Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-6377 — Path Traversal in Next4Biz's CSM (Customer Service Management)

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This i…

Remote | Path Traversal
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
0.0 NA
CVE-2026-86317 — ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion

A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server. Perfor…

| Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.4 HIGH
CVE-2026-19843 — 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console …

A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper…

Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.8 CRITICAL
CVE-2026-18922 — 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to direct…

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connecti…

Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-18453 — 389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results a…

A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending …

Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-18355 — 389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound…

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an…

Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.5 MEDIUM
CVE-2026-80057 — Dell Secure Connect Gateway Use of Hard-coded Cryptographic Key Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker…

| Cryptography
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.4 HIGH
CVE-2026-79644 — Dell SCG Improper Certificate Validation Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker w…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.2 HIGH
CVE-2026-79645 — Dell Secure Connect Gateway Missing Authentication for Critical Function Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticate…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-78480 — Dell Secure Connect Gateway Missing Authentication for Critical Function Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticate…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.3 MEDIUM
CVE-2026-8279 — Masteriyo LMS <= 2.2.0 - Missing Authorization to Unauthenticated Arbitrary Course Progre…

The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsControll…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.3 MEDIUM
CVE-2026-86451 — MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects

Affected versions of MISP allow authenticated users to retrieve object-reference records by UUID through EventGraphTool::get_reference_data() without first checking whether the requester is authorize…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
2.3 LOW
CVE-2026-86441 — MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hid…

Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.1 MEDIUM
CVE-2026-86440 — MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs

Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous rendere…

Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-86435 — commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with dupl…

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-86434 — commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision

league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on e…

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-86433 — commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling li…

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.9 MEDIUM
CVE-2026-86432 — commonmark 2.0.0 before 2.8.4 Denial of Service via XML

commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested M…

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.2 HIGH
CVE-2026-86431 — commonmark before 2.9.1 XSS via AttributesExtension form feed bypass

league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C for…

commonmark | Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-86430 — league/commonmark before 2.9.1 Denial of Service via parsing

league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform …

commonmark | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
Showing 20 of 12448 Results