Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2026-77401 — Zope AccessControl: Information disclosure through Python string `format` and `format_map…

Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safel…

Remote | Information Disclosure
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.9 MEDIUM
CVE-2026-77119 — NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 v…

bind | Remote | Misconfiguration
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.4 HIGH
CVE-2026-76825 — RestrictedPython: Sandbox escape via string.Formatter field resolution

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a c…

Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.5 HIGH
CVE-2026-76163 — named aborts on a TKEY query when the user configuration has no global options statement

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected progr…

bind | Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.3 MEDIUM
CVE-2026-75029 — Message parser retains every identical singleton RDATA, enabling wire-to-work amplificati…

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended t…

bind | Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.1 HIGH
CVE-2026-74909 — Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enf…

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web a…

single_sign-on build_of_keycloak | Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.1 HIGH
CVE-2026-63671 — @nuxtjs/mdc: the URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS fro…

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and reli…

Remote | Cross-Site Scripting
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.5 HIGH
CVE-2026-63128 — RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transpo…

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an un…

Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.2 HIGH
CVE-2026-63127 — RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from Resource…

Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.3 MEDIUM
CVE-2026-61709 — OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-incl…

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an in…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.3 MEDIUM
CVE-2026-19668 — Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "ma…

bind | Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.5 HIGH
CVE-2026-19666 — Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affect…

bind | Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
6.5 MEDIUM
CVE-2026-19033 — Unauthenticated IXFR deltas are applied to the live zone before TSIG verification

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an a…

bind | Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.5 HIGH
CVE-2026-18212 — Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompres…

single_sign-on data_grid build_of_keycloak | Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
4.4 MEDIUM
CVE-2025-36591 — Dell ECS and ObjectScale Use of a Broken or Risky Cryptographic Algorithm Vulnerability

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with …

elastic_cloud_storage | Cryptography
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.1 HIGH
CVE-2026-92469 — microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated …

microservices-platform | Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-92468 — microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via search-center

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specify…

microservices-platform | Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.7 HIGH
CVE-2026-92467 — microservices-platform through 6.0.0 Unverified Password Change via /users/password

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by…

microservices-platform | Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.8 HIGH
CVE-2026-92466 — microservices-platform through 6.0.0 Missing Authorization via Disabled URL Permission Ch…

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks af…

microservices-platform | Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.3 MEDIUM
CVE-2026-92365 — vllm-project vllm thinking_budget_state.py algorithmic complexity

A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inef…

vllm | Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
Showing 20 of 14707 Results