Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.4 HIGH
CVE-2026-54241 — libde265: SAO sequential filter heap buffer overflow via signed integer overflow

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted …

Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.4 HIGH
CVE-2026-54240 — libde265: Pixel accessor signed integer overflow causes heap OOB read/write

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image di…

Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.5 MEDIUM
CVE-2026-50018 — Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable …

hoverfly | Remote | Denial of Service
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-50013 — Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchroni…

hoverfly | Remote | Race Condition
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.3 MEDIUM
CVE-2026-49992 — Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permiss…

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, a…

kimai | Remote | Cross-Site Request Forgery
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-49846 — libks has path traversal in kws HTTP parser via URI segment overflow

libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its interna…

Remote | Path Traversal
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.2 MEDIUM
CVE-2026-48496 — opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the …

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileg…

| Denial of Service
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-45056 — Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution

matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-cr…

matrix-rust-sdk | Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.7 HIGH
CVE-2026-44715 — OpenMRS has Broken Access Control in HL7 Configuration

OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7Arc…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
4.8 MEDIUM
CVE-2026-81918 — Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Pag…

Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in …

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.1 MEDIUM
CVE-2026-81917 — Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library block file d…

Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.1 MEDIUM
CVE-2026-81907 — Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) vin Expre…

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the …

Remote | Cross-Site Request Forgery
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.1 MEDIUM
CVE-2026-68535 — Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Concrete CMS Ar…

Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as her…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.3 HIGH
CVE-2026-54174 — melange: Incomplete package integrity verification allows data section substitution

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` et…

melange | Remote | Supply Chain
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.1 HIGH
CVE-2026-54166 — Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Vali…

Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` permission can trigger server-side HTTP requests to attacker-controlled URLs thr…

Remote | Server-Side Request Forgery
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.4 MEDIUM
CVE-2026-54165 — Stored DOM-XSS in public shared-folder image gallery (one-click, unauthenticated victim)

Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click stored DOM-based cross-site scripting (XSS) vulnerability in the public, unauthen…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-50025 — Mousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie state

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-lay…

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-49865 — Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker ca…

kimai | Remote | Server-Side Request Forgery
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.1 HIGH
CVE-2026-49464 — NL Portal: IDOR allows any authenticated user to complete and tamper with another user's …

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
4.3 MEDIUM
CVE-2026-49439 — OpenRemote read-only asset users can write predicted datapoints

OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints…

openremote | Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
Showing 20 of 13702 Results