Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-57173 — vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions

vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file with…

vllm | Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.4 HIGH
CVE-2026-42784 — Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusi…

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed…

Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.6 CRITICAL
CVE-2026-20331 — Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Softwar…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure …

Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.9 CRITICAL
CVE-2026-20307 — Cisco Identity Services Engine Remote Code Execution Vulnerability

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device…

identity_services_engine_software | Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.1 CRITICAL
CVE-2026-20306 — Cisco Identity Services Engine Command Injection Vulnerability

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges t…

identity_services_engine_software | Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.1 CRITICAL
CVE-2026-20305 — Cisco Identity Services Engine Command Injection Vulnerability

A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate priv…

identity_services_engine_software | Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.9 CRITICAL
CVE-2026-20234 — Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential V…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have con…

identity_services_engine_software | Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
6.3 MEDIUM
CVE-2026-18120 — Missing Authorization in legacy Express entries search endpoint allows disclosure of Expr…

Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by the normal dashboard …

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
0.0 NA
CVE-2026-92406 — SourceCodester Inventory and Monitoring System btn_functions.php add sql injection

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. …

| Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
2.0 LOW
CVE-2026-85387 — Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST AP…

Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authoriza…

Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
4.6 MEDIUM
CVE-2026-92627 — Heap Use-After-Free in H5T__conv_f_f

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a te…

| Memory Corruption
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.5 HIGH
CVE-2026-92626 — Control iD iDSecure Unauthenticated Denial of Service

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state tha…

idsecure | Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.5 HIGH
CVE-2026-92625 — Control iD iDSecure Unauthenticated Denial of Service

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an inter…

idsecure | Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
6.6 MEDIUM
CVE-2026-92615 — Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-ten…

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or ten…

advanced_cluster_management_for_kubernetes | Remote | Race Condition
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.1 CRITICAL
CVE-2026-92397 — Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipul…

Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
3.3 LOW
CVE-2026-92385 — SourceCodester Online Food Ordering System Category Update update_category.php cross site…

A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. …

online_food_ordering_system | Remote | Cross-Site Scripting
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
0.0 NA
CVE-2026-90999 — Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged…

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation en…

| Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.5 MEDIUM
CVE-2026-76104 — Dell ObjectScale Incorrect Permission Assignment Vulnerability

Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially…

objectscale | Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
10.0 CRITICAL
CVE-2026-70416 — Dell ObjectScale Deserialization of Untrusted Data Vulnerability

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, l…

objectscale | Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.7 HIGH
CVE-2026-61595 — djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tena…

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. Th…

Remote | Information Disclosure
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
Showing 20 of 14707 Results