Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-71543 — OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-si…

openbao | Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.0 HIGH
CVE-2026-68919 — GoCD has stored XSS possible via forged package material comments on Stage/Job/VSM pages

GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by packa…

gocd | Remote | Cross-Site Scripting
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
4.2 MEDIUM
CVE-2026-61630 — nginx ignition has TOTP Reuse During Validity Window

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity…

Remote | Authentication
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.5 HIGH
CVE-2026-61629 — nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplif…

nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `g…

Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.1 HIGH
CVE-2026-61628 — nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition

nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full Rea…

Remote | Authentication
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
2.3 LOW
CVE-2026-55870 — GoCD is vulnerable to credential exposure when admins insecurely configure material URLs

GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only…

gocd | Remote | Information Disclosure
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
4.9 MEDIUM
CVE-2026-55625 — GoCD is vulnerable to authorization bypass via material connection test APIs

GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test acc…

gocd | Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.8 HIGH
CVE-2026-55567 — BleachBit: Exploit File Delete to Escalate Privilege

BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivil…

bleachbit | Path Traversal
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.2 HIGH
CVE-2026-55074 — Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (ho…

Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination …

Remote | Path Traversal
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.4 HIGH
CVE-2026-55071 — MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled in…

| Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
3.7 LOW
CVE-2026-55060 — GoCD is vulnerable to authorization bypass via support process list API

GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user…

gocd | Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.3 MEDIUM
CVE-2026-54584 — mport trusts environment-controlled temporary directories in privileged metadata extracti…

mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control t…

Remote | Misconfiguration
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
4.3 MEDIUM
CVE-2026-52743 — GoCD before 26.1.0 is vulnerable to authorization bypass via job status API

GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the…

gocd | Remote | Information Disclosure
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.1 MEDIUM
CVE-2026-52742 — GoCD is vulnerable to historical server configuration API authorization bypass

GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restrict…

gocd | Remote | Information Disclosure
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.5 HIGH
CVE-2026-52741 — GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages

GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with…

gocd | Remote | Cross-Site Scripting
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.3 MEDIUM
CVE-2026-52740 — GoCD is vulnerable to pipeline template view API authorization bypass

GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authent…

gocd | Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.1 HIGH
CVE-2026-94404 — MISP CSRF vulnerability allows unauthorized attribute modification

MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did no…

misp | Remote | Cross-Site Request Forgery
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.3 HIGH
CVE-2026-94401 — MISP Arbitrary Local File Read and SSRF via MISP Export Upload

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly ve…

misp | Remote | Server-Side Request Forgery
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
6.3 MEDIUM
CVE-2026-94394 — MISP ObjectReferencesController: Granular Distribution and Sharing Group Restrictions Byp…

When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are a…

misp | Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
6.4 MEDIUM
CVE-2026-94393 — MISP Event Report Cross-Event Reparenting via Unscoped UUID Resolution in editReport

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a resu…

misp | Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
Showing 20 of 13717 Results