Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-100884 — Krayin laravel-crm attachment-download Endpoint acl.php resource injection

A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachme…

laravel-crm | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.3 LOW
CVE-2026-96283 — Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongo…

By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to s…

enterprise_linux enterprise_linux | Denial of Service
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.1 LOW
CVE-2026-96282 — Flatpak: flatpak: extension metadata path traversal file existence oracle

A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications us…

enterprise_linux enterprise_linux | Remote | Path Traversal
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.3 LOW
CVE-2026-100882 — Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting

A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the compone…

laravel-crm | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
2.6 LOW
CVE-2026-100881 — zhistaredu StarTraining application.yml cross site scripting

A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enable…

startraining | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
0.0 NA
CVE-2026-100883 — Krayin laravel-crm acl.php access control

A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to imprope…

laravel-crm | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
2.5 LOW
CVE-2026-96284 — Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci sym…

A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when impor…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.2 MEDIUM
CVE-2026-96281 — Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system ap…

On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper Rem…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.5 HIGH
CVE-2026-96280 — Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent ope…

enterprise_linux enterprise_linux | Remote | Memory Corruption
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.8 CRITICAL
CVE-2026-101090 — Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oau…

Remote | Injection
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.1 LOW
CVE-2026-101089 — Nezha before 2.2.7 Information Disclosure via /api/v1/profile

Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract pas…

Remote | Information Disclosure
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.0 MEDIUM
CVE-2026-101088 — Nezha before 2.3.1 Denial of Service via Concurrent Server Delete

Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously report…

Remote | Denial of Service
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
5.3 MEDIUM
CVE-2026-101087 — Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6

Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges — specifically…

Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101086 — Nezha Dashboard before 2.3.5 Task Type Validation Bypass

Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types…

Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101085 — Nezha before 2.3.8 Denial of Service via Alert Rule

Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluat…

Remote | Denial of Service
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.6 CRITICAL
CVE-2026-101084 — obot before v0.21.1 Authorization Bypass via /mcp-connect

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Att…

Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.8 CRITICAL
CVE-2026-101065 — Obot Quickstart Docker Deployment Unauthenticated Admin Access

Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080…

Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.3 HIGH
CVE-2026-101064 — Obot before v0.23.0 Server-Side Request Forgery via MCP

Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attac…

Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.9 MEDIUM
CVE-2026-101063 — Obot before v0.23.0 Authentication Bypass via Registry API

Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata inclu…

Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.8 HIGH
CVE-2026-101062 — Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration

Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on …

Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
Showing 20 of 14032 Results