Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-97864 — GibbonEdu Gibbon Unit Planner units_add_blockAjax.php makeBlock missing authentication

A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the file modules/Planner/units_add_blockAjax.php of the component Unit Planner. The…

gibbon | Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.5 MEDIUM
CVE-2026-97222 — Gnumeric: gnumeric: heap use-after-free when opening a malformed workbook

A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-objec…

gnumeric | Memory Corruption
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.8 HIGH
CVE-2026-93834 — Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape

A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicio…

Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.3 CRITICAL
CVE-2026-93647 — Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Cal…

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbo…

collaboration_suite | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.8 CRITICAL
CVE-2026-93643 — Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code E…

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-travers…

collaboration_suite | Remote | Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.3 CRITICAL
CVE-2026-93642 — Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share…

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as…

collaboration_suite | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.3 CRITICAL
CVE-2026-93641 — Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Shar…

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act a…

collaboration_suite | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.2 HIGH
CVE-2026-85750 — Piwigo arbitrary file read and remote code execution via insecure image processing

Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of us…

piwigo | Remote | Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.8 HIGH
CVE-2026-85542 — IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attac…

guardium_data_protection | Remote | Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.5 HIGH
CVE-2026-85029 — IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restri…

guardium_data_protection | Remote | Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.6 HIGH
CVE-2026-84893 — IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal databa…

guardium_data_protection | Remote | Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.5 HIGH
CVE-2026-84884 — IBM Guardium Data Protection is affected by multiple vulnerabilities.

IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could…

guardium_data_protection | Remote | Information Disclosure
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.8 MEDIUM
CVE-2026-80431 — Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal …

Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer, b…

kitty | Memory Corruption
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.6 MEDIUM
CVE-2026-80430 — Improper link resolution in the kitty drag and drop protocol allows a client to create fi…

Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to create files a…

kitty | Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.3 MEDIUM
CVE-2026-100190 — Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework showDomain …

The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically it…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.9 MEDIUM
CVE-2026-100187 — AIL Framework Onion Module: Non-Onion URL Accepted as Crawler Task Due to Bypassed Domain…

The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a …

Remote | Server-Side Request Forgery
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.3 MEDIUM
CVE-2026-100177 — Ail Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Organization Co…

The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler tas…

Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.5 HIGH
CVE-2026-100176 — Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip

The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. When an a…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.1 MEDIUM
CVE-2026-100174 — Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped Tag Names

The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS). A user with the ability to create a custom tag could embed an HTML payload con…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.5 HIGH
CVE-2026-100172 — Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic values in HTML…

The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/…

Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
Showing 20 of 14494 Results