Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-101047 — Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLs

Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Appl…

fleet | Remote | Information Disclosure
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.1 LOW
CVE-2026-101046 — Fleet before 4.89.0 SQL Injection via ORDER BY Activity Endpoints

Fleet before 4.89.0 contains an SQL injection vulnerability in the activity list endpoints (GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities). The deprecated cursor-pagination…

fleet | Remote | Injection
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.9 HIGH
CVE-2026-101045 — Fleet Homebrew Cask OS Command Injection via Metadata

Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some in…

fleet | Remote | Injection
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101044 — pacquet before 12.0.0-alpha.5 Path Traversal via lockfile alias

pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lockfile before u…

Remote | Path Traversal
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.3 HIGH
CVE-2026-101043 — pnpm 11.0.0 before 11.11.0 Environment Variable Exfiltration via Proxy Settings

pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.y…

Remote | Misconfiguration
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.8 HIGH
CVE-2026-88778 — TCP Initial Sequence Number (ISN) prediction

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS,…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.8 HIGH
CVE-2026-88777 — Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of…

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.8 HIGH
CVE-2026-88776 — Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of…

Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.8 HIGH
CVE-2026-88775 — Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of…

Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS …

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.0 HIGH
CVE-2026-88774 — Feature policy bypass due to improper HTTP URL based expression usage

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gatew…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.3 CRITICAL
CVE-2026-88773 — HTTP Request Smuggling

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.5 CRITICAL
CVE-2026-88772 — Memory overflow vulnerability leading to Remote Code Execution or Denial of Service

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gatew…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.5 CRITICAL
CVE-2026-88771 — A remote code execution vulnerability exists due to improper input validation, which can …

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.3 HIGH
CVE-2026-101050 — Heym before 0.0.53 Authentication Bypass via Telegram Webhook

Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credential_id is absent or secret_token is empty. Remote unauthenticated attackers can…

Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.3 HIGH
CVE-2026-101049 — Heym before 0.0.53 Slack Webhook Signature Verification Bypass

Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to know…

Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.4 HIGH
CVE-2026-101042 — Parse Server 9.0.0 Authentication Bypass via Unverified Provider Identity

Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, Linked…

parse-server | Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.3 MEDIUM
CVE-2026-101041 — Vulnerability-Lookup - Race Condition in Account Recovery Token Consumption Allows Passwo…

The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in the consumption of single-use recove…

Remote | Race Condition
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
5.3 MEDIUM
CVE-2026-101033 — KitchenOwl through 0.7.10 IDOR via unchecked category ID

KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households t…

Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.3 HIGH
CVE-2026-101032 — navi through 2.24.0 OS Command Injection via Cheatsheet Variables

navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metacharacters through crafted file names in suggestion …

| Injection
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.7 HIGH
CVE-2026-100872 — Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite

Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Att…

sylius | Remote | Misconfiguration
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
Showing 20 of 14021 Results