Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.1 LOW
CVE-2026-101089 — Nezha before 2.2.7 Information Disclosure via /api/v1/profile

Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract pas…

Remote | Information Disclosure
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.0 MEDIUM
CVE-2026-101088 — Nezha before 2.3.1 Denial of Service via Concurrent Server Delete

Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously report…

Remote | Denial of Service
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
5.3 MEDIUM
CVE-2026-101087 — Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6

Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges — specifically…

Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101086 — Nezha Dashboard before 2.3.5 Task Type Validation Bypass

Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types…

Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101085 — Nezha before 2.3.8 Denial of Service via Alert Rule

Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluat…

Remote | Denial of Service
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.6 CRITICAL
CVE-2026-101084 — obot before v0.21.1 Authorization Bypass via /mcp-connect

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Att…

Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.8 CRITICAL
CVE-2026-101065 — Obot Quickstart Docker Deployment Unauthenticated Admin Access

Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080…

Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.3 HIGH
CVE-2026-101064 — Obot before v0.23.0 Server-Side Request Forgery via MCP

Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attac…

Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.9 MEDIUM
CVE-2026-101063 — Obot before v0.23.0 Authentication Bypass via Registry API

Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata inclu…

Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.8 HIGH
CVE-2026-101062 — Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration

Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on …

Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
4.0 MEDIUM
CVE-2026-100880 — zhistaredu StarTraining Upload Endpoint MimeTypeUtils.java cross site scripting

A weakness has been identified in zhistaredu StarTraining up to 3.8.1. This vulnerability affects unknown code of the file du-common/src/main/java/com/edu/common/utils/file/MimeTypeUtils.java of the …

startraining | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
4.3 MEDIUM
CVE-2026-100879 — zhistaredu StarTraining dataScope Endpoint SysRoleServiceImpl.java checkRoleAllowed autho…

A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The man…

startraining | Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.5 MEDIUM
CVE-2026-100878 — zhistaredu StarTraining authRole Endpoint SysUser.java SysUser.isAdmin authorization

A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/Sy…

startraining | Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
5.0 MEDIUM
CVE-2026-100877 — mathurvishal CloudClassroom-PHP-Project registrationform.php cross site scripting

A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file regist…

cloudclassroom-php-project | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.5 MEDIUM
CVE-2026-96279 — Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks

A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary hos…

enterprise_linux flatpak enterprise_linux | Remote | Information Disclosure
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.5 MEDIUM
CVE-2026-100876 — mathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authentication

A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file loginlinkstudent.php. Performing a man…

cloudclassroom-php-project | Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.5 HIGH
CVE-2026-100875 — mathurvishal CloudClassroom-PHP-Project updatedetailsfromfaculty.php sql injection

A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromfaculty.php. Su…

cloudclassroom-php-project | Remote | Injection
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.5 HIGH
CVE-2026-100874 — mathurvishal CloudClassroom-PHP-Project addnewstudent.php sql injection

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file addnewstudent.php. This manipulation caus…

cloudclassroom-php-project | Remote | Injection
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
5.0 MEDIUM
CVE-2026-100873 — mathurvishal CloudClassroom-PHP-Project cross-site request forgery

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function. The manipulation results in cross-…

cloudclassroom-php-project | Remote | Cross-Site Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
4.7 MEDIUM
CVE-2026-101061 — utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass

utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable p…

python-utcp | Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
Showing 20 of 14021 Results