-10832 — Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron…

A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding R…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
Showing 20 of 14452 Results