Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-90778 — SIPp through 3.7.7 Buffer Overflow via SIP To Header Tag

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can s…

sipp | Remote | Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.8 HIGH
CVE-2026-90777 — ESPnet before 202609 Remote Code Execution via Unsafe Deserialization

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious …

Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.7 HIGH
CVE-2026-90776 — Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft mali…

nodemailer | Remote | Denial of Service
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.1 HIGH
CVE-2026-90775 — PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule Weight

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out…

Remote | Memory Corruption
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90518 — PHPGurukul Bank Locker Management System sidebar.php access control

A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in imp…

bank_locker_management_system | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.5 MEDIUM
CVE-2026-90517 — PHPGurukul Bank Locker Management System view-assign-locker.php authorization

A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads …

bank_locker_management_system | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90516 — SourceCodester School Registration and Fee System pay_report.php sql injection

A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of …

school_registration_and_fee_system | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90515 — SourceCodester School Registration and Fee System delete_stud.php sql injection

A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulatio…

school_registration_and_fee_system | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.7 HIGH
CVE-2026-90774 — rustypaste before 0.18.1 Path Traversal via filename header

rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path trave…

Remote | Path Traversal
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
3.2 LOW
CVE-2026-90773 — procs through 0.14.12 Terminal Escape Sequence Injection via Command

procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape…

| Information Disclosure
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.3 HIGH
CVE-2026-90772 — Amundsen Frontend through 4.3.0 Stored XSS via Description

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject maliciou…

Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.3 MEDIUM
CVE-2026-90771 — joi before 17.13.8 and 18.2.9 Prototype Pollution via messages

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys i…

Remote | Misconfiguration
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.8 HIGH
CVE-2026-90770 — Spug through 3.4.0 Remote Code Execution via ping_check

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authent…

Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.3 HIGH
CVE-2026-90769 — Open Notebook before 1.11.0 Server-Side Request Forgery via link-source

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply …

open-notebook | Remote | Server-Side Request Forgery
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.6 HIGH
CVE-2026-90768 — CAPEv2 through commit 471ee4b REST API Task Endpoints Missing Ownership Check

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all ta…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.1 HIGH
CVE-2026-90767 — Froxlor before 2.3.12 SSH Key Injection via authorized_keys

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inje…

froxlor | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
9.2 CRITICAL
CVE-2026-90562 — LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administ…

langbot | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
9.3 CRITICAL
CVE-2026-90561 — Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich…

strapi | Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90514 — SourceCodester School Registration and Fee System save_stud.php sql injection

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Sta…

school_registration_and_fee_system | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.9 MEDIUM
CVE-2026-90513 — simalexan api-lambda-send-email-ses API Gateway Endpoint template.yml SES.sendEmail missi…

A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component AP…

api-lambda-send-email-ses | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
Showing 20 of 13131 Results