Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.2 CRITICAL
CVE-2026-79752 — CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-77614 — Opencast: Session fixation in login enables account takeover via crafted link

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_defau…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-93013 — RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal

RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary fil…

ragflow | Remote | Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.5 HIGH
CVE-2026-71538 — @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Windows fallback path in src/npmRunner.ts, used when npm_execpath does not provide…

| Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.2 CRITICAL
CVE-2026-76834 — b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key

b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negati…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.1 CRITICAL
CVE-2026-63472 — Vendure: External-authentication account takeover: external login linked to a pre-existin…

Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authent…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-63461 — Vendure: Shop API list queries can return non-public entities when filterOperator is OR

Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets queries combine mandatory visibility guards with caller-supplied filters us…

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.5 HIGH
CVE-2026-63460 — Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends

Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOper…

Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.7 HIGH
CVE-2026-63459 — Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entit…

Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to st…

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.9 MEDIUM
CVE-2026-61793 — Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter

Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false an…

Remote | Server-Side Request Forgery
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
3.5 LOW
CVE-2026-54471 — Dell SmartFabric Manager Improper Privilege Management Vulnerability

Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentiall…

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.1 HIGH
CVE-2026-26950 — Dell SmartFabric Manager Insufficient Verification of Data Authenticity Vulnerability

Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit thi…

Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
3.8 LOW
CVE-2026-12284 — Mattermost Desktop App Missing IPC Sender Validation in Calls Leave Handler

Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a co…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.5 MEDIUM
CVE-2026-76781 — Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute

A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` …

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
2.6 LOW
CVE-2026-75588 — Mattermost Desktop App plugin popout scheme validation bypass

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to loa…

Remote | Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.1 MEDIUM
CVE-2026-92973 — ansi2html 1.7.0a0 through 1.9.3 Cross-Site Scripting via OSC 8

ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling ANSI text input c…

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-92972 — SGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpoint

SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing ta…

sglang | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.7 HIGH
CVE-2026-92971 — InternLM LMDeploy through 0.17.0 Assertion Denial of Service

InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers…

lmdeploy | Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-92970 — HUBzero CMS through 2.2.32 Path Traversal via File Upload

HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. A…

Remote | Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.9 MEDIUM
CVE-2026-92963 — vm2 before 3.11.2 Information Disclosure via Internal State

vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalTh…

Remote | Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14768 Results