Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-86095 — Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attribute Name

Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attack…

netcdf | Memory Corruption
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.9 HIGH
CVE-2026-48019 — CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail re…

Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime ha…

framework | Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.1 HIGH
CVE-2026-86091 — ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler

ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue …

ntopng | Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.1 HIGH
CVE-2026-86090 — ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient…

ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly d…

ntopng | Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.6 HIGH
CVE-2026-82684 — Tycon Systems TPDIN-Monitor-WEB3 Missing Authorization

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.8 HIGH
CVE-2026-77393 — Inductive Automation Ignition Incorrect Default Permissions

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8…

ignition | Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.8 MEDIUM
CVE-2026-76925 — Flatpak: flatpak: toctou race condition allows symlink redirection

A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chm…

Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
9.6 CRITICAL
CVE-2026-75925 — IXON VPN Client CRLF Injection

Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are writ…

Remote | Misconfiguration
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.7 HIGH
CVE-2026-46636 — Twig: Sandbox method allowlist bypass via `Markup` subclass

Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Ma…

twig | Remote | Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.1 HIGH
CVE-2026-85787 — An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs…

An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read…

postgres-mcp-server | Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
3.7 LOW
CVE-2026-85704 — ramon-victor freegpt-webui Jailbreak Mode config.py getJailbreak race condition

A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the comp…

freegpt-webui | Remote | Race Condition
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.5 MEDIUM
CVE-2026-85703 — ramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation of resources

A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component …

freegpt-webui | Remote | Denial of Service
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-85702 — ramon-victor freegpt-webui Backend Conversation API backend.py _conversation missing auth…

A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the co…

freegpt-webui | Remote | Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.5 MEDIUM
CVE-2026-85701 — ramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing…

A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the c…

freegpt-webui | Remote | Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.8 HIGH
CVE-2026-82712 — Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request Forgery

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

Remote | Cross-Site Request Forgery
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-79426 — CRMEB Arbitrary File Deletion Vulnerability

An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.

| Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-79423 — Seacms Remote Code Execution Vulnerability

An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.

| Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.1 HIGH
CVE-2026-77847 — Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credential…

| Misconfiguration
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-75439 — Free5GC UPF Denial of Service Vulnerability

An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component

| Denial of Service
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-75438 — Open5GS Buffer Overflow

Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function

| Memory Corruption
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
Showing 20 of 12761 Results