Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-91769 — TLS Hostname Verification Falls Back to CN After SAN Mismatch

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once…

php | Cryptography
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.5 MEDIUM
CVE-2026-91767 — Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard…

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are toget…

php | Memory Corruption
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.9 MEDIUM
CVE-2026-91766 — Cross-origin credential leak in HTTP stream wrapper redirects

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a …

php | Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.5 HIGH
CVE-2026-91765 — SOAP: Unbounded Recursion in Server-Side cleanup_xml_node

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements …

php | Remote | Denial of Service
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.3 MEDIUM
CVE-2026-6103 — Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection

phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF …

php | Misconfiguration
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.5 HIGH
CVE-2026-57443 — SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests

SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) expo…

Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.9 MEDIUM
CVE-2026-17545 — PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can c…

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. …

php | Remote | Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.5 HIGH
CVE-2026-10758 — Esri Lerc has a security vulnerability

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earl…

Remote | Memory Corruption
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
3.1 LOW
CVE-2026-100417 — RustDesk before 1.5.0 One-Way File Transfer Bypass

RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers …

rustdesk | Remote | Misconfiguration
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.8 HIGH
CVE-2026-100391 — MediaFlow Proxy through 2.4.9 Server-Side Request Forgery via Incomplete Validation

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers…

Remote | Server-Side Request Forgery
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.1 CRITICAL
CVE-2026-100390 — Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X…

zoraxy | Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.2 CRITICAL
CVE-2026-100389 — GestSup before 3.2.61 Remote Code Execution via IMAP Attachment

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers ca…

gestsup | Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.4 MEDIUM
CVE-2026-100388 — RustDesk before 1.5.0 Missing Authorization Check on Incoming File Clipboard Messages

RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers wi…

rustdesk | Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.1 HIGH
CVE-2026-100387 — pgPointcloud through 1.2.5 heap out-of-bounds read via WKB deserialization

pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers c…

Remote | Memory Corruption
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-100380 — Reflected XSS in Wikibase Special:SetLabel language validation

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). Th…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-100379 — Cross-request disclosure of CentralAuth cookies in Wikipedia Android App

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipe…

Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-100378 — Missing permission check in the Translate sandbox doRemind action

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate …

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.9 MEDIUM
CVE-2026-100377 — Revision-deleted pages can be viewed through WikiLambda's action=edit and Special:ViewAbs…

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation. This issue affects Mediawiki - WikiLambda Extensi…

Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.8 MEDIUM
CVE-2026-100376 — TemplateSandbox can be abused for XSS by asking another user to preview a page with a cer…

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XS…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.4 HIGH
CVE-2026-100369 — CliInvoke: Argument Injection in Extensibility Runner Factory

CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2…

| Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
Showing 20 of 14637 Results