Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-81569 — Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized…

An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow…

dolphinscheduler | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.7 HIGH
CVE-2026-4034 — TIBCO Administrator Injection Vulnerability

Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console.

administrator | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.1 HIGH
CVE-2026-95520 — Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow w…

A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in i…

Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.8 HIGH
CVE-2026-87748 — Privilege Escalation via Account Takeover in Interprobe's Qorela DC

Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2.

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.3 CRITICAL
CVE-2026-85520 — Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module

Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that …

Remote | Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.5 MEDIUM
CVE-2026-73597 — Dell Secure Connect Gateway Cross-Site Request Forgery Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potent…

secure_connect_gateway_policy_manager | Remote | Cross-Site Request Forgery
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
3.8 LOW
CVE-2026-73596 — Dell Secure Connect Gateway Policy Manager Insecure Default Initialization Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote…

secure_connect_gateway_policy_manager | Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.7 MEDIUM
CVE-2026-73595 — Dell Secure Connect Gateway Improper Verification of Cryptographic Signature Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker …

secure_connect_gateway_policy_manager | Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.4 MEDIUM
CVE-2026-73594 — Dell Secure Connect Gateway Improper Certificate Validation Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adj…

secure_connect_gateway_policy_manager | Information Disclosure
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
3.0 LOW
CVE-2026-73593 — Dell Secure Connect Gateway Active Debug Code Vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerability. A high privileged attacker with local access could potentially exploit thi…

secure_connect_gateway_policy_manager | Information Disclosure
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-66083 — Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasour…

The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not a…

dolphinscheduler | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.9 MEDIUM
CVE-2026-41875 — Cross-Site Request Forgery in admin panel of Quick.Cart

Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request tha…

quick.cart | Remote | Cross-Site Request Forgery
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.8 MEDIUM
CVE-2026-102507 — Sliver 1.7.7 Denial of Service via PE Parser Slice Bounds in Operator RPC

Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire team…

sliver | Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-102497 — Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker

The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walke…

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-102496 — Apache XMLSchema: Denial of service through deeply nested schema structures

Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a deni…

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-102495 — Apache XMLSchema: Denial of service through unbounded recursion when resolving schema imp…

Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users a…

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
1.3 LOW
CVE-2026-101266 — Checkout validation bypass

A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps.

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.8 HIGH
CVE-2026-95509 — Out-of-bounds read vulnerability in string formatting impacts Qt for MCUs

Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.5 MEDIUM
CVE-2026-96423 — Heap-based Buffer Overflow in Wireshark

X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.5 MEDIUM
CVE-2026-96422 — Reachable Assertion in Wireshark

Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

| Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14424 Results