Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-102279 — Laravel: XSS in Debug Page Information

Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML …

framework | Cross-Site Scripting
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-102278 — brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exha…

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once pe…

brace-expansion | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
3.6 LOW
CVE-2026-97027 — Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bu…

Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowli…

enterprise_linux enterprise_linux | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
3.9 LOW
CVE-2026-97026 — Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path

Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modi…

enterprise_linux enterprise_linux | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
3.2 LOW
CVE-2026-97025 — Flatpak: flatpak: world-readable oci authentication token in system-helper cache path

Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the tok…

enterprise_linux enterprise_linux | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-102277 — brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of se…

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns …

brace-expansion | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-102276 — brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhausti…

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseC…

brace-expansion | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-102265 — PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs…

| Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.5 MEDIUM
CVE-2026-102006 — VxWorks 7 Memory allocation

In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the callin…

vxworks | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-102275 — PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion

PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare t…

| Cryptography
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-101187 — Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injection

A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device …

| Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-91096 — Proxygen WebTransport Use-After-Free Vulnerability

In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for s…

proxygen | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-91095 — Proxygen Use-After-Free Vulnerability

In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handl…

proxygen | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-84895 — Proxygen Use-After-Free Vulnerability

In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies th…

proxygen | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-102274 — PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set

PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in…

| Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-102273 — PyJWT accepts public JWK containers as HMAC secrets

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms a…

| Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-102272 — PyJWT BOM Bypass

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted…

| Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-102271 — PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217…

PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are abse…

| Cryptography
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-101146 — Eleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit informat…

A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.createAndSaveAudit of the file /qm/cz.zoom.scorecard.webui.Scorecard/QMUtilsServic…

quality_management | Information Disclosure
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-102270 — PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certifica…

| Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
Showing 20 of 14242 Results