Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-79767 — Gardener: Authorization Bypass via Group Subject Injection

Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckP…

| Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-61570 — MPXJ: XXE Vulnerability in MerlinReader

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, MerlinReader creates a DocumentBuilder with default settings whil…

| XML External Entity
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-65829 — MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted Primavera P3 PRX or SureTrak STX file …

| Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-77322 — SIPGO: DoS via unvalidated WebSocket frame length

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to ac…

sipgo | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-58268 — SIPGO: DoS via unvalidated Content-Length in the stream parser

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates a SIP body buffer from the client-controlled Content-Length …

sipgo | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.8 CRITICAL
CVE-2026-87121 — Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

Remote | Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-83805 — Nautobot: Authorization bypass in approval workflow REST API allows self-approval and una…

Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, ch…

| Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-83801 — Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store HTML or JavaSc…

| Cross-Site Scripting
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.1 HIGH
CVE-2026-63104 — Kaneo 2.3.12 < 2.12.2 Missing Authorization via Bulk Task Endpoint

Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assig…

Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.8 CRITICAL
CVE-2026-47116 — LTSecurity LTK3500SF Hard-coded Credentials via Telnet/SSH

LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where root and guest account passwords are stored as reversible hashes in /etc/shadow, recoverable using dictionary-based cracking…

Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-94574 — CVE-2026-94574

A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged use…

| Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-89281 — CVE-2026-89281

The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.

| Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-89282 — CVE-2026-89282

The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits w…

| Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.5 HIGH
CVE-2026-95862 — UniFi Gateway Out-of-bounds Write Vulnerability

A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

unifi_connect | Remote | Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.5 HIGH
CVE-2026-95861 — UniFi Gateway Uncontrolled Recursion Denial of Service

A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

unifi_connect | Remote | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-95831 — Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which ex…

Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certifica…

| Supply Chain
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.1 HIGH
CVE-2026-94462 — Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)

Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::V3::Store::CartsController#associate use…

Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.3 CRITICAL
CVE-2026-91130 — Home Assistant: XSS in Statistics Graph Card

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity nam…

Remote | Cross-Site Scripting
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.4 MEDIUM
CVE-2026-91129 — Home Assistant: mDNS Server-Side Request Forgery

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announ…

| Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.5 MEDIUM
CVE-2026-89277 — CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…

| Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
Showing 20 of 14143 Results