Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-45140 — Chamilo LMS CStudio upload flow allows unauthenticated remote code execution

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory doe…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-15815 — CVE-2026-15815 CVE Record

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin instal…

Remote | Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2025-55787 — MailData Email Archiving System SQL Injection

In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.

| Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2021-3030 — Cute Editor for ASP.NET Reflected Cross-Site Scripting

Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can c…

| Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.5 HIGH
CVE-2026-93337 — NetworkManager-l2tp Privilege Escalation via pppd Plugin Injection

NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu pr…

| Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-92993 — Dromara mayfly-go Machine Script Feature machine_script.go RunMachineScript os command in…

A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machin…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.2 CRITICAL
CVE-2026-92943 — Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.7 MEDIUM
CVE-2026-92758 — Logs may collect sensitive information

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

| Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.8 MEDIUM
CVE-2026-92757 — Malformed connection string may disable field level encryption

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

| Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.8 MEDIUM
CVE-2026-92756 — Combining encryption settings may disable encryption

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leadin…

| Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.6 CRITICAL
CVE-2026-54752 — NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote C…

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cach…

Remote | Supply Chain
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.5 HIGH
CVE-2026-54716 — Valhalla: Degenerate exclude_polygons (collinear points, zero area) causes OOM in /source…

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring f…

Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.8 HIGH
CVE-2026-54692 — SAIL: XBM X10 decoder writes 2 bytes per literal into a 1-byte-per-literal buffer (heap o…

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allo…

| Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.8 CRITICAL
CVE-2026-54627 — SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/he…

Remote | Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.8 CRITICAL
CVE-2026-54626 — SAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch)

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allo…

Remote | Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.4 CRITICAL
CVE-2026-54618 — Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without au…

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exch…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-54594 — OmniBlocks: Spamming in Discussions tab possible via disc.yml

OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invoke…

Remote | Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.3 MEDIUM
CVE-2026-54495 — Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec cont…

The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featurefla…

openfeature | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.5 HIGH
CVE-2026-50285 — Pomerium: Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback

Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an output-memory limit …

pomerium | Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.5 HIGH
CVE-2026-50125 — MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memor…

MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the unauthenticated get_resource tool, whic…

Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14421 Results