Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 CRITICAL
CVE-2026-67394 — Plesk for Linux OS Command Injection Privilege Escalation

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerabil…

Remote | Injection
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-65643 — cPanel Eval Injection Remote Code Execution

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

cpanel | Remote | Injection
Sep 01, 2026 Sep 17, 2026
Sep 01, 2026
Sep 17, 2026
3.7 LOW
CVE-2026-48932 — Node.js HTTP Request Smuggling Vulnerability

A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the orig…

node.js | Remote | Misconfiguration
Sep 01, 2026 Sep 03, 2026
Sep 01, 2026
Sep 03, 2026
2.5 LOW
CVE-2026-18743 — Popt-devel: popt-static: short realloc in poptconfigfiletostring

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occ…

Sep 01, 2026 Sep 08, 2026
Sep 01, 2026
Sep 08, 2026
7.8 HIGH
CVE-2026-19820 — Backblaze Client for Windows Improper Link Resolution Vulnerability

A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitat…

Remote | Path Traversal
Sep 01, 2026 Sep 11, 2026
Sep 01, 2026
Sep 11, 2026
Showing 20 of 14965 Results