Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-86451 — MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects

Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether the requester is authorize…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
2.3 LOW
CVE-2026-86441 — MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hid…

Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.1 MEDIUM
CVE-2026-86440 — MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs

Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous rendere…

Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-86435 — commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with dupl…

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-86434 — commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision

league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on e…

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-86433 — commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling li…

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.9 MEDIUM
CVE-2026-86432 — commonmark 2.0.0 before 2.8.4 Denial of Service via XML

commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested M…

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.2 HIGH
CVE-2026-86431 — commonmark before 2.9.1 XSS via AttributesExtension form feed bypass

league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C for…

commonmark | Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-86430 — league/commonmark before 2.9.1 Denial of Service via parsing

league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform …

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-86429 — commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes

The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extensio…

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-86428 — commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes

commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numer…

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.8 HIGH
CVE-2026-86427 — LibreNMS before 26.8.0 Argument Injection via graph_title

LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-qu…

Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.2 CRITICAL
CVE-2026-86426 — LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string …

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
4.8 MEDIUM
CVE-2026-86425 — ImageMagick before 7.1.2-30 Heap-use-after-free via Layer

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger me…

| Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
2.5 LOW
CVE-2026-86424 — ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink s…

| Race Condition
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
4.8 MEDIUM
CVE-2026-86423 — ImageMagick before 7.1.2-30 Heap-use-after-free via GetList

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after…

| Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
3.3 LOW
CVE-2026-86422 — ImageMagick before 7.1.2-30 Path Policy TOCTOU Symlink Race

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink r…

| Path Traversal
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.3 MEDIUM
CVE-2026-86421 — ImageMagick before 7.1.2-30 Memory Leak via MSL decoder

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust …

Remote | Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.3 MEDIUM
CVE-2026-86420 — ImageMagick before 7.1.2-30 Denial of Service Memory Budget

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory …

Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.0 HIGH
CVE-2026-86419 — MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed …

Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed …

Remote | Server-Side Request Forgery
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
Showing 20 of 12498 Results