Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-84437 — OpenCart Autocomplete Workflow address.php cross site scripting

A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autocomplete Workflow. The manip…

| Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84715 — FeatherPanel before 1.3.7.10 Privilege Escalation via Subuser Permission Update

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser wi…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.7 HIGH
CVE-2026-84485 — APITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load o…

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team h…

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.7 HIGH
CVE-2026-84484 — ION-DTN before 4.2.0 Out-of-Bounds Read via decodeSdnv

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Atta…

Remote | Memory Corruption
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.7 HIGH
CVE-2026-84702 — facefusion before 3.7.0 Path Traversal via Job Identifier

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job ide…

Remote | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-84701 — NocoBase Rich Text Field Stored Cross-Site Scripting via API

NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup throug…

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84700 — Pika Unauthenticated Replication Access via Internal Protobuf Port

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authentica…

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.3 CRITICAL
CVE-2026-84699 — Team Password Manager before 14.184.308 Authentication Bypass in Password Reset

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenti…

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.1 HIGH
CVE-2026-84698 — PX4 Autopilot sd_bench Heap Buffer Overflow via Block Size

PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a bl…

| Memory Corruption
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.9 MEDIUM
CVE-2026-84697 — Mailpit SSRF Deny List Bypass via Azure Metadata and IPv6 Prefix

Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal…

mailpit | Remote | Server-Side Request Forgery
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.3 CRITICAL
CVE-2026-84696 — Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypa…

| Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.3 CRITICAL
CVE-2026-84695 — BookStack before 26.05.4 Stored XSS via Drawing Upload

BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attacker…

bookstack | Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84694 — Coolify before 4.2.0 Remote Code Execution via Environment Variable Key

Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into envi…

coolify | Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-84430 — gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes

A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpo…

Remote
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.3 MEDIUM
CVE-2026-84427 — zhayujie CowAgent Bash Tool bash.py denial of service

A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to …

cowagent | Remote | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.3 MEDIUM
CVE-2026-84425 — zhayujie CowAgent Browser Tool browser_tool.py BrowserTool denial of service

A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulat…

cowagent | Remote | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-84431 — AirAsia MOVE App com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRealPath path …

A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Perform…

| Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-84359 — Google Chrome Skia Cross-Origin Information Disclosure

Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium securi…

chrome chrome | Information Disclosure
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-84358 — Google Chrome Downloads Improper Privilege Management Address Bar Spoofing

Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Ch…

chrome chrome | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-84357 — Google Chrome Omnibox Improper Input Validation

Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium…

chrome chrome | Misconfiguration
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
Showing 20 of 12555 Results