Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-93761 — Denial of service via unbounded regex matching in Mongoid's in-memory query matcher

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedd…

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.3 HIGH
CVE-2026-93760 — NoSQL injection of JavaScript-executing query operators via unsafe-by-default operator gu…

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally…

Remote | Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.8 HIGH
CVE-2026-93759 — Server-side JavaScript injection via string query criteria bypassing the strict operator …

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able t…

Remote | Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-93753 — deepmerge through 4.3.1 Prototype Poisoning via mergeObject

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious…

Remote | Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-93752 — CSSOM through 0.5.0 Denial of Service via length Property

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaratio…

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.9 MEDIUM
CVE-2026-93751 — uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft perc…

uri-js | Remote | Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.2 HIGH
CVE-2026-93750 — http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wildcard

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string compariso…

Remote | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-93749 — source-map-js through 1.2.1 Event Loop Denial of Service

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large of…

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-93748 — http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached response…

Remote | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.1 MEDIUM
CVE-2026-93432 — Io.quarkus.qute:quarkus-core: cross-site scripting (xss) and json injection via qute {#ev…

A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.5 MEDIUM
CVE-2026-92768 — Cockpit-machines: sensitive data exposure in process list via command-line

A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-lin…

enterprise_linux enterprise_linux | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.0 MEDIUM
CVE-2026-92747 — Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json…

A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `r…

enterprise_linux enterprise_linux | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.0 MEDIUM
CVE-2026-92745 — Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via proc…

A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline to…

enterprise_linux enterprise_linux | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.1 CRITICAL
CVE-2026-92702 — Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty…

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP …

Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.1 CRITICAL
CVE-2026-92701 — Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding…

trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value i…

Remote | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.2 HIGH
CVE-2026-91127 — File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC …

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-85058 — Moquette: Missing Authorization in io.moquette:moquette-broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWr…

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.1 MEDIUM
CVE-2026-84992 — md-editor-v3: XSS via fenced-code language rendering bypass

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdow…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.4 HIGH
CVE-2026-84975 — PJSIP: TLS server identity (hostname) verification bypass via embedded NUL in certificate…

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c co…

Remote | Cryptography
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.2 MEDIUM
CVE-2026-81182 — SysReptor: Unauthorized file disclosure by broken access control in writable shared notes

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from t…

sysreptor | Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
Showing 20 of 14464 Results