Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.8 MEDIUM
CVE-2026-88061 — career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowing…

career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api routes…

Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-84432 — Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog contr…

Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action cre…

Remote | Cross-Site Request Forgery
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.8 HIGH
CVE-2026-55416 — Pimcore Custom Reports Bundle SQL Injection Vulnerability

# Security Advisory: SQL Injection in Custom Reports via Malicious Report Configuration ## Summary ### Impact A SQL injection vulnerability exists in the Custom Reports bundle (`bundles/CustomRepo…

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-9338 — IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple …

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excess…

websphere_application_server | Remote | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-9336 — IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple …

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit t…

websphere_application_server | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.9 CRITICAL
CVE-2026-89049 — Server-side request forgery in the Session Manager port forwarding functionality in AWS S…

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agen…

Remote | Server-Side Request Forgery
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-88060 — Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in F…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side renderin…

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
4.0 MEDIUM
CVE-2026-88059 — Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaP…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common Ht…

Remote | Information Disclosure
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-88058 — Angular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Con…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side renderin…

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-88057 — Angular: Sanitization bypass via directive host bindings on concrete host elements in @an…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runti…

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-88056 — Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Renderin…

Remote | Server-Side Request Forgery
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.3 HIGH
CVE-2026-88036 — GridFS data disclosure and deletion via query-operator injection in file IDs in the Mongo…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query con…

c_driver | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.7 MEDIUM
CVE-2026-88035 — Heap buffer overflow via wrapped size check during SASL username canonicalization in Mong…

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able …

c_driver | Memory Corruption
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.3 HIGH
CVE-2026-88034 — GridFS data disclosure and deletion via query-operator injection in file IDs in the Mongo…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query c…

c_driver | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.3 HIGH
CVE-2026-88033 — GridFS data disclosure and deletion via query-operator injection in file IDs in the Mongo…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query …

java_driver | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.2 HIGH
CVE-2026-88032 — Application denial of service via cancellation race in reactive client-side encryption in…

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the …

java_driver | Remote | Memory Corruption
Sep 10, 2026 Sep 11, 2026
Sep 10, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-88021 — Consul vulnerable to an authorization bypass in the Connect service mesh

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy …

consul | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.7 HIGH
CVE-2026-87993 — Consul-template vulnerable to an information disclosure issue in error handling

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downst…

| Information Disclosure
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.4 MEDIUM
CVE-2026-87107 — Consul vulnerable to an authorization bypass in the catalog deregistration path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{ser…

consul | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-87106 — Consul vulnerable to a denial of service in the native RPC listener

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A …

consul | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Showing 20 of 13408 Results