Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-91765 — SOAP: Unbounded Recursion in Server-Side cleanup_xml_node

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements …

Remote | Denial of Service
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.3 MEDIUM
CVE-2026-6103 — Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection

phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF …

| Misconfiguration
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.5 HIGH
CVE-2026-57443 — SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests

SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) expo…

Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.9 MEDIUM
CVE-2026-17545 — PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can c…

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. …

Remote | Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.5 HIGH
CVE-2026-10758 — Esri Lerc has a security vulnerability

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earl…

Remote | Memory Corruption
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
3.1 LOW
CVE-2026-100417 — RustDesk before 1.5.0 One-Way File Transfer Bypass

RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers …

Remote | Misconfiguration
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.8 HIGH
CVE-2026-100391 — MediaFlow Proxy through 2.4.9 Server-Side Request Forgery via Incomplete Validation

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers…

Remote | Server-Side Request Forgery
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.1 CRITICAL
CVE-2026-100390 — Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X…

Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.2 CRITICAL
CVE-2026-100389 — GestSup before 3.2.61 Remote Code Execution via IMAP Attachment

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers ca…

Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.4 MEDIUM
CVE-2026-100388 — RustDesk before 1.5.0 Missing Authorization Check on Incoming File Clipboard Messages

RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers wi…

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.1 HIGH
CVE-2026-100387 — pgPointcloud through 1.2.5 heap out-of-bounds read via WKB deserialization

pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers c…

Remote | Memory Corruption
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-100380 — Reflected XSS in Wikibase Special:SetLabel language validation

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). Th…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-100379 — Cross-request disclosure of CentralAuth cookies in Wikipedia Android App

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipe…

Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-100378 — Missing permission check in the Translate sandbox doRemind action

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate …

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.9 MEDIUM
CVE-2026-100377 — Revision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbs…

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation. This issue affects Mediawiki - WikiLambda Extensi…

Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.8 MEDIUM
CVE-2026-100376 — TemplateSandbox can be abused for XSS by asking another user to preview a page with a cer…

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XS…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.4 HIGH
CVE-2026-100369 — CliInvoke: Argument Injection in Extensibility Runner Factory

CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2…

| Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
3.4 LOW
CVE-2025-1218 — Various packet overreads in mysqlnd_writeprotocol.c

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated pac…

| Memory Corruption
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.5 MEDIUM
CVE-2025-14181 — Integer overflow to buffer overflow in soap HTTP parsing

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised …

Remote | Memory Corruption
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.9 MEDIUM
CVE-2026-96878 — Cargo Exhibit field alias allows stored XSS

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
Showing 20 of 14463 Results