Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.2 CRITICAL
CVE-2026-101276 — iperf Heap Use-After-Free Vulnerability

iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so …

Remote | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2024-58387 — Inspur HCM Cloud Arbitrary File Read via file/download Endpoint

Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying…

Remote | Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2023-54403 — Yonyou U8 CRM Arbitrary File Read via getemaildata.php

Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 pa…

Remote | Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2023-54402 — iDocView SSRF via /doc/upload Endpoint Hardcoded Token

iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token v…

Remote | Server-Side Request Forgery
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.3 MEDIUM
CVE-2026-103548 — Improperly Stored Credentials

Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user.

Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.2 CRITICAL
CVE-2026-103547 — OpenBSD ldapd Authentication Correlation Vulnerability

In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. Aft…

openbsd | Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.0 MEDIUM
CVE-2026-103387 — garycourt uri-js Mailto Header mailto.ts URI.parse uncaught exception

A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the …

uri-js | Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-102994 — pypdf: Possible long runtimes/large memory usage when parsing indirect objects

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whites…

pypdf | Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.7 HIGH
CVE-2026-102993 — pypdf: Possible large memory usage when retrieving Roman page labels

pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively la…

pypdf | Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.2 CRITICAL
CVE-2026-102992 — piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadB…

piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applic…

Remote
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
6.5 MEDIUM
CVE-2026-102991 — Mako: Path traversal via drive-letter URI on Windows in TemplateLookup

Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/temp…

mako | Remote | Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.2 HIGH
CVE-2026-102990 — basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing p…

basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LIN…

basic-ftp | Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.5 HIGH
CVE-2026-101885 — ZeroClaw before 0.8.5 Path Traversal via Plugin Manifest wasm_path

ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convinc…

| Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.7 HIGH
CVE-2026-101884 — OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override

OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Atta…

openclaw | Remote | Injection
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.4 MEDIUM
CVE-2026-101883 — OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present

OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers w…

openclaw | Remote | Server-Side Request Forgery
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.8 HIGH
CVE-2026-101882 — OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set

OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundl…

openclaw | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-101881 — OpenClaw Windows Node before 2026.7.1 Denial of Service

OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attack…

openclaw | Remote | Denial of Service
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.8 HIGH
CVE-2026-101880 — OpenClaw Windows Node before 2026.7.1 Authorization Bypass

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators o…

openclaw | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-101879 — OpenClaw Windows Node before 2026.7.1-3 Missing Authorization

OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera sna…

openclaw | Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
8.8 HIGH
CVE-2026-97291 — WordPress Schema & Structured Data for WP & AMP plugin <= 1.66 - PHP Object Injection vul…

Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.

Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Showing 20 of 14965 Results