Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-90450 — Improper Authorization via Fail-Open Access Control

The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request han…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-90449 — Reverse Proxy Authentication Bypass

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's o…

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.1 HIGH
CVE-2026-90448 — Application Programming Interface Improper Access Control

A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route ac…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.1 HIGH
CVE-2026-90447 — Routing Rule Authentication Bypass Vulnerability

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client c…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-90446 — Elasticsearch Path Traversal via Improper Input Validation

An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without …

Remote | Server-Side Request Forgery
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.1 HIGH
CVE-2026-90445 — Arbitrary File Write via Zip Slip Vulnerability

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination director…

Remote | Path Traversal
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.7 HIGH
CVE-2026-90444 — Product Name OS Command Injection via Filename Validation Bypass

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system comma…

Remote | Injection
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-90443 — Web Application Cross-Site Scripting and Open Redirect

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthent…

Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.5 MEDIUM
CVE-2026-54258 — Cross-monitor event media authorization bypass in direct event media endpoints

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` a…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.5 MEDIUM
CVE-2026-54248 — Doco-CD has an OCI Trust Policy Bypass via Artifact-Contained Configuration

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact v…

Remote | Misconfiguration
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.4 HIGH
CVE-2026-54241 — libde265: SAO sequential filter heap buffer overflow via signed integer overflow

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted …

Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.4 HIGH
CVE-2026-54240 — libde265: Pixel accessor signed integer overflow causes heap OOB read/write

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image di…

Remote | Memory Corruption
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.5 MEDIUM
CVE-2026-50018 — Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable …

hoverfly | Remote | Denial of Service
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-50013 — Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchroni…

hoverfly | Remote | Race Condition
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.3 MEDIUM
CVE-2026-49992 — Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permiss…

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, a…

kimai | Remote | Cross-Site Request Forgery
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-49846 — libks has path traversal in kws HTTP parser via URI segment overflow

libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its interna…

Remote | Path Traversal
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.2 MEDIUM
CVE-2026-48496 — opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the …

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileg…

| Denial of Service
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-45056 — Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution

matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-cr…

matrix-rust-sdk | Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.7 HIGH
CVE-2026-44715 — OpenMRS has Broken Access Control in HL7 Configuration

OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7Arc…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.1 CRITICAL
CVE-2026-61534 — Yayson Prototype Pollution Vulnerability

# Summary `Store`/`LegacyStore` key internal lookup tables by the `type`, `id`, and relationship names from a JSON:API document. Because these were plain objects, a document with `type: "__proto__"` …

Remote | Misconfiguration
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
Showing 20 of 13718 Results