Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.3 HIGH
CVE-2026-9816 — Insufficient server-side validation of board member role fields permits privilege escalat…

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or n…

Aug 17, 2026 Aug 19, 2026
Aug 17, 2026
Aug 19, 2026
5.0 MEDIUM
CVE-2026-75077 — SourceCodester Class and Exam Timetabling System BSCE2.php cross site scripting

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such manipulation of the argument …

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Aug 17, 2026 Aug 20, 2026
Aug 17, 2026
Aug 20, 2026
9.6 CRITICAL
CVE-2026-71424 — Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers

Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization h…

onyx | Remote | Information Disclosure
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
7.1 HIGH
CVE-2026-69148 — MLflow: CreateModelVersion source validation does not check READ permission on referenced…

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_sourc…

mlflow | Remote | Authorization
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
6.5 MEDIUM
CVE-2026-69146 — MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlfl…

mlflow | Remote | Authorization
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
9.8 CRITICAL
CVE-2026-67960 — PbootCMS Arbitrary Code Execution Vulnerability

An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components

Remote | Injection
Aug 17, 2026 Aug 31, 2026
Aug 17, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-67918 — Hermes Studio Directory Traversal Vulnerability

Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint

Remote | Path Traversal
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-67868 — S2OPC Heap-Based Out-of-Bounds Write Vulnerability

A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary cod…

Remote | Memory Corruption
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-67854 — Qcms SQL Injection Vulnerability

SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

Remote | Injection
Aug 17, 2026 Aug 31, 2026
Aug 17, 2026
Aug 31, 2026
4.3 MEDIUM
CVE-2026-65351 — Apple Safari Denial of Service Vulnerability

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Proces…

macos iphone_os safari ipados safari macos +1 more | Remote | Denial of Service
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
6.6 MEDIUM
CVE-2026-65349 — Apple Kernel Out-of-Bounds Read

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An a…

macos iphone_os tvos watchos ipados macos +2 more | Memory Corruption
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
6.5 MEDIUM
CVE-2026-65347 — Apple ImageIO Denial of Service Vulnerability

The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-se…

macos iphone_os tvos watchos ipados macos +2 more | Remote | Denial of Service
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
8.8 HIGH
CVE-2026-65346 — Apple Image Processing Integer Overflow Vulnerability

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Proces…

macos iphone_os tvos watchos ipados macos +2 more | Remote | Memory Corruption
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-65343 — Apple iOS and macOS Use-After-Free Vulnerability

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. A remote attacker may …

macos iphone_os tvos watchos ipados macos +2 more | Remote | Memory Corruption
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
5.4 MEDIUM
CVE-2026-65341 — Apple WebKit Memory Corruption

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, wa…

macos iphone_os tvos watchos safari ipados +4 more | Remote | Memory Corruption
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
4.3 MEDIUM
CVE-2026-65340 — Apple Safari Denial of Service Vulnerability

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Proces…

Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
5.0 MEDIUM
CVE-2026-65339 — Apple iOS and iPadOS and macOS Information Disclosure Vulnerability

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to …

macos iphone_os tvos watchos ipados macos +2 more | Information Disclosure
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
4.3 MEDIUM
CVE-2026-65338 — Apple Safari Memory Corruption Vulnerability

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing …

macos iphone_os safari ipados safari macos +1 more | Remote | Memory Corruption
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
4.3 MEDIUM
CVE-2026-65337 — Apple Safari Memory Corruption Vulnerability

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Proces…

macos iphone_os safari ipados safari macos +1 more | Remote | Denial of Service
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
4.3 MEDIUM
CVE-2026-65336 — Apple Safari Denial of Service Vulnerability

This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Proces…

macos iphone_os safari ipados safari macos +1 more | Remote | Denial of Service
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
Showing 20 of 14636 Results