Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-92893 — Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, exp…

A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with …

satellite satellite | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.3 MEDIUM
CVE-2026-92894 — Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model override value …

A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the ca…

satellite satellite | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.0 HIGH
CVE-2026-78428 — Flaw in Nuevector can result in one user receiving another user's authenticated session w…

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurre…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.3 MEDIUM
CVE-2026-78427 — Admission Control Bypass via Hardcoded Sidecar Image Exemption

The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely …

Remote | Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
3.7 LOW
CVE-2026-78426 — Logout bypass via alternate JWT spelling

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continu…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.6 HIGH
CVE-2026-78425 — SAML Audience Confusion Allows Cross-SP Authentication

Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.4 HIGH
CVE-2026-50610 — Improper Access control Vulnerability in NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated lo…

| Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.4 HIGH
CVE-2026-50609 — Unauthorized Registry Modification Vulnerability in NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service may allow a…

| Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
1.2 LOW
CVE-2026-50608 — Authentication Vulnerability in NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before…

| Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.2 CRITICAL
CVE-2026-15688 — Password Authentication Bypass Vulnerability in GX Works3 and Motion Control Setting

Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invali…

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.3 MEDIUM
CVE-2026-87831 — Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Customer A…

The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated us…

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.3 MEDIUM
CVE-2026-87829 — Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Unvalidate…

The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated us…

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.8 HIGH
CVE-2026-86320 — Flatpak-builder: host code execution via `git am` hook execution in patch source extracti…

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch…

enterprise_linux enterprise_linux | Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
2.7 LOW
CVE-2026-50607 — WebSocket Exposure Vulnerability in NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which m…

Remote | Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
1.2 LOW
CVE-2026-50606 — Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and Pred…

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key withi…

| Cryptography
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.4 HIGH
CVE-2026-50605 — Privilege Escalation Vulnerability in NitroSense and PredatorSense Software

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated…

| Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
3.7 LOW
CVE-2026-91017 — Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Fo…

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-90982 — @fastify/static vulnerable to route guard bypass via path case-folding

@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume,…

fastify-static | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.6 HIGH
CVE-2026-87963 — Yo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username Parameter

The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escap…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-86801 — To Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via U…

The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, a…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14855 Results