Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-76855 — Netcore NR255-V 1.5.130703 Cross-User Session Disclosure via Audit Endpoints

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.…

Remote | Information Disclosure
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.1 HIGH
CVE-2026-76854 — Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via l7_web_auth_user_show.cgi

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling. Attackers can query this compo…

Remote | Information Disclosure
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.1 HIGH
CVE-2026-76853 — Netcore NR268 1.7.121109 Security Check Bypass in parame_put_file.cgi

Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in…

Remote | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.8 HIGH
CVE-2026-76852 — Netcore NR268 1.7.121109 Forgeable Firmware Authenticity Check in mtd_write

Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uui…

Remote | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.8 CRITICAL
CVE-2026-73807 — mySCADA myPRO Manager Missing Authorization

The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnera…

mypro | Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.3 MEDIUM
CVE-2026-73444 — On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) aut…

On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP i…

eos | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.6 CRITICAL
CVE-2026-73437 — On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) …

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from …

eos | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.8 CRITICAL
CVE-2026-61560 — @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables …

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdo…

Remote | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.8 HIGH
CVE-2026-10144 — Rsbuild < 2.0.9 Command Injection via openBrowser() URL Handling

Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands by supplying a crafted URL containing shell metacharacters to the server.open co…

| Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-92237 — Devolutions PowerShell Universal Sensitive Information Disclosure in Log Files

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to ob…

powershell_universal | Information Disclosure
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.4 MEDIUM
CVE-2026-92234 — QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors

QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who fo…

qloapps | Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.7 HIGH
CVE-2026-92000 — adm-zip 0.5.14 through 0.6.0 Denial of Service via Zero Declared Uncompressed Size

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressib…

Remote | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.8 CRITICAL
CVE-2026-91939 — Cotonti 1.0.0 Comments Plugin PHP Object Injection via ci Parameter

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-c…

Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.6 CRITICAL
CVE-2026-91749 — Google Chrome Workers Use-After-Free Vulnerability

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security sever…

chrome chrome | Remote | Memory Corruption
Sep 15, 2026 Sep 16, 2026
Sep 15, 2026
Sep 16, 2026
8.3 HIGH
CVE-2026-91748 — Google Chrome Extensions Race Condition Vulnerability

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execu…

chrome chrome | Remote | Race Condition
Sep 15, 2026 Sep 16, 2026
Sep 15, 2026
Sep 16, 2026
3.1 LOW
CVE-2026-91747 — Google Chrome Skia Use-After-Free Vulnerability

Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium securi…

chrome chrome | Remote | Memory Corruption
Sep 15, 2026 Sep 16, 2026
Sep 15, 2026
Sep 16, 2026
4.3 MEDIUM
CVE-2026-91746 — Google Chrome Compositing Integer Overflow

Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Remote | Information Disclosure
Sep 15, 2026 Sep 16, 2026
Sep 15, 2026
Sep 16, 2026
0.0 NA
CVE-2026-91745 — Google Chrome V8 Use-After-Free Vulnerability

Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.3 MEDIUM
CVE-2026-91744 — Google Chrome PlatformIntegration Race Condition

Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain s…

chrome chrome | Remote | Race Condition
Sep 15, 2026 Sep 16, 2026
Sep 15, 2026
Sep 16, 2026
8.3 HIGH
CVE-2026-91743 — Google Chrome Core Race Condition Vulnerability

Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a craft…

chrome chrome | Remote | Race Condition
Sep 15, 2026 Sep 16, 2026
Sep 15, 2026
Sep 16, 2026
Showing 20 of 14274 Results