Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-76731 — Authentication Bypass in the Captive Portal of HPE Networking Instant On

An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exp…

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.5 MEDIUM
CVE-2026-76730 — Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON A…

An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication control…

| Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.6 MEDIUM
CVE-2026-76729 — Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Inst…

A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. …

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.2 HIGH
CVE-2026-76728 — Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Network…

A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successf…

Remote | Server-Side Request Forgery
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.2 HIGH
CVE-2026-76727 — Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON

Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Suc…

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.1 HIGH
CVE-2026-76726 — Authentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON…

An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outsi…

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.6 CRITICAL
CVE-2026-76725 — Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs

A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Suc…

| Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.6 CRITICAL
CVE-2026-76724 — Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs…

A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially c…

| Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.6 CRITICAL
CVE-2026-76723 — Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in…

Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exp…

| Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.8 CRITICAL
CVE-2026-76722 — Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Ser…

Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underl…

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.8 CRITICAL
CVE-2026-76721 — Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Netwo…

Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successfu…

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-67993 — Upright Login Cross-Site Request Forgery

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.

| Cross-Site Request Forgery
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-67987 — ruby_llm Regular Expression Denial of Service

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or …

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.8 HIGH
CVE-2026-61519 — Liberu CRM 0.9.1 < 10.0.0 Broken Access Control via TeamPolicy::addTeamMember()

Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated pr…

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.3 MEDIUM
CVE-2026-53989 — Dockhand < 1.0.36 Open Redirect via OIDC Initiation Endpoint

Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that allows unauthenticated remote attackers to redirect authenticated users to attacker-controlled site…

Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
10.0 CRITICAL
CVE-2026-53988 — Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints

Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting…

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.8 CRITICAL
CVE-2026-39117 — AltumCode 66Uptime Remote Code Execution

An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.3 MEDIUM
CVE-2026-102879 — ClaraVerse through 0.3.1 SSRF Protection Bypass

ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the download_file and scrape_web agent tools. Authenticated users can bypass hostname validation and IPv6 transiti…

Remote | Server-Side Request Forgery
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.6 HIGH
CVE-2026-102878 — mcp-chrome-bridge through 1.0.31 CORS Origin Bypass

mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make…

Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.4 MEDIUM
CVE-2026-102877 — Fider before 0.38.0 SSRF via DNS rebinding in webhook validation

Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators cont…

Remote | Server-Side Request Forgery
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14665 Results