Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-71183 — Apache DolphinScheduler: Missing Authorization Checks Allow Disclosure of Data Source Inf…

An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /aut…

dolphinscheduler | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-66087 — Apache DolphinScheduler: Project Authorization Bypass in the Task instance stop/savepoint…

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to operate task instance in projects they are not authorized to access through the  * /dolphinsched…

dolphinscheduler | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-66084 — Apache DolphinScheduler: Project Authorization Bypass in the Task Definition with-upstrea…

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to modify task definitions in projects they are not authorized to access through the /dolphinscheduler/proj…

dolphinscheduler | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-66082 — Apache DolphinScheduler: Cross-project authorization bypasses in DolphinScheduler API (sc…

An authorization bypass vulnerability in Apache DolphinScheduler allows authenticated users to perform unauthorized operations on workflow schedules, workflow definitions, and task instances in other…

dolphinscheduler | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.9 MEDIUM
CVE-2026-4894 — Authentication bypass in multiple products from Frappe Technologies

A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the emai…

Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
10.0 CRITICAL
CVE-2026-12260 — SQL injection in the NetBoard CRM demo platform

SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to b…

netboard_crm_demo_platform | Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
9.8 CRITICAL
CVE-2026-105110 — Iskratel Innbox Unauthenticated Remote Code Execution via login.xgi CLI Parameter

OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.

Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.5 HIGH
CVE-2026-93699 — WP Toolkit for cPanel Argument Injection Vulnerability

Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.

| Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.1 MEDIUM
CVE-2026-107466 — Flatpak-builder: local file exfiltration via `file

A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manife…

enterprise_linux enterprise_linux | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.4 HIGH
CVE-2026-87428 — Brocade ASCG Credential Disclosure Vulnerability

In Brocade ASCG before 3.5.0, a  local unauthorized user on the ASCG VM who can issue a request to the SANnav host network namespace can extract stored management credentials for onboarded SANnav ins…

active_support_connectivity_gateway | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-87426 — Brocade ASCG Information Disclosure Vulnerability

An unauthenticated network-based attacker can query specific internal management endpoints on Brocade ASCG versions before 3.5.0 to enumerate the configuration details and state of managed Brocade Fa…

active_support_connectivity_gateway | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.6 HIGH
CVE-2026-87425 — Brocade ASCG TLS Trust Store Improper Neutralization

An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0. By supplying an unauthorized Certificate Authority (CA) certificate to an unauthenticat…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.6 HIGH
CVE-2026-87424 — Brocade ASCG Authentication Bypass Vulnerability

A vulnerability in the SupportLink API authentication component of Brocade ASCG versions prior to 3.5.0 allows an attacker to bypass authentication across deployments due to the use of a hard coded c…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.7 HIGH
CVE-2026-85490 — Brocade ASCG Path Traversal Vulnerability

When Brocade ASCG before 3.5.0 processes support bundle archives ingested from remote compromised endpoints, the application fails to sanitize path traversal sequences contained within archive entrie…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.7 HIGH
CVE-2026-85489 — Brocade ASCG Authentication Bypass Vulnerability

An authentication flaw exists in the Brocade ASCG administrative management service component. An unauthenticated network user can issue direct API requests to perform privileged actions, including a…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.0 HIGH
CVE-2026-85488 — Brocade ASCG Hardcoded Credential Vulnerability

Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer. Any local authenticated user with read access to the installation path can disc…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.6 HIGH
CVE-2026-85487 — Brocade ASCG Path Traversal Vulnerability

A path traversal vulnerability exists in the HTTP service component of Brocade ASCG versions before 3.5.0. An unauthenticated attacker on the local network could send a manipulated API request to the…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.6 HIGH
CVE-2026-85486 — Brocade ASCG Remote Code Execution

Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.6 HIGH
CVE-2026-85423 — Brocade ASCG Authentication Bypass and Remote Code Execution Vulnerability

A vulnerability has been identified in the data collection service of Brocade ASCG versions before 3.5.0. An API endpoint within the data collector service fails to perform authentication or authoriz…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.4 HIGH
CVE-2026-85422 — Brocade ASCG Hardcoded Cryptographic Key Vulnerability

A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect …

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 15568 Results