Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-85237 — Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass

A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did no…

misp | Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-85236 — MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request

A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. …

misp | Remote | Cross-Site Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-85138 — SeaCMS WeChat index.php addslashes sql injection

A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in…

seacms | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-85137 — SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection

A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument…

seacms | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.1 MEDIUM
CVE-2026-84967 — Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell …

A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an…

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.9 MEDIUM
CVE-2026-84966 — BSON element injection via NUL-embedded document keys in builder append

An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremel…

c_driver | Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.9 MEDIUM
CVE-2026-84965 — Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds

An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale point…

c_driver | Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.2 HIGH
CVE-2026-84964 — Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS cl…

A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially fo…

c_driver | Remote | Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.3 MEDIUM
CVE-2026-84963 — Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON…

An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be…

c_driver | Remote | Information Disclosure
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.7 MEDIUM
CVE-2026-84962 — Authenticated KMS request forgery via CRLF injection in GCP key identifier strings

An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-l…

libmongocrypt | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-83961 — ColdFusion | Improper Authentication (CWE-287)

ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The …

| Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.8 MEDIUM
CVE-2026-82525 — Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing

Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external enti…

| XML External Entity
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-75036 — Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing

A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user w…

Remote | Server-Side Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.7 HIGH
CVE-2026-75035 — Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector sco…

A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of …

rancher | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.4 HIGH
CVE-2026-75034 — Rancher: SAML Assertion Replay

A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detecte…

rancher | Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-71963 — Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection

Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository …

hermes-agent | Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.7 HIGH
CVE-2026-57445 — Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve

Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d…

Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.7 HIGH
CVE-2026-55658 — Gardens v2: StreamingEscrow buffer drains to the proposal beneficiary on cancel via the p…

Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a s…

Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.7 HIGH
CVE-2026-53924 — Gardens v2: Permissionless syncOutflow bypasses streaming proposal disputes

Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Prior to 0xc9d4e0dacd937364793…

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.1 MEDIUM
CVE-2026-53720 — pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buf…

pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently lar…

| Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Showing 20 of 12638 Results