Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-80229 — OpenSSL provider use-after-free

When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library…

curl | Memory Corruption
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-19931 — Negotiate ambient user conn reuse

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's…

curl | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-18924 — HTTP/2 server push UAF

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

curl | Memory Corruption
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-13608 — OpenLDAP SASL authentication bypass

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-…

curl | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
8.3 HIGH
CVE-2026-82751 — Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and spon…

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have t…

mpp | Remote | Misconfiguration
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
8.3 HIGH
CVE-2026-82750 — Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cos…

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have t…

mpp | Remote | Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.4 MEDIUM
CVE-2026-83534 — PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_para…

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed i…

Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.4 MEDIUM
CVE-2026-19634 — PostgreSQL Anonymizer: SQL injection in import_database_rules() and import_roles_rules() …

PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequentl…

Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
8.8 HIGH
CVE-2026-19633 — PostgreSQL Anonymizer: unprivileged masked users can execute code via operators, domain c…

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions.…

Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.1 HIGH
CVE-2026-86283 — MISP UiBeta Collection View Bypasses Event ACL, Exposing Unauthorized Event Data

MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The Col…

misp | Remote | Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.5 MEDIUM
CVE-2026-86217 — code-projects Hotel and Tourism Reservation in PHP Database Backup hotel_db%20(1).sql inf…

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. Th…

hotel_and_tourism_reservation_in_php | Remote | Information Disclosure
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.0 MEDIUM
CVE-2026-86216 — code-projects Hotel and Tourism Reservation in PHP details.php cross site scripting

A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument ro…

hotel_and_tourism_reservation_in_php | Remote | Cross-Site Scripting
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
4.3 MEDIUM
CVE-2026-86215 — Mstfakts College-Management-System Logout server.php session expiration

A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation o…

college-management-system | Remote | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
9.0 CRITICAL
CVE-2026-86259 — OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitra…

Remote | Server-Side Request Forgery
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
8.2 HIGH
CVE-2026-86258 — nbviewer through 1.0.1 Path Traversal via LocalFileHandler

nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibli…

Remote | Path Traversal
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86214 — Mstfakts College-Management-System login.php improper authentication

A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authenti…

mstfakts_college-management-system | Remote | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86213 — Mstfakts College-Management-System Search university.php mysqli_query sql injection

A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of…

college-management-system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.4 MEDIUM
CVE-2026-86257 — wger before 2.6 CSV Formula Injection via member export

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HY…

wger wger | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.4 MEDIUM
CVE-2026-86256 — wger before 2.6 Open Redirect via trainer-login next parameter

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects…

wger wger | Remote | Misconfiguration
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.1 HIGH
CVE-2026-86255 — wger before 2.5 Uncontrolled Resource Consumption via date_sequence

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequen…

wger wger | Remote | Denial of Service
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
Showing 20 of 12299 Results