Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-101187 — Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injection

A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device …

zhome_a0101 | Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
4.3 MEDIUM
CVE-2026-101146 — Eleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit informat…

A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.createAndSaveAudit of the file /qm/cz.zoom.scorecard.webui.Scorecard/QMUtilsServic…

quality_management | Remote | Information Disclosure
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
4.3 MEDIUM
CVE-2026-101145 — Eleveo Call Recording Software User Management userAddAction.do ldap injection

A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such manipulati…

call_recording_software | Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-101144 — Eleveo Call Recording Software Query Builder searchAction.do access control

A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes impr…

call_recording_software | Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.0 HIGH
CVE-2026-100392 — InvoicePlane: Primary Administrator Privilege Downgrade via `Users::form()` (Missing Obje…

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Seco…

invoiceplane | Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.7 HIGH
CVE-2026-100371 — InvoicePlane: Incomplete Authorization Remediation in Users::form() Enables Primary Admin…

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address a previo…

invoiceplane | Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
4.7 MEDIUM
CVE-2026-100370 — DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerousUrl() Allows…

DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href and xlink:href attributes. …

Remote | Cross-Site Scripting
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-96760 — Authlib library contains a signature‑verification bypass vulnerability

Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as su…

authlib | Cryptography
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.1 HIGH
CVE-2026-93355 — LiteLLM Weak JWT Authentication via Email-Based User Lookup

LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-base…

litellm | Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.8 HIGH
CVE-2026-87741 — ConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via 'style' Param…

The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action…

convertplus | Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.8 HIGH
CVE-2026-86950 — Apple Kernel Out-of-Bounds Write Vulnerability

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously craft…

macos iphone_os ipados macos | Remote | Memory Corruption
Sep 28, 2026 Sep 29, 2026
Sep 28, 2026
Sep 29, 2026
7.8 HIGH
CVE-2026-102004 — VxWorks 7

Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09

vxworks | Memory Corruption
Sep 28, 2026 Sep 29, 2026
Sep 28, 2026
Sep 29, 2026
3.7 LOW
CVE-2026-101915 — @grpc/grpc-js: The server transmits some error messages thrown by method handlers to the …

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws an uncaught error, the server …

Remote | Information Disclosure
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-101914 — @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for c…

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comp…

Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
4.3 MEDIUM
CVE-2026-101143 — Eleveo Quality Management QMBODownload information disclosure

A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of the file /qm/cz.zoom.scorecard.webui.Scorecard/cz.zoom.scorecard.webui.Scorecard/…

quality_management | Remote | Information Disclosure
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-101142 — Eleveo Quality Management Questionnaire Audio Upload Scorecard.jsp path traversal

A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component Questionnaire Audio Upload. Th…

quality_management | Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
4.0 MEDIUM
CVE-2026-101141 — Eleveo Call Recording Software Play Audio audio.jsp cross site scripting

A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio Page. Executing a manipulation of the argumen…

call_recording_software | Remote | Cross-Site Scripting
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.5 MEDIUM
CVE-2026-97686 — VxWorks 7 Memory Resource leak

Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminatin…

vxworks | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.1 HIGH
CVE-2026-97023 — Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy di…

A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment…

enterprise_linux flatpak enterprise_linux | Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-84894 — Moxygen Use-After-Free Vulnerability

In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote pe…

| Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
Showing 20 of 14293 Results