Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-81934 — Redis TLS pending-data list use-after-free

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated att…

Remote | Memory Corruption
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
4.8 MEDIUM
CVE-2026-81931 — Unrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows…

Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero Flow CRM before 5.16.0 allows an authenticated user holding the create product permission (routine Selle…

prospero_flow_crm | Remote | Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
4.7 MEDIUM
CVE-2026-81893 — Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile…

enterprise_linux enterprise_linux | Memory Corruption
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.1 HIGH
CVE-2026-81838 — Zip Slip Arbitrary File Write in AWS diagram-as-code (awsdac)

A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesys…

| Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-81834 — RooCodeInc Roo-Code README File ExecaTerminalProcess code injection

A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminalProcess of the component README File Handler. Executing a manipulation can lead…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.5 MEDIUM
CVE-2026-81833 — RooCodeInc Roo-Code CodeIndexManager helpers.ts optimizeQuery code injection

A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function optimizeQuery of the file src/utils/helpers.ts of the component CodeIndexManage…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.4 MEDIUM
CVE-2026-81731 — Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description

Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description field of the Workspace Link doctype is declared with "ignore_xss_filter": 1 in …

Remote | Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.8 HIGH
CVE-2026-81730 — Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename

Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/email…

Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.1 HIGH
CVE-2026-81729 — Dolibarr before 23.0.4 Incorrect Authorization on REST API Document Deletion

Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/class/api_documents.class.php calls dol_check_secure_access_document() wit…

Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.6 HIGH
CVE-2026-81728 — Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies onl…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.8 MEDIUM
CVE-2026-81530 — KMS master key exposure via unredacted credential serialization in driver settings string

A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in th…

c_driver | Cryptography
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.1 HIGH
CVE-2026-81529 — Connection-option injection via unescaped settings in the canonical MongoDB URL builder

Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connectio…

c_driver | Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.4 MEDIUM
CVE-2026-81528 — NoSQL injection via array replacement bypassing update shape validation in driver write p…

A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a value supplied as a replacement is forwarded to the server witho…

c_driver | Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.9 MEDIUM
CVE-2026-81527 — NoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translation

A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When application…

c_driver | Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.1 HIGH
CVE-2026-81526 — Cross-database write redirection via unvalidated dotted database name in bulk write names…

The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. An actor able to influence that identi…

rust_driver | Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.6 HIGH
CVE-2026-81525 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP D…

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database opera…

php_driver | Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.4 MEDIUM
CVE-2026-81524 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Dri…

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an…

c_driver | Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
4.4 MEDIUM
CVE-2026-81523 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in libmongoc…

A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact i…

libmongocrypt | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.6 HIGH
CVE-2026-81522 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ D…

A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier fro…

c_driver | Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.1 HIGH
CVE-2026-81521 — Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite…

The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the…

go_driver | Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Showing 20 of 12336 Results