Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-26084 — Fortinet FortiSandbox Improper Access Control Vulnerability

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 m…

Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.9 MEDIUM
CVE-2026-22575 — Fortinet FortiManager Improper Access Control Vulnerability

An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiM…

Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-20293 — Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for…

Sep 08, 2026 Sep 11, 2026
Sep 08, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-16497 — NVIDIA Triton Inference Server Denial of Service Vulnerability

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.

triton_inference_server | Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-86853 — Repeated external URL scheme launches could potentially cause a denial of service in Fire…

A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is clos…

firefox firefox_mobile | Remote | Denial of Service
Sep 08, 2026 Oct 05, 2026
Sep 08, 2026
Oct 05, 2026
9.1 CRITICAL
CVE-2026-86840 — Bifrost Unauthorized Channel Commission Attribution Allows Commission Diversion

The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` …

Remote | Authorization
Sep 08, 2026 Sep 10, 2026
Sep 08, 2026
Sep 10, 2026
9.3 CRITICAL
CVE-2026-86738 — Snipe-IT before 8.7.0 CSS Injection via Custom CSS

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Su…

snipe-it | Remote | Injection
Sep 08, 2026 Sep 09, 2026
Sep 08, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-86737 — snipe-it before 8.7.0 Missing Authorization via barcode endpoint

snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate…

snipe-it | Remote | Authorization
Sep 08, 2026 Sep 10, 2026
Sep 08, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-86736 — snipe-it before 8.7.0 Checkout Request Counter Integrity Failure

snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions…

snipe-it | Remote | Denial of Service
Sep 08, 2026 Sep 19, 2026
Sep 08, 2026
Sep 19, 2026
5.9 MEDIUM
CVE-2026-86735 — snipe-it before 8.7.0 SSRF via IPv6 transition address bypass

snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Att…

snipe-it | Remote | Server-Side Request Forgery
Sep 08, 2026 Sep 09, 2026
Sep 08, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86734 — Snipe-IT before 8.7.1 Denial of Service via Unbounded Note Field

Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous…

snipe-it | Remote | Denial of Service
Sep 08, 2026 Sep 10, 2026
Sep 08, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-86733 — Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore

Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets line…

snipe-it | Remote | Injection
Sep 08, 2026 Sep 09, 2026
Sep 08, 2026
Sep 09, 2026
8.8 HIGH
CVE-2026-86732 — Craft CMS before 5.10.12 Remote Code Execution via element-index

Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the cr…

craft_cms cms | Remote | Authentication
Sep 08, 2026 Sep 10, 2026
Sep 08, 2026
Sep 10, 2026
7.1 HIGH
CVE-2026-86731 — Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersController

Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers…

craft_cms cms | Remote | Authorization
Sep 08, 2026 Sep 19, 2026
Sep 08, 2026
Sep 19, 2026
8.8 HIGH
CVE-2026-86730 — Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE

Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attac…

craft_cms cms | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.1 CRITICAL
CVE-2026-86729 — WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize

WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a ra…

avideo | Remote | Authentication
Sep 08, 2026 Sep 10, 2026
Sep 08, 2026
Sep 10, 2026
8.7 HIGH
CVE-2026-86728 — AVideo through 29.0 Unauthenticated Disclosure via epg.json.php

AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can re…

avideo | Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-86727 — AVideo through 29.0 Information Disclosure via stats.json.php

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoin…

avideo | Remote | Information Disclosure
Sep 08, 2026 Sep 10, 2026
Sep 08, 2026
Sep 10, 2026
7.1 HIGH
CVE-2026-86726 — AVideo through 29.0 Information Disclosure via restreamsActive.json.php

AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other stream…

avideo | Remote | Information Disclosure
Sep 08, 2026 Sep 19, 2026
Sep 08, 2026
Sep 19, 2026
7.1 HIGH
CVE-2026-86725 — AVideo SocialMediaPublisher Missing Authorization via add.json.php

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to mo…

avideo | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
Showing 20 of 15616 Results