Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-100520 — Laranode before 1.2.1 Path Traversal in File Manager Upload Endpoint

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directo…

Remote | Path Traversal
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
4.8 MEDIUM
CVE-2026-100505 — Ghidra 11.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager

Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating rema…

ghidra | Memory Corruption
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.3 HIGH
CVE-2026-100504 — Ghidra through 12.1.4 Stack-based Buffer Overflow via leftshift128

Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craf…

ghidra | Memory Corruption
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
4.8 MEDIUM
CVE-2026-100503 — Ghidra through 12.1.4 Heap Use-After-Free in Decompiler

Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a ma…

ghidra | Memory Corruption
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-96795 — Horilla: Authenticated RCE in Horilla List-View Export

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], inte…

horilla | Remote | Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.9 MEDIUM
CVE-2026-86066 — Horilla attendance approval endpoint is vulnerable to cross-site request forgery

Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, …

horilla | Remote | Cross-Site Request Forgery
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.1 HIGH
CVE-2026-57449 — Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositor…

Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official pl…

actual | Remote | Misconfiguration
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.9 MEDIUM
CVE-2026-92842 — OOB read / info leak in convert.* stream filters when line-break-chars contains NUL

The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itsel…

php | Remote | Memory Corruption
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.5 MEDIUM
CVE-2026-91768 — IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memc…

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attac…

php php-fpm | Misconfiguration
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.5 HIGH
CVE-2026-88003 — InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after a role downgrade becau…

invoiceplane | Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.5 HIGH
CVE-2026-71483 — Horilla: Reflected Cross-Site Scripting (XSS) in Employee Filter View

Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutraliz…

horilla | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.5 MEDIUM
CVE-2026-63432 — Horilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allows Authentic…

Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.py render a user-controlled body a…

horilla | Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.5 MEDIUM
CVE-2026-63431 — Horilla: Missing Authorization on Payroll Component Views Exposes Employee Salary Structu…

Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_allowance, and view_singl…

horilla | Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.9 MEDIUM
CVE-2026-100502 — Flame through 2.4.0 Admin Token Insufficient Session Expiration

Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplyi…

Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.3 HIGH
CVE-2026-100501 — Flame through 2.4.0 Brute-Force Attack via Login Endpoint

Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the a…

Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.3 HIGH
CVE-2026-100419 — gitoxide gix-fs before 0.23.0 Worktree Escape via Symlink

gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. Durin…

gix-fs gitoxide | Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.9 MEDIUM
CVE-2026-100418 — Flame through 2.4.0 Information Exposure via GET /api/config

Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can …

Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.8 MEDIUM
CVE-2026-100383 — Stored i18n XSS in WikiLambda's VisualEditor integration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Cross-Site Scripting (XSS). …

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
10.0 CRITICAL
CVE-2026-100382 — Unauthenticated remote code execution through wikitext in ExternalData

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This …

Remote | Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.3 MEDIUM
CVE-2026-100381 — UploadWizard Flickr collection and set titles allow DOM XSS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS).…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
Showing 20 of 14565 Results