Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.7 LOW
CVE-2026-81181 — SysReptor: Session Fixation in Password-Protected Shared Notes

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful aut…

sysreptor | Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.8 HIGH
CVE-2026-81180 — SysReptor: Authenticated RCE by insecure image processing

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Gho…

sysreptor | Remote | Supply Chain
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.1 HIGH
CVE-2026-81179 — SysReptor: Host header injection might allow account takeover

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-co…

sysreptor | Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
3.5 LOW
CVE-2026-81178 — SysReptor: Anonymous note-share link discloses project member identities and non-shared n…

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the …

sysreptor | Remote | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.9 MEDIUM
CVE-2026-77396 — PJSIP: Heap buffer overflow in the AVI parser

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as t…

| Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.5 MEDIUM
CVE-2026-77386 — Kyoo: OIDC login token can be redirected to an attacker-controlled URL

Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The lo…

Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.3 MEDIUM
CVE-2026-77385 — Kyoo: Transcoder serves uncataloged files from the media directory

Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcode…

Remote | Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.5 MEDIUM
CVE-2026-71537 — Paymenter: Credit-refund double-spend race condition in service downgrade (doUpgrade)

Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pe…

Remote | Race Condition
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.3 MEDIUM
CVE-2026-69186 — c-ares: Memory-amplification denial of service via unvalidated DNS header record counts

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enou…

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-69184 — c-ares: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A mal…

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.8 MEDIUM
CVE-2026-64847 — AnyIO process-pool workers can block indefinitely on undrained stderr

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected t…

| Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.1 HIGH
CVE-2026-63458 — Perses project query parameter authorization bypass exposes cross-project resources

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through…

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.1 HIGH
CVE-2026-63445 — Perses: Unvalidated project parameter enables filesystem path traversal

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project query …

Remote | Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.3 HIGH
CVE-2026-63199 — Perses: Missing authorization in datasource proxy allows cross-scope secret disclosure

Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the caller on …

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.1 HIGH
CVE-2026-62279 — LubeLogger: IDOR in DuplicateRecordsToOtherVehicles Allows Copying Records from Any User'…

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecord…

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.1 HIGH
CVE-2026-62278 — LubeLogger: Path Traversal in HandleTranslationFileUpload Allows Authenticated Users to W…

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenticated non-administrative users could reach HandleTranslationFileUpload and in…

Remote | Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.2 HIGH
CVE-2026-61552 — Icinga 2 DSL Injection via Unescaped Import Template Name

Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping th…

Remote | Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.6 HIGH
CVE-2026-61551 — Icinga 2: Stack overflow via deeply nested JSON objects

Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsin…

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.8 CRITICAL
CVE-2026-61550 — Icinga 2: Improper access control for JSON-RPC update certificate messages

Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unaut…

Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.1 CRITICAL
CVE-2026-59163 — Mnemosyne has JWT signature verification bypass sync server that allows authentication by…

Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passe…

Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
Showing 20 of 14464 Results