Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-96609 — Robur Albatross Ring Buffer Denial of Service Vulnerability

Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condition. This is only exploitable by users …

Remote | Denial of Service
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.0 HIGH
CVE-2026-96600 — Isotope eCommerce through 2.9.10 SQL Injection via Backend Callbacks

Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL …

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.2 HIGH
CVE-2026-96599 — Isotope eCommerce through 2.9.10 Weak Order Identifier Generation

Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, allowing unauthenticated attackers to guess identifiers. Guest orders lack owner…

Remote | Authentication
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
0.0 NA
CVE-2026-96276 — Flatpak: flatpak: arbitrary write in host context via flatpak build-init

If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files…

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-96275 — Flatpak: flatpak: arbitrary write access as root via extra-data extraction

A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as ro…

enterprise_linux enterprise_linux | Remote | Path Traversal
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-92419 — IDOR in WEBCON BPS

WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedPeople parameter in the Gantt vacation chart API does not validate whether the r…

webcon_bps | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-92164 — Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files

Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSession mounts a FileAdapter for the file scheme and inherits redirect handling fr…

streamlink | Remote | Path Traversal
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.4 MEDIUM
CVE-2026-88974 — WPGraphQL: Contributor can publish and modify posts without the required capabilities via…

WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post…

wpgraphql | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-73858 — Solspace Freeform: Limited Twig template injection via submitted field values

Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be evaluated by the isolated Twig render…

freeform | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-73591 — Dell Secure Connect Gateway Information Exposure Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote ac…

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.3 MEDIUM
CVE-2026-73589 — Dell Secure Connect Gateway Policy Manager Weak Encoding for Password Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local acces…

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.4 HIGH
CVE-2026-73588 — Dell Secure Connect Gateway Policy Manager Missing Authentication for Critical Function V…

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access c…

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.8 MEDIUM
CVE-2026-73587 — Dell Secure Connect Gateway Improper Certificate Validation Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access cou…

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.4 MEDIUM
CVE-2026-73586 — Dell Secure Connect Gateway Insufficient Session Expiration Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could…

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
3.7 LOW
CVE-2026-71178 — Dell Secure Connect Gateway Policy Manager Improper Authorization Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with …

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.4 MEDIUM
CVE-2026-71177 — Dell Secure Connect Gateway Improper Restriction of Rendered UI Layers or Frames Vulnerab…

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote a…

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.8 MEDIUM
CVE-2026-63002 — REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames

REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync pag…

Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.8 MEDIUM
CVE-2026-63001 — REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`

REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_manager/lib/media_manager.php inserts a Media Manager type name into raw backen…

Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.4 MEDIUM
CVE-2026-63000 — REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates

REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/install/lib/api/api_package_update.php inherits the false default from rex_api_fu…

Remote | Cross-Site Request Forgery
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
4.3 MEDIUM
CVE-2026-62998 — REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration

REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortab…

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14282 Results