Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.6 MEDIUM
CVE-2026-27872 — EasyIO FG

- Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.

Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.4 HIGH
CVE-2026-15911 — Confluent Kafka Python Improper TLS Certificate Validation

Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.

confluent-kafka | Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.1 HIGH
CVE-2026-104059 — Lektor 3.3.14 CSRF via Admin API Endpoints

Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-orig…

Remote | Cross-Site Request Forgery
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.3 MEDIUM
CVE-2026-104058 — Podgrab Missing Authentication on WebSocket /ws Endpoint

Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, allowing unauthenticated…

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-104057 — Podgrab Unauthenticated DoS via Concurrent Map Access in WebSocket Handler

Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshand…

Remote | Race Condition
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-104056 — CVE-2026-104056

Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all …

authlib | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-9032 — Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerabili…

Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser.  The interface is reachable without authentication after initial setup and does not validat…

tapo_c200 tapo_c120 | Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.2 HIGH
CVE-2026-97662 — Argument injection in the diff scan operation in AWS security-agent-mcp-server allows arb…

An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary fi…

| Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-78578 — Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Servi…

Tapo C120 v1 and C200 v5 do not enforce authentication for do method HTTPS onboarding connect actions after initial setup.  An unauthenticated adjacent attacker can submit unauthorized wireless confi…

tapo_c200 tapo_c120 | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-78577 — Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200

Tapo C120 v1 and C200 V5 contain a vulnerability in the HTTPS onboarding scan function due to missing authentication. After initial setup, an unauthenticated attacker on the same local network can in…

tapo_c200 tapo_c120 | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-73976 — djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`)

djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separa…

Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-68496 — jackson-dataformats-binary: Smile parser does not enforce StreamReadConstraints.maxNameLe…

The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced …

jackson-dataformats-binary | Remote | Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.5 HIGH
CVE-2026-68495 — jackson-dataformats-binary: CBOR parser does not enforce StreamReadConstraints.maxNameLen…

The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced f…

jackson-dataformats-binary | Remote | Denial of Service
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.3 MEDIUM
CVE-2026-56098 — Rubygem-katello: improper authorization logic allows resource enumeration

A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While t…

satellite satellite | Remote | Authorization
Oct 01, 2026 Oct 02, 2026
Oct 01, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-56097 — Rubygem-katello: sql injection in registry proxy via labels

A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries…

satellite satellite | Remote | Injection
Oct 01, 2026 Oct 02, 2026
Oct 01, 2026
Oct 02, 2026
6.7 MEDIUM
CVE-2026-12545 — Rubygem-hammer_cli: command injection via insecure editor invocation

A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation …

satellite satellite | Injection
Oct 01, 2026 Oct 02, 2026
Oct 01, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-12542 — Foreman: command injection in foreman-tail

A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them d…

satellite satellite | Injection
Oct 01, 2026 Oct 02, 2026
Oct 01, 2026
Oct 02, 2026
8.8 HIGH
CVE-2026-104018 — VxWorks 7 improper privilege management

An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a …

vxworks | Remote | Authorization
Oct 01, 2026 Oct 02, 2026
Oct 01, 2026
Oct 02, 2026
2.1 LOW
CVE-2026-103923 — KaTeX: Existing prototype pollution can bypass trust restrictions

KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for the renderer options object, the trust …

katex | Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.3 CRITICAL
CVE-2026-103922 — Capacitor Android and iOS: remote content can be loaded at the app origin via the interna…

Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host a…

Remote | Server-Side Request Forgery
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 14871 Results