Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.9 LOW
CVE-2026-38332 — TinyEXIF Heap-Based Buffer Over-Read

TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.

| Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.1 HIGH
CVE-2026-37008 — CrewAI Sandbox Bypass via Python Runtime Manipulation

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not a…

| Misconfiguration
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.8 MEDIUM
CVE-2026-36989 — LuxSoft LuxCal SQL Injection Vulnerability

A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.

luxcal_web_calendar | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.4 HIGH
CVE-2026-36453 — Rhymix Insecure Direct Object Reference Vulnerability

Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.3 MEDIUM
CVE-2026-90583 — kagisearch smallweb Query String Rendering sw.py index cross site scripting

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query Stri…

Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.5 MEDIUM
CVE-2026-90582 — evanchiu serverless-todo API Todo Endpoint index.js saveTodos resource consumption

A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argume…

Remote | Denial of Service
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90581 — cym1102 nginxWebUI autoUpdate MainController.autoUpdate code injection

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument u…

nginxwebui | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90580 — FlowiseAI Flowise Evaluations Endpoint index.ts axios.post server-side request forgery

A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evalua…

flowise | Remote | Server-Side Request Forgery
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.3 MEDIUM
CVE-2026-29812 — CyberPanel Improper Logging of Domain Manipulation Actions

CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

Remote | Misconfiguration
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.7 HIGH
CVE-2026-29811 — CyberPanel Domain Alias ORM Injection Vulnerability

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a P…

Remote | Misconfiguration
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.3 MEDIUM
CVE-2026-29810 — CyberPanel Logic Error Vulnerability

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

Remote
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
3.5 LOW
CVE-2025-70820 — Zettlab D6 Ultra Path Traversal Vulnerability

Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.

| Path Traversal
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90579 — cheshire-cat-ai Cheshire Cat AI custom_auth_handler.py _authorize_http_key missing authen…

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of t…

Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.3 MEDIUM
CVE-2026-90578 — GPAC MP4Box list.c gf_list_count use after free

A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after fre…

| Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.3 MEDIUM
CVE-2026-90577 — GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow

A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a ma…

| Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
3.3 LOW
CVE-2026-90576 — GPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereference

A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation …

| Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.3 MEDIUM
CVE-2025-70819 — Zettlab D6 Ultra Arbitrary File System Mount Vulnerability

Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.

| Path Traversal
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
1.8 LOW
CVE-2025-64059 — Grav Stored Cross-Site Scripting

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and u…

grav | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
3.0 LOW
CVE-2025-45480 — Floodlight Link Spoofing Vulnerability

Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.

floodlight | Misconfiguration
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.0 MEDIUM
CVE-2020-15875 — LibreNMS SQL Injection Vulnerability

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase par…

Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
Showing 20 of 13135 Results