Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-54723 — devpi: Database contents leak

devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthen…

| Information Disclosure
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-57578 — DotVVM: Missing authorization in AuthorizeActionFilter

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFi…

| Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-57577 — DotVVM: ReDOS in routing

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause ex…

| Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-57581 — DotVVM: Unrestricted file upload

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submi…

| Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-73494 — blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Ja…

| Misconfiguration
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-53752 — docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively fol…

| Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-90806 — DjangoCRM django-crm Bulk Case Update bulk_views.py BulkUpdateCasesView authorization

A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update…

| Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-53659 — http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` al…

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression f…

| Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.8 HIGH
CVE-2026-85892 — Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

None

Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-47256 — OpenTelemetry: Path traversal in Sentry exporter via attacker-controlled service.name rea…

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. P…

| Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-55091 — flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id k…

flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fie…

| Misconfiguration
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-54150 — next-video: Unauthenticated arbitrary file read via /api/video request handler

next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts an unauthenticated…

| Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-55866 — SpiceDBChecks involving relations with caveats can result in unconditional permission whe…

SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PE…

spicedb | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-55847 — Allure: Stored XSS via unescaped ANSI helper in Allure report status message/trace render…

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-…

| Cross-Site Scripting
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-55846 — Allure: Path Traversal in Allure Report HTTP Server Allows Arbitrary File Read

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setU…

| Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.2 HIGH
CVE-2026-85921 — Windows Secure Kernel Mode Elevation of Privilege Vulnerability

None

Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.6 MEDIUM
CVE-2026-19542 — Stack-based out-of-bounds write in tdelete during tree rebalancing

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. Th…

Remote | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
4.8 MEDIUM
CVE-2026-90804 — GNU Binutils Eh Frame Section elf-eh-frame.c _bfd_elf_write_section_eh_frame buffer overf…

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Per…

binutils | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.3 MEDIUM
CVE-2026-90803 — GNU Binutils ld elf64-x86-64.c elf_x86_64_relocate_section buffer overflow

A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such ma…

binutils | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
4.4 MEDIUM
CVE-2026-90802 — GNU Binutils ld libbfd.c bfd_putl64 null pointer dereference

A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack re…

binutils | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
Showing 20 of 12594 Results