Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.6 MEDIUM
CVE-2026-81830 — OpenVPN Windows Interactive Service Arbitrary File Read Vulnerability

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

| Path Traversal
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
2.3 LOW
CVE-2026-81738 — OpenVPN Out-of-Bounds Write Vulnerability

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

Remote | Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
0.0 NA
CVE-2026-78254 — Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write

The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the dow…

ant | Path Traversal
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.9 MEDIUM
CVE-2026-78221 — OpenVPN Windows Interactive Service Buffer Overflow

An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive informati…

| Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.6 MEDIUM
CVE-2026-78043 — OpenVPN Windows Interactive Service Arbitrary Configuration Loading Vulnerability

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files vi…

| Path Traversal
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-14296 — nRF54H20: MCUBoot can be tricked to executing unauthenticated code

When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional verification. The MCUboot in the bare…

| Misconfiguration
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86279 — SourceCodester Syllabus-Aligned Learning Management & Examination System Login auth_proce…

A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the compone…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.0 MEDIUM
CVE-2026-86278 — SourceCodester Syllabus-Aligned Learning Management & Examination System manage_subjects.…

A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulatio…

Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86277 — SourceCodester Syllabus-Aligned Learning Management & Examination System delete_exam.php …

A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the ar…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.9 CRITICAL
CVE-2026-79698 — Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, …

Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.9 CRITICAL
CVE-2026-79697 — Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command inje…

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, …

Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86276 — SourceCodester Syllabus-Aligned Learning Management & Examination System db.php hard-code…

A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead…

Remote | Information Disclosure
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.5 MEDIUM
CVE-2026-86275 — SourceCodester Syllabus-Aligned Learning Management & Examination System auth.php registe…

A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manip…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.5 MEDIUM
CVE-2026-86274 — projeto-siga Authentication Flow ExAutenticacaoController.java ExAutenticacaoController.a…

A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86273 — projeto-siga HTML-to-PDF Endpoint ExUtilController.java DownloadExterno.getUrl server-sid…

A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilControl…

Remote | Server-Side Request Forgery
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86272 — Beijing Meite Software Technology U+Smart Enjoyment WebSite UploadFormImg.ashx unrestrict…

A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Execut…

Remote | Misconfiguration
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.8 MEDIUM
CVE-2026-86271 — FluentCMS PermissionManager.cs GetAccessible authorization

A vulnerability was found in FluentCMS up to 0.0.5. This affects the function GetAccessible of the file src/Backend/FluentCMS.Services/Permissions/PermissionManager.cs. Performing a manipulation resu…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.5 MEDIUM
CVE-2026-86270 — itsourcecode Sales and Inventory System settings_edit.php sql injection

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation of the argument ID l…

sales_and_inventory_system | Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.2 MEDIUM
CVE-2026-86315 — Samsung Escargot Out-of-Bounds Write Vulnerability

An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the hos…

| Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.5 MEDIUM
CVE-2026-86269 — itsourcecode Sales and Inventory System emp_edit1.php sql injection

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation of the argument ID causes sql inj…

sales_and_inventory_system | Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
Showing 20 of 12351 Results