Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.1 LOW
CVE-2026-54649 — punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloudfl…

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(),…

Remote | Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.8 CRITICAL
CVE-2026-54617 — GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default…

Remote | Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.7 HIGH
CVE-2026-54571 — ESPAsyncWebServer: Integer overflow in multipart boundary parser causes denial of service

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPos…

Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.1 HIGH
CVE-2026-54524 — Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Report

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Pay…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-54504 — MCP Documentation Server: Web UI API binds to all interfaces without authentication by de…

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startW…

| Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.2 HIGH
CVE-2026-54451 — Elixir protobuf: Unbounded recursion depth in embedded-message decoding

Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when th…

protobuf | Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.2 HIGH
CVE-2026-54253 — TS3 Manager: Reflected XSS via /api/download port parameter steals operator session

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter …

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-54239 — FaustWP — Authentication Bypass via Initialization Vector Modification in Token Envelope

Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-52852 — Traccar: Uncontrolled Infinite Loop DoS via Group Parent Cycle

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a tri…

Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.1 HIGH
CVE-2026-52851 — Traccar: Authenticated Blind SQL Injection in DELETE /api/permissions

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an ext…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.2 HIGH
CVE-2026-52727 — lxc-ci: Pacman keyring stored in archlinux image with a private key

lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-sign…

Remote | Supply Chain
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NONE
CVE-2026-49292 — Kiwi TCMS: The /init-db/ page renders and responds to requests after first use

Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies rep…

kiwi_tcms | Remote | Misconfiguration
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.0 CRITICAL
CVE-2026-47252 — Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrom…

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.6 HIGH
CVE-2026-19477 — Stack-based Buffer Overflow Vulnerability in Linux (uldaq)

There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information disclosure or arbitrary code execution. This vulnera…

| Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.5 MEDIUM
CVE-2026-92927 — SourceCodester Drug Recommendation System drug_recommendor.sql information disclosure

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in infor…

Remote | Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.5 HIGH
CVE-2026-92926 — code-projects Matrimonial System partner_preference.php writepartnerprefs sql injection

A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argumen…

matrimonial_system | Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.9 MEDIUM
CVE-2026-89038 — Verizon Cloud for Android < 26.7.10 Path Traversal via OneTouchUploadActivity

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the…

| Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-54677 — Scoold: Authenticated user can post replies and comments to private-space questions witho…

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of a private space can create content in questions belonging to that space because…

scoold | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-54676 — Scoold: GET /api/posts/{id}/answers leaks private-space replies when personal API tokens …

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieve replies from questions in private spaces they cannot access because src/main/j…

scoold | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.3 MEDIUM
CVE-2026-54551 — WireGuard Portal: Authenticated WebSocket /api/v0/ws broadcasts all peers' and interfaces…

WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.3.0, the authenticated GET /api/v0/ws statistics WebSocket in internal/app/api/…

Remote | Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14422 Results