Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-18312 — CVE-2026-18312

Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping. The application interpolates untrusted values directly into URL stri…

| Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-67411 — RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, native MQTT and MQTT over WebSocket behind a trusted PROXY Protocol frontend could lose the …

| Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-67413 — RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an …

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, 4.1.14, 4.2.9, and 4.3.3, the optional rabbitmq_jms_topic_exchange plugin's x-jms-topic exchange accepted a client-controlled rj…

| Denial of Service
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-61837 — RabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology to any authen…

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, AMQP 1.0 management GET /bindings exposes full binding topology to any authenticated AMQP user without…

| Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.0 MEDIUM
CVE-2026-80432 — Missing authorization in the kitty drag and drop protocol allows a client to obtain dragg…

Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over …

kitty | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-67415 — RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Servi…

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, the Shovel parameter parser converted attacker-controlled runtime parameter values into non-garbage-collected Erlang at…

| Denial of Service
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-67412 — RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message acce…

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message acce…

| Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
0.0 NA
CVE-2026-67409 — RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes A…

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18, JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication…

| Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.3 MEDIUM
CVE-2026-97869 — langchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticScopeSerializ…

A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the function AgenticScopeSerializer.fromJson of the file AgenticScopeJsonSerialization…

langchain4j | Remote | Misconfiguration
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.0 MEDIUM
CVE-2026-97868 — sheshbabu zen Note Editor NotesEditor.jsx dangerouslySetInnerHTML cross site scripting

A security vulnerability has been detected in sheshbabu zen up to 1.5.0. Affected by this issue is the function dangerouslySetInnerHTML of the file features/notes/NotesEditor.jsx of the component Not…

zen | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.3 MEDIUM
CVE-2026-97469 — PostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLink

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-for…

Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
2.3 LOW
CVE-2026-96874 — Stored XSS in Cargo Drilldown tab names

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo ext…

cargo | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.8 CRITICAL
CVE-2026-92161 — FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Dis…

FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified fie…

Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.8 MEDIUM
CVE-2026-85293 — InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mai…

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and…

invoiceplane | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.8 MEDIUM
CVE-2026-85292 — InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth)

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the requir…

invoiceplane | Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.5 MEDIUM
CVE-2026-85291 — InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorizat…

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL and u…

invoiceplane | Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-85290 — InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path di…

invoiceplane | Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.5 MEDIUM
CVE-2026-85289 — InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Paymen…

invoiceplane | Remote | Cross-Site Request Forgery
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.5 MEDIUM
CVE-2026-85274 — InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF t…

invoiceplane | Remote | Cross-Site Request Forgery
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.2 HIGH
CVE-2026-67236 — RabbitMQ: Plaintext username:password stored in an insecure cookie after successful POST …

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing base64-encoded username:password crede…

rabbitmq_server | Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
Showing 20 of 14480 Results