Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-93958 — D-Link R95 DHMAPI ssi system os command injection

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-93957 — olivier-ls PHP-FTS Filter Matching SearchEngine.php matchesSingleFilter comparison

A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleFilter of the file src/SearchEngine.php of the component Filter Matching. The ma…

Remote | Misconfiguration
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
3.3 LOW
CVE-2026-86551 — Wi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX7…

The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure data…

| Information Disclosure
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.0 MEDIUM
CVE-2026-94057 — Exim SMTP Smuggling Vulnerability

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
7.5 HIGH
CVE-2026-94056 — Exim Information Disclosure Vulnerability

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

Remote | Memory Corruption
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
3.7 LOW
CVE-2026-94055 — Exim Use-After-Free Vulnerability

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

Remote | Memory Corruption
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
7.0 HIGH
CVE-2026-94054 — Exim Proxy-Protocol Out-of-Bounds Write

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

Remote | Memory Corruption
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.8 HIGH
CVE-2026-93993 — Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a cr…

Remote | Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.1 HIGH
CVE-2026-93992 — Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft maliciou…

Remote | Path Traversal
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.3 HIGH
CVE-2026-93991 — Argo Workflows 4.1.0 through 4.1.3 Cross-Namespace Disclosure via Negated Selector

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field s…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.7 HIGH
CVE-2026-93990 — Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone hi…

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
3.1 LOW
CVE-2026-93989 — vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token …

vllm | Remote | Memory Corruption
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
7.1 HIGH
CVE-2026-93988 — QloApps through 1.7.0 Arbitrary File Read via getEmailHTML

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply re…

qloapps | Remote | Path Traversal
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.0 MEDIUM
CVE-2026-93956 — olivier-ls PHP-FTS Search SearchEngine.php buildHighlights cross site scripting

A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. Executin…

Remote | Cross-Site Scripting
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-93955 — grimmory-tools grimmory Download Endpoint KoboController.java streamFileToResponse author…

A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controlle…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
4.3 MEDIUM
CVE-2026-93954 — grimmory-tools grimmory Settings API Endpoint AppSettingController.java AppSettingControl…

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/co…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.3 MEDIUM
CVE-2026-82672 — Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against…

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint…

mint | Remote | Misconfiguration
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
0.0 NA
CVE-2026-82560 — Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD…

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin…

| Denial of Service
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.5 MEDIUM
CVE-2026-94001 — Keycloak-services: keycloak-services: admin credential delete bypasses denied reset-passw…

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained r…

single_sign-on build_of_keycloak | Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
6.6 MEDIUM
CVE-2026-94000 — Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to r…

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a gro…

single_sign-on build_of_keycloak | Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
Showing 20 of 13894 Results