Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-84289 — NousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocation

A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool. Performing a manipulat…

hermes-agent | Remote | Memory Corruption
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
4.3 MEDIUM
CVE-2026-84288 — NousResearch hermes-agent ACP Prompt Workflow session.py HermesACPAgent.prompt denial of …

A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt Workflow. Such…

hermes-agent | Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.8 HIGH
CVE-2026-83549 — SonicWall SMA1000 Appliance Management Console OS Command Injection

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) whic…

sma1000 | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-83548 — SonicWall SMA1000 Appliance Server-Side Request Forgery

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit th…

sma1000 | Server-Side Request Forgery
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.7 HIGH
CVE-2026-76851 — Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code…

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-…

enterprise_server | Remote | Server-Side Request Forgery
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.0 CRITICAL
CVE-2026-75604 — Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-…

next.js | Remote | Path Traversal
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.7 HIGH
CVE-2026-19118 — Race condition vulnerability was identified in GitHub Enterprise Server that allowed remo…

A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access t…

enterprise_server | Remote | Race Condition
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.2 HIGH
CVE-2026-18730 — Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a…

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an …

enterprise_server | Remote | Server-Side Request Forgery
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2023-54391 — Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any exi…

Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.4 MEDIUM
CVE-2026-84470 — Automation-controller: automation-controller-container: automation-controller/awx: bulk j…

A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level …

ansible_automation_platform | Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.4 MEDIUM
CVE-2026-84371 — ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html…

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.2 HIGH
CVE-2026-84370 — SVGO: removeScripts allows executable links through namespace and control-character bypas…

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, …

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.1 MEDIUM
CVE-2026-84369 — SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, …

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
3.7 LOW
CVE-2026-84368 — joi: Prototype pollution via a `__proto__` language key in custom messages

joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi package contain prototype poll…

Remote | Misconfiguration
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
3.7 LOW
CVE-2026-84367 — joi: object().rename() with a template target can set the validated object's prototype

joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used by object().rename() permi…

Remote | Misconfiguration
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.4 HIGH
CVE-2026-84366 — Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key reque…

Remote | Misconfiguration
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-84365 — Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output …

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every traversal sequence, and toSSG…

Remote | Path Traversal
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.3 MEDIUM
CVE-2026-84364 — Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested objects with dot-notation pa…

Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.9 MEDIUM
CVE-2026-84363 — Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy i…

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a literal hash fragment as the start of a query…

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.7 HIGH
CVE-2026-84361 — Composer: Perforce source URL permits P4PORT `rsh:` command execution

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set …

Remote | Supply Chain
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
Showing 20 of 12532 Results