Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-93590 — ImageMagick before 7.1.2-31 Policy Bypass in UHDR encoder

ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource pol…

Remote | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.3 MEDIUM
CVE-2026-93589 — ImageMagick before 7.1.2-31 Division by Zero in FLIF encoder

ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes …

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
3.1 LOW
CVE-2026-93588 — ImageMagick before 7.1.2-31 Null Pointer Dereference via PNM

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the fail…

Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.8 MEDIUM
CVE-2026-93587 — ImageMagick before 7.1.2-31 Policy Bypass via PCD decoder

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decode…

| Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
2.9 LOW
CVE-2026-93586 — ImageMagick before 7.1.2-31 Use After Free via ImagesToBlob

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a li…

| Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.2 CRITICAL
CVE-2023-5778 — Missing Length Check

Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. …

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.3 MEDIUM
CVE-2026-93492 — Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size

A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93491 — Io.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.…

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This actio…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-93504 — SveltyCMS User Attribute Update Endpoint +server.ts access control

A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation lead…

| Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93488 — Io.netty/netty-codec-http: netty: denial of service via unbounded concurrent spdy streams

A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides …

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.8 MEDIUM
CVE-2026-28199 — Sensitive File Disclosure via Relative Path Traversal in NetBackup Flex OS Shell

An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagn…

| Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.4 CRITICAL
CVE-2026-28198 — Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS…

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a…

Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.4 CRITICAL
CVE-2026-28197 — Privilege Escalation via Argument Injection in NetBackup Flex OS Shell

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbi…

Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
3.1 LOW
CVE-2026-21806 — HCL BigFix Service Management was affected with Admin Session Concurrency vulnerability (…

HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative accou…

Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-93578 — Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp cl…

Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-93575 — Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder

### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder checks if the MQTT packet's `Remaining Length` exceeds `maxBytesInMessage`, but fails to validate the `Properties Length` agains…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93572 — Io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers multiply patc…

## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator re…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-93563 — Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtprespo…

Unbounded multi-line response accumulation in SmtpResponseDecoder leads to memory-exhaustion DoS

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-93561 — Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch…

Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.7 MEDIUM
CVE-2026-81627 — Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smr…

A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
Showing 20 of 14424 Results