Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-93858 — OpenStack Mistral Command Injection Vulnerability

In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target host …

Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-107702 — QloApps through 1.7.0 Authorization Bypass via id_hotel in Admin Room Booking

QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminHotelRoomsBookingController::postProcess() that allows restricted back-office employees to access other hotels' data by su…

qloapps | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.4 MEDIUM
CVE-2026-107698 — FFmpeg before 7.1.4 and 8.0.2 SSRF via RTSP Redirect Handling

FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without validating the Locat…

ffmpeg | Remote | Server-Side Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-107697 — FFmpeg before 8.1.3 HLS Demuxer Security Check Bypass via parse_playlist()

FFmpeg before 8.1.3 contains a protection mechanism failure in the HLS demuxer that allows attackers to bypass protocol and allowed_extensions restrictions when opening child playlists. Attackers can…

ffmpeg | Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.1 HIGH
CVE-2026-107696 — FFmpeg through 9.0.2 Infinite Loop via RTSP Redirect Handling in rtsp.c

FFmpeg through 9.0.2 contains an infinite loop vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that follows RTSP 3xx redirects without any redirect limit. Attackers controlling an RTSP serve…

ffmpeg | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.1 HIGH
CVE-2026-107695 — FFmpeg before 8.1.3 HLS Demuxer Infinite Loop via Self-Referencing Playlist

FFmpeg before 8.1.3 contains an infinite loop vulnerability in the HLS demuxer that allows remote attackers to cause denial of service because parse_playlist() accepts Master Playlist tags inside Med…

ffmpeg | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.4 MEDIUM
CVE-2026-107380 — enshrined/svg-sanitize: Stored XSS via DTD Entity / HTML5 Named Character Reference Colli…

savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity referen…

svg-sanitizer | Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-107379 — enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash

savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::rem…

svg-sanitizer | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.7 HIGH
CVE-2026-107378 — CairoSVG: Quadratic-time DoS parsing a crafted SVG <path>

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to 2.9.1, rendering an attacker-controlled SVG with a path containing many segments can cause quadratic CPU consumption in ca…

cairosvg | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.5 HIGH
CVE-2026-107377 — datamodel-code-generator: Protobuf weak-import path traversal allows files to be written …

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured …

Remote | Path Traversal
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.2 HIGH
CVE-2026-107376 — webonyx graphql-php: Unbounded recursion in parser causes stack overflow on crafted neste…

webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseVal…

graphql-php | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.8 HIGH
CVE-2026-107375 — JHipster: SQL Injection in the Parameter of JHipster-Generated Reactive (WebFlux + R2DBC)…

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring…

generator-jhipster | Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.1 HIGH
CVE-2026-107362 — Server-Side Request Forgery in Malcolm

Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream *.php files and Malcolm only overwrites config.php …

Remote | Server-Side Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.2 MEDIUM
CVE-2026-107361 — Authentication Bypass Using an Alternate Path or Channel in Malcolm

The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0.0). Arkime trusts the X-Forwarded-User header from …

| Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.1 HIGH
CVE-2026-107337 — Cross-Site Request Forgery in Malcolm

The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard CORS (CORS(app)). An attacker can force the operator's browser to execute arbit…

| Cross-Site Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-107336 — Authentication Bypass by Spoofing in Malcolm

Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lo…

Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-107335 — Improper Handling of Highly Compressed Data in Malcolm

Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchiv…

Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.4 MEDIUM
CVE-2026-107334 — Incorrect Authorization in Malcolm

Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upl…

Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.1 HIGH
CVE-2026-107333 — Incorrect Authorization in Malcolm

Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. A…

Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.8 MEDIUM
CVE-2026-107332 — Insecure Default File Permissions on Cached Credentials in AWS Toolkit for Visual Studio …

Insecure file permissions in the CodeCatalyst connection handler in AWS Toolkit for VS Code before 4.10.0 allowed local users to obtain CodeCatalyst bearer tokens via reading world-readable token cac…

aws-toolkit-vscode | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 14454 Results