Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-91120 — Discourse: Stored HTML injection in video notification emails

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlled video titles in lazy video embeds could be reparsed as HTML when Discourse ge…

discourse | Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.4 MEDIUM
CVE-2026-91119 — Discourse: Encode action_code_who in mention URLs

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated the free-form action_code_…

discourse | Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.7 HIGH
CVE-2026-85057 — ZITADEL: Actions V1 sandbox escape: host file read via require()

ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without restricting its filesystem s…

zitadel | Remote | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.2 HIGH
CVE-2026-85056 — ZITADEL: MFA bypass via session reuse in Login V2

ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that session for a later authenti…

zitadel | Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.3 MEDIUM
CVE-2026-81508 — ESF-IDF: Heap Out-of-Bounds Read in Bluedroid A2DP Sink Media Packet Processing

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP sink function btc_a2dp_sink_handle_inc_media() reads a timestamp field from the r…

esp-idf | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-71540 — Wazuh Manager cluster header parsing allows pre-authentication memory exhaustion

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.p…

wazuh | Remote | Denial of Service
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-63645 — OpenObserve: Unauthenticated /config/runtime endpoint exposes PostgreSQL database credent…

OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after…

openobserve | Remote | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-61816 — zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing …

zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in version 2.0.0 and prior to…

Remote | Denial of Service
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.2 HIGH
CVE-2026-61815 — zbateson/mail-mime-parser has CRLF header injection via attachment filename

zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to version 3.0.6 and 4.0.2, CRLF…

Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-61811 — Wazuh: Unbounded Recursion in os_xml `_getattributes()` Causes analysisd Worker Thread St…

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() function in src/os_xml/os_xml.c re…

wazuh | Remote | Denial of Service
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.4 HIGH
CVE-2026-61788 — @bytebase/dbhub's read-only mode does not prevent database writes

DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting `readonly = true` on the `execute_sql` tool does not make the connection read…

Remote | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.1 MEDIUM
CVE-2026-61784 — xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS

xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values when serializi…

Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-61782 — @rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and…

Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds to all network interf…

Remote | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.3 CRITICAL
CVE-2026-61742 — DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution

DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started with the documented HTTP tra…

Remote | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.3 CRITICAL
CVE-2026-61741 — http4s-scala-xml has an XML External Entity (XXE) processing issue

http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory…

Remote | XML External Entity
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
10.0 CRITICAL
CVE-2026-61732 — Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output c…

Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutr…

Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.3 CRITICAL
CVE-2026-61604 — ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass

The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification meth…

Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.2 MEDIUM
CVE-2026-57179 — social-auth-core has a Session Fixation issue

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it …

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.4 HIGH
CVE-2026-57178 — social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when …

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.3 MEDIUM
CVE-2026-57177 — social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using t…

Remote | Cross-Site Request Forgery
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
Showing 20 of 14191 Results