Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.6 MEDIUM
CVE-2026-54177 — backpack/crud: HasUploadFields keeps the attacker-supplied file extension — public-disk u…

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.…

Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.5 MEDIUM
CVE-2026-54176 — backpack/crud: MyAccountController allows changing the login email without a current-pass…

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.…

Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.6 HIGH
CVE-2026-54175 — backpack/crud: Unverified password change in MyAccountController via mass assignment

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, My…

Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.9 MEDIUM
CVE-2026-54150 — next-video: Unauthenticated arbitrary file read via /api/video request handler

next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts an unauthenticated…

Remote | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.6 HIGH
CVE-2026-54087 — EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileFiel…

EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.t…

Remote | Cross-Site Scripting
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-53752 — docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively fol…

Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-53659 — http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` al…

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression f…

Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.8 MEDIUM
CVE-2026-53495 — containerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of Service

containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in inte…

containerd | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-50276 — dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defau…

Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.5 HIGH
CVE-2026-50270 — dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which default…

dd-trace-java | Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.5 MEDIUM
CVE-2026-50157 — Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security a…

symfony | Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
3.3 LOW
CVE-2026-49400 — October CMS: PHP Object Injection via Backend Widget Session Storage

October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, the backend `SessionMaker` trait stored widget session state as `base64(serialize…

october | Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.7 HIGH
CVE-2026-49250 — Conform: parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields

Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From 1.8.0 until 1.19.4, the parseSubmission future API in packages/conform-dom/form…

Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.3 MEDIUM
CVE-2026-47256 — OpenTelemetry: Path traversal in Sentry exporter via attacker-controlled service.name rea…

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. P…

opentelemetry_collector_contrib | Remote | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
3.3 LOW
CVE-2026-46696 — October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls

October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained by…

Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
2.7 LOW
CVE-2026-44162 — fluent-plugin-s3: Denial of Service (DoS) via Decompression Bomb in `in_s3`

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory wi…

Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.2 HIGH
CVE-2026-34151 — XWiki Platform: Resource path traversal via /skin/ action endpoint in Jetty 12+

XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended ski…

xwiki | Remote | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.6 MEDIUM
CVE-2026-19542 — Stack-based out-of-bounds write in tdelete during tree rebalancing

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. Th…

Remote | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.7 HIGH
CVE-2026-19499 — Buffer overflow in strfmon and strfmon_l right-justification padding

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation…

Remote | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
4.8 MEDIUM
CVE-2026-90804 — GNU Binutils Eh Frame Section elf-eh-frame.c _bfd_elf_write_section_eh_frame buffer overf…

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Per…

binutils | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
Showing 20 of 12618 Results