Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-54575 — mport package fetch and clean paths are vulnerable to TOCTOU filesystem races

mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util…

| Race Condition
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-8674 — Assertion failure in the DNS stub resolver with a long search domain

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library ver…

| Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-54578 — mport verify can compare stale checksum data after hashing failures

mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stal…

| Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-54586 — mport permits repository and package mirror fetches over insecure transport

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and …

| Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-54585 — mport sample file handling can write outside the configured root

mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manif…

| Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-54580 — mport index decompression can leave partial or corrupt index data after zstd failures

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not c…

| Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-54582 — mport package installation can overwrite existing unmanaged or differently owned files

mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmp…

| Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-54577 — mport audit can inspect the wrong package when options are present

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_…

| Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-54583 — mport package bundle downloads allow unsafe destination filenames

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and …

| Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-54581 — mport bootstrap index fetch can continue after hash verification failure

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a miss…

| Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-28326 — SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

access_rights_manager | Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.1 MEDIUM
CVE-2026-93296 — MISP Overmind: Stored Cross-Site Scripting via Unescaped Object Names in Statistics Legen…

MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card (event_general.ctp) and the server/feed preview card (preview_general.…

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.5 HIGH
CVE-2026-93292 — SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders

SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.1 MEDIUM
CVE-2026-93295 — MISP Background Job Argument Injection via Console Path Switches Enables Remote Code Exec…

MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP conso…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-85716 — AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not verified

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and proce…

| Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.0 HIGH
CVE-2026-93015 — BlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds Write

BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVER response with mor…

| Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.1 HIGH
CVE-2026-93014 — RosarioSIS before 12.9 Path Traversal in File Deletion via filename Parameter

RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers …

Remote | Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-93013 — RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal

RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary fil…

ragflow | Remote | Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-92881 — vgmstream AWB parser awb.c init_vgmstream_awb_memory divide by zero

A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the component AWB parser. Such manipulation leads…

Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.1 CRITICAL
CVE-2026-91039 — dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing …

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a loc…

ash_authentication | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 15357 Results