Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-38998 — LIVE555 Streaming Media Use-After-Free Vulnerability

A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via…

| Memory Corruption
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.5 HIGH
CVE-2026-79323 — Magefan Blog GraphQL Information Disclosure

Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog comm…

Remote | Information Disclosure
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.6 HIGH
CVE-2026-79322 — Mageplaza Blog for Magento SQL Injection

SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands …

Remote | Injection
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
4.3 MEDIUM
CVE-2026-61907 — Cyrus IMAP JMAP Snooze Access Control Bypass

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause inse…

cyrus_imap | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
9.6 CRITICAL
CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin…

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escal…

Remote | Cross-Site Scripting
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-52482 — SJRC F11 SJ-GPS-PRO Information Disclosure Vulnerability

An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service spawns /app/sh_for_telnet

| Information Disclosure
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.5 MEDIUM
CVE-2026-39020 — Wings3D Denial of Service Vulnerability

An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file

| Denial of Service
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.5 MEDIUM
CVE-2025-51619 — Thesycon DPC Latency Checker Kernel Memory Corruption Denial of Service

A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause a denial-of-service (BSOD) condition on Windows systems. The driver exposes an…

| Memory Corruption
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.6 HIGH
CVE-2026-8044 — [Product/Vendor Name] Argument Injection Vulnerability

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when ma…

Remote | Injection
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
9.2 CRITICAL
CVE-2026-87930 — MaxSite CMS through 109.6 PHP Object Injection via ci_session

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies…

cms | Remote | Information Disclosure
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-87929 — MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge adminis…

cms | Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-87928 — MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page

MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML co…

cms | Remote | Cross-Site Scripting
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.8 HIGH
CVE-2026-87927 — MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supply…

cms | Remote | Path Traversal
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
3.0 LOW
CVE-2026-87876 — Cups: openprinting cups: remaining case-insensitive username matching in scheduler side p…

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of us…

Sep 09, 2026 Sep 10, 2026
Sep 09, 2026
Sep 10, 2026
4.3 MEDIUM
CVE-2026-87875 — Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-…

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNM…

Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.1 HIGH
CVE-2026-87874 — Community.general: community.general: memcached cache plugin deserializes untrusted pickl…

A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit s…

ceph_storage openstack_platform | Remote | Memory Corruption
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
6.8 MEDIUM
CVE-2026-87872 — Community.general: community.general: ocapi module_utils (ocapi_command, ocapi_info) hard…

A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and…

ceph_storage openstack_platform | Misconfiguration
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.5 HIGH
CVE-2026-87853 — Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, perf…

Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.7 MEDIUM
CVE-2026-85788 — Incomplete list of disallowed inputs in awslabs mysql-mcp-server

Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach f…

Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
0.0 NA
CVE-2026-80925 — vlan: fix skb_under_panic and races when toggling HW VLAN offload

In the Linux kernel, the following vulnerability has been resolved: vlan: fix skb_under_panic and races when toggling HW VLAN offload Toggling hardware VLAN TX offload (NETIF_F_HW_VLAN_CTAG_TX or N…

linux_kernel | Race Condition
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
Showing 20 of 13953 Results