Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.6 MEDIUM
CVE-2026-15923 — Infinite loop denial of service in Zephyr SDIO byte-I/O from a card-supplied zero max_blk…

The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteratio…

zephyr zephyr | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.3 MEDIUM
CVE-2026-53496 — ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes

ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in…

Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-76442 — Cisco Secure Email Gateway Security Hardening Release

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive i…

Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.8 CRITICAL
CVE-2026-76461 — Cisco Secure Email Gateway SQL Injection Vulnerability

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the…

secure_email | Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-54156 — node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/sou…

node-opcua | Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.8 CRITICAL
CVE-2026-76443 — Cisco Secure Email Gateway Security Hardening Release

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive i…

Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.8 CRITICAL
CVE-2026-76440 — Cisco Secure Email Gateway Security Hardening Release

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive i…

Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.8 CRITICAL
CVE-2026-20353 — Cisco Secure Email Gateway Security Hardening Release

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive i…

secure_email | Remote | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
9.8 CRITICAL
CVE-2026-76441 — Cisco Secure Email Gateway Security Hardening Release

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive i…

Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.7 HIGH
CVE-2026-54155 — node-opcua: Missing nonce verification in UserNameIdentityToken authentication

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an …

node-opcua | Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.3 MEDIUM
CVE-2026-57497 — webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by call…

webtransport-go | Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.8 HIGH
CVE-2026-61701 — Laravel MagicLink: Insecure Deserialization of MagicLink Actions Leads to Remote Code Exe…

Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action d…

Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
3.3 LOW
CVE-2026-46696 — October CMS Twig Sandbox Security Policy Bypass

A vulnerability was identified in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to Twig with unrestricted metho…

Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-90796 — itsourcecode Leave Management System index.php sql injection

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql in…

Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-90791 — GPAC MP4Box base_scenegraph.c gf_node_unregister use after free

A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation resu…

Remote | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.5 MEDIUM
CVE-2026-90790 — a2aproject a2a-python Push Notification Sender base_push_notification_sender.py _dispatch…

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of …

Remote | Server-Side Request Forgery
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-90789 — itsourcecode Leave Management System login.php sql injection

A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_…

leave_management_system | Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-82438 — Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's…

| Misconfiguration
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-82437 — Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer

Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For daemon logs those settings were not applied: the access decision combined the "…

| Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-82435 — Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Dec…

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffe…

| Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
Showing 20 of 12547 Results