Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-93310 — O-RAN-SC SMO OAM VES Collector allocation of resources

A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of t…

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-79954 — NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID

NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SP…

cryptolib | Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.4 MEDIUM
CVE-2026-93454 — Aureus ERP through 1.6.0 Stored XSS via Payment Term Note

Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitra…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-93453 — SOGo before 5.12.11 Password Reset Token Interception via Origin Header

SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled dom…

sogo | Remote | Server-Side Request Forgery
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-93452 — snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressibl…

snappy-java | Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.9 MEDIUM
CVE-2026-93451 — snappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methods

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the…

snappy-java | Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-93450 — go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal an…

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attack…

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.3 MEDIUM
CVE-2026-93309 — O-RAN-SC SMO OAM VES Collector allocation of resources

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of …

smo_oam | Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.3 MEDIUM
CVE-2026-93308 — O-RAN-SC SMO OAM VES Collector allocation of resources

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of…

smo_oam | Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.7 HIGH
CVE-2026-85887 — M365 Copilot Information Disclosure Vulnerability

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.9 CRITICAL
CVE-2026-85878 — Azure Database for PostgreSQL Elevation of Privilege Vulnerability

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.2 HIGH
CVE-2026-83946 — Azure Portal Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
10.0 CRITICAL
CVE-2026-69843 — Microsoft Fabric Elevation of Privilege Vulnerability

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
10.0 CRITICAL
CVE-2026-62874 — Azure Billing Elevation of Privilege Vulnerability

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.4 MEDIUM
CVE-2026-2585 — Brizy – Page Builder <= 2.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sa…

brizy | Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.3 MEDIUM
CVE-2026-18441 — LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct O…

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 vi…

Remote | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-93436 — vLLM through 0.29.0 Memory Exhaustion via Rejected Requests

vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0…

vllm vllm | Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.7 HIGH
CVE-2026-93435 — redis-parser through 3.0.0 Denial of Service via Unbounded Recursion

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nest…

Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.8 HIGH
CVE-2026-87886 — Acronis Backup Incorrect Default Permissions Vulnerability - [Actively Exploited]

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for …

CISA KEV | Misconfiguration
Sep 17, 2026 Sep 18, 2026
Sep 17, 2026
Sep 18, 2026
9.6 CRITICAL
CVE-2026-87701 — Azure Cosmos DB Elevation of Privilege Vulnerability

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14447 Results