Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.6 MEDIUM
CVE-2026-78135 — strongSwan libcharon IKEv2 Authentication Bypass

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
4.2 MEDIUM
CVE-2026-89145 — Flextype CMS 0.9.9 through 1.0.0-alpha.3 Stored XSS via Plugin Directory

Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the…

| Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
4.2 MEDIUM
CVE-2026-89092 — Stack overflow in nscd due to unbounded alloca use

The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution …

| Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
4.4 MEDIUM
CVE-2026-88914 — Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux ce…

A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arit…

enterprise_linux enterprise_linux | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.1 HIGH
CVE-2026-78134 — strongSwan EAP-TTLS and EAP-PEAP Incorrect Access Control

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-78133 — strongSwan libcharon Use-After-Free Vulnerability

libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-78132 — strongSwan x509 Plugin Infinite Loop Vulnerability

strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.

Remote | Denial of Service
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
3.7 LOW
CVE-2026-78131 — strongSwan X.509 Plugin Memory Leak

strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.

Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-78130 — strongSwan X.509 Attribute Certificate Parser NULL Pointer Dereference

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.9 MEDIUM
CVE-2026-78129 — strongSwan PKCS#5 Decryption Infinite Loop Denial of Service

strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

Remote | Denial of Service
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
3.7 LOW
CVE-2026-78127 — strongSwan libcharon Memory Leak

libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.9 MEDIUM
CVE-2026-78126 — strongSwan EAP-AKA Plugin NULL Pointer Dereference

strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
3.7 LOW
CVE-2026-78124 — strongSwan OpenSSL Plugin Memory Leak Vulnerability

strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.

Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.9 MEDIUM
CVE-2026-78123 — strongSwan OpenSSL Plugin PKCS#7 Expired Pointer Dereference

strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.

Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-84941 — Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading…

An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive informat…

omada_software_controller oc200 oc220 oc300 oc400 | Remote | Information Disclosure
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.3 MEDIUM
CVE-2026-81906 — [UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks

Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an e…

concrete_cms | Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.3 MEDIUM
CVE-2026-81905 — Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a …

Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemp…

concrete_cms | Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-77807 — AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPres…

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 v…

acymailing | Remote | Path Traversal
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.3 MEDIUM
CVE-2026-18121 — Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calen…

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the …

concrete_cms | Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.7 HIGH
CVE-2026-17176 — OS command injection Vulnerability in Deco BE11000

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Suc…

| Injection
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
Showing 20 of 13419 Results