Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-8067 — Hitachi Energy RTU500 Improper Authorization Vulnerability

An improper authorization vulnerability in the RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause te…

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.1 CRITICAL
CVE-2026-8066 — Hitachi Energy RTU500 Directory Traversal Vulnerability

A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depen…

Remote | Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.1 CRITICAL
CVE-2026-8065 — Hitachi Energy RTU500 Authentication Bypass and Arbitrary Firmware Upload Vulnerability

An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Success…

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-86843 — Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute…

The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, whic…

| Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.7 HIGH
CVE-2026-84739 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in G…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenti…

Remote | Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-81930 — Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer tok…

Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.sn…

| Server-Side Request Forgery
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-81914 — Apache Airflow Google provider: Google Drive query injection via unescaped file and folde…

Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that de…

| Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-81862 — Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credent…

Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's cre…

| Information Disclosure
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.5 HIGH
CVE-2026-7395 — Asset Suite HTTPPublishAdapterTestServlet Improper Authorization

Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosure and integrity compromise. The HTTPPu…

asset_suite asset_suite | Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.3 MEDIUM
CVE-2026-76720 — HPE OneView - URL Redirect vulnerability

A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect.

Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.2 HIGH
CVE-2026-76719 — HPE OneView - Cross-site scripting vulnerability

A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions.

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.2 HIGH
CVE-2026-76718 — HPE OneView - Cross-site scripting vulnerability

A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions.

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
3.7 LOW
CVE-2026-4523 — Missing Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthen…

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.0 HIGH
CVE-2026-19547 — Local Privilege Escalation in Ghostscript for Windows

Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths und…

ghostscript | Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.0 CRITICAL
CVE-2026-15390 — Out-of-bounds write in Das U-Boot

Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by s…

| Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.1 MEDIUM
CVE-2026-11796 — Asset Suite Improper Access Control Vulnerability

Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service condi…

asset_suite asset_suite | Remote | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.3 MEDIUM
CVE-2026-10518 — Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticate…

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.0 MEDIUM
CVE-2026-102474 — Dash: dash: heap out-of-bounds write in conv_escape via undersized unicode escape reserva…

A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an …

enterprise_linux enterprise_linux | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.5 MEDIUM
CVE-2026-102473 — Dash: dash: super-polynomial backtracking in pmatch when libc fnmatch is disabled

A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwi…

enterprise_linux enterprise_linux | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.1 HIGH
CVE-2026-96440 — Flowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Directory(Path…

Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote au…

agentflow | Remote | Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14330 Results