Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-89011 — isomorphic-git < 1.42.0 Prototype Pollution via getRemoteInfo

isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted …

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.3 HIGH
CVE-2026-89087 — cstruct OCaml Out-of-Bounds Access Vulnerability

The cstruct package before 6.3.0 for OCaml mishandles indexes.

Remote | Memory Corruption
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.1 CRITICAL
CVE-2026-89086 — jose OCaml Improper RSA Signature Validation

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required st…

Remote | Cryptography
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.2 HIGH
CVE-2026-89054 — OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configura…

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every…

horizon | Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-84432 — Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog contr…

Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action cre…

Remote | Cross-Site Request Forgery
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-9338 — IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple …

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excess…

websphere_application_server | Remote | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-9336 — IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple …

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit t…

websphere_application_server | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.9 CRITICAL
CVE-2026-89049 — Server-side request forgery in the Session Manager port forwarding functionality in AWS S…

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agen…

Remote | Server-Side Request Forgery
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-88060 — Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in F…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side renderin…

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
4.0 MEDIUM
CVE-2026-88059 — Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaP…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common Ht…

Remote | Information Disclosure
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-88058 — Angular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Con…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side renderin…

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-88057 — Angular: Sanitization bypass via directive host bindings on concrete host elements in @an…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runti…

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-88056 — Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Renderin…

Remote | Server-Side Request Forgery
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.3 HIGH
CVE-2026-88036 — GridFS data disclosure and deletion via query-operator injection in file IDs in the Mongo…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query con…

c_driver | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.7 MEDIUM
CVE-2026-88035 — Heap buffer overflow via wrapped size check during SASL username canonicalization in Mong…

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able …

c_driver | Memory Corruption
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.3 HIGH
CVE-2026-88034 — GridFS data disclosure and deletion via query-operator injection in file IDs in the Mongo…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query c…

c_driver | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.3 HIGH
CVE-2026-88033 — GridFS data disclosure and deletion via query-operator injection in file IDs in the Mongo…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query …

java_driver | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.2 HIGH
CVE-2026-88032 — Application denial of service via cancellation race in reactive client-side encryption in…

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the …

java_driver | Remote | Memory Corruption
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-88021 — Consul vulnerable to an authorization bypass in the Connect service mesh

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy …

consul | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.7 HIGH
CVE-2026-87993 — Consul-template vulnerable to an information disclosure issue in error handling

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downst…

| Information Disclosure
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Showing 20 of 13372 Results