Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-80217 — FF-RFI Remote Command Execution Vulnerability

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

| Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.8 HIGH
CVE-2026-77853 — Fujitsu M-Plane OS Command Injection

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may ex…

| Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.0 HIGH
CVE-2026-76159 — Duplicati for Windows - Incorrect Permission Assignment for Critical Resource

Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privilege…

| Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.3 HIGH
CVE-2026-75092 — Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysql…

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --…

Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.9 MEDIUM
CVE-2026-91819 — MISP: HTTP Method Override Bypasses CSRF and Form Validation in BetterSecurityComponent

Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override hea…

misp | Remote | Cross-Site Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.2 HIGH
CVE-2026-91778 — Octopus Server Arbitrary Script Execution Vulnerability

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission vali…

octopus_server | Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.0 MEDIUM
CVE-2026-91091 — GPAC Node Insertion base_scenegraph.c gf_node_list_insert_child memory corruption

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such ma…

gpac | Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
3.9 LOW
CVE-2026-91090 — GPAC base_scenegraph.c gf_node_activate_ex stack-based overflow

A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer o…

gpac | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-91089 — GPAC base_scenegraph.c gf_node_get_name_and_id use after free

A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible…

gpac | Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
4.8 MEDIUM
CVE-2026-91088 — GPAC URL url.c gf_url_concatenate_ex heap-based overflow

A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based…

gpac | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-91087 — GPAC Compositor media_object.c gf_mo_get_od_id use after free

A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can l…

gpac | Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-91086 — GPAC MPEG Video Reframer reframe_mpgvid.c mpgviddmx_process heap-based overflow

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. …

gpac | Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.5 MEDIUM
CVE-2026-91005 — SourceCodester Online Faculty Clearance System Profile Picture Upload edit_picture.php mo…

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture …

online_faculty_clearance_system | Remote | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.1 CRITICAL
CVE-2026-90711 — proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet writ…

| Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.5 MEDIUM
CVE-2026-89141 — AI Engine <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sens…

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' para…

ai_engine | Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-75983 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.23 - Authen…

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the …

Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.4 MEDIUM
CVE-2026-18063 — Job Postings <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pos…

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitizati…

jobs_for_wordpress | Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.4 MEDIUM
CVE-2026-15402 — Eventin <= 4.1.23 - Authenticated (Custom+) Stored Cross-Site Scripting via 'etn_shedule_…

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter …

Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-91004 — SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument I…

online_faculty_clearance_system | Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.1 CRITICAL
CVE-2026-91003 — D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes s…

Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
Showing 20 of 13017 Results