Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-105747 — Docling: METS-GBS archive member limit enforced after full member enumeration (memory exh…

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.131.0, METS-GBS format detection in docling/datamode…

docling | Remote | Denial of Service
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
2.2 LOW
CVE-2026-105746 — Docling: KServe v2 OCR engine does not enforce enable_remote_services

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.83.0 until 2.131.0, the KServeV2OcrModel class defined in docling…

docling | Remote | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.7 MEDIUM
CVE-2026-105745 — Docling: Plugin entry points are imported before the allow_external_plugins check

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.27.0 until 2.131.0, Docling plugin factories in docling/models/fa…

docling | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.5 HIGH
CVE-2026-105744 — Docling: Arbitrary file read/write (and command execution when shell-escape is enabled) w…

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tik…

docling | Remote | Information Disclosure
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.0 MEDIUM
CVE-2026-105743 — Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi-record reso…

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.91.0 until 2.132.0, validate_url_safety in docling/backend/utils/…

docling | Remote | Server-Side Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
3.7 LOW
CVE-2026-105742 — Docling: Configured HTTP headers sent to every remote image host named by a document

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.95.0 until 2.132.0, the HTML image resource loader in docling/bac…

docling | Remote | Server-Side Request Forgery
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.5 HIGH
CVE-2026-105468 — girishsaraf Online-Appointment-Booking-System Login mlogin.php mysqli_query sql injection

A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the c…

online-appointment-booking-system | Remote | Injection
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
4.3 MEDIUM
CVE-2026-103546 — Improper validation of Ops Manager configuration in MongoDB Kubernetes Operator

In MongoDB Controllers for Kubernetes, insufficient validation of Ops Manager backup configuration may allow a user who can modify an OpsManager custom resource to cause unintended administrative cha…

Remote | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.9 MEDIUM
CVE-2026-103433 — Bake filesystem entitlement consent is skipped for certain secret and oci-layout definiti…

Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpre…

Remote | Path Traversal
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
5.4 MEDIUM
CVE-2026-0482 — AMD Versal Adaptive SoC USB Boot Buffer Overflow

In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot mode—when enabled through board modifications—could allow crafted images to trigger a buffer overflow and overwrite an ac…

| Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.5 HIGH
CVE-2026-0461 — AMD Zynq UltraScale+ MPSoC and RFSoC USB Boot Mode Buffer Overflow Vulnerability

Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow…

| Memory Corruption
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
0.0 NA
CVE-2026-105469 — girishsaraf Online-Appointment-Booking-System AJAX Endpoint get_town.php sql injection

A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the…

Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.0 MEDIUM
CVE-2026-93326 — Crafted Git build source can bypass certain policy validation

A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look like it is coming from a different remote …

buildkit | Remote | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.8 MEDIUM
CVE-2026-84900 — HP ThinPro 8.1 SP10 and ThinPro 9 SP3 Security Updates

Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.1 SP10, which includes updates to mitigate potential vu…

thinpro | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
9.2 CRITICAL
CVE-2026-77226 — Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint

Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability …

Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.3 HIGH
CVE-2026-105773 — Canimaan Software ClamXAV local privilege escalation

Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability in the Privileged Helper Tool caused by a race condition and insufficient file validation, allowing a…

| Race Condition
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
6.3 MEDIUM
CVE-2026-105768 — apko /etc/passwd and /etc/group UID/GID truncation writes package-supplied entries as root

apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5, UserEntry.Parse and GroupEntry.Parse in pkg/passwd read the UID and GI…

apko | Remote | Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.1 HIGH
CVE-2026-105741 — Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write

Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation end…

langflow | Remote | Misconfiguration
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
9.9 CRITICAL
CVE-2026-105740 — Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary …

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP s…

langflow | Remote | Authentication
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
7.1 HIGH
CVE-2026-105699 — Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers

Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow authenticated access to the project identifier in a project-scoped MCP connection but d…

langflow | Remote | Authorization
Oct 05, 2026 Oct 05, 2026
Oct 05, 2026
Oct 05, 2026
Showing 20 of 14499 Results