Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-85157 — WWBN AVideo Broken Access Control via feed/index.php program_id

WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied. Attackers …

avideo | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.9 MEDIUM
CVE-2026-85156 — WWBN AVideo Broken Access Control via Channel Page

WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags an…

avideo | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.7 HIGH
CVE-2026-85155 — WWBN AVideo SQL Injection via get.json.php APIName channels

WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary …

avideo | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-85154 — WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash

WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the vide…

avideo | Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
0.0 NA
CVE-2026-85105 — NousResearch hermes-agent Session Management s71.py _sess_nowait authorization

A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait of the file s71.py of the component Session Management. This manipulation of the argumen…

hermes-agent | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.8 HIGH
CVE-2026-76642 — util-linux libmount Privilege Escalation via Failed Mount Helper

util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing file…

| Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-85124 — @fastify/http-proxy vulnerable to prefix escape via backslash dot-segments

@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handle…

Remote | Path Traversal
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-85150 — Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_…

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Spec…

enterprise_linux enterprise_linux | Remote | Denial of Service
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.2 CRITICAL
CVE-2026-76178 — Multiple vulnerabilities in Ocsreports for OCS Inventory NG

A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicio…

Remote | Cross-Site Scripting
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.9 MEDIUM
CVE-2026-15933 — Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise)

OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan del…

Remote | Information Disclosure
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-76177 — Multiple vulnerabilities in Ocsreports for OCS Inventory NG

Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user w…

Remote | Server-Side Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.6 HIGH
CVE-2026-76176 — Multiple vulnerabilities in Ocsreports for OCS Inventory NG

SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An aut…

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
0.0 NA
CVE-2026-85100 — 2FastLabs agent-squad Streaming Agent Response Workflow orchestrator.ts AgentSquad.routeR…

A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript/src/orchestrator.ts of the…

| Denial of Service
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.6 HIGH
CVE-2026-76175 — Multiple vulnerabilities in Ocsreports for OCS Inventory NG

SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an …

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.4 CRITICAL
CVE-2026-76174 — Multiple vulnerabilities in Ocsreports for OCS Inventory NG

Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, wit…

Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.8 MEDIUM
CVE-2026-80253 — ShizenBox2 Improper Physical Access Control Vulnerability

An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical access to the product may execute bootloader commands without authentication.

| Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-80254 — ShizenBox2 Authorization Bypass via User-Controlled Key

Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an attacker who can log in to the product may change the other user's password.

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.6 HIGH
CVE-2026-84830 — OS command injection in privileged configuration handling

SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.

secure_email_gateway | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.6 HIGH
CVE-2026-84832 — Unsafe deserialization in the REST interface

SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute…

secure_email_gateway | Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.7 HIGH
CVE-2026-84831 — Mandatory MFA bypass before enrollment

SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required b…

secure_email_gateway | Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Showing 20 of 12596 Results