Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-71553 — ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persiste…

ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module t…

apostrophecms | Remote | Denial of Service
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
4.3 MEDIUM
CVE-2026-71486 — vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output…

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse ob…

vllm vllm | Remote | Denial of Service
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
9.1 CRITICAL
CVE-2026-71472 — Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-st…

A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands o…

Aug 17, 2026 Aug 27, 2026
Aug 17, 2026
Aug 27, 2026
8.8 HIGH
CVE-2026-70495 — Search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared a…

A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker ga…

Aug 17, 2026 Aug 27, 2026
Aug 17, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-68005 — ACME mini_httpd Denial of Service Vulnerability

An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_request() function

Remote | Denial of Service
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-68004 — OSSRS SRS Remote Code Execution Vulnerability

An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsS…

Remote | Authorization
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-67678 — RainyGao-Hithub DocSys Arbitrary Code Execution via Unrestricted File Upload

File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code

Remote | Injection
Aug 17, 2026 Aug 31, 2026
Aug 17, 2026
Aug 31, 2026
6.1 MEDIUM
CVE-2026-63670 — ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close

ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp i…

apostrophecms | Remote | Cross-Site Scripting
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
6.5 MEDIUM
CVE-2026-63669 — ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-pri…

ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldPare…

apostrophecms | Remote | Authorization
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
6.5 MEDIUM
CVE-2026-63667 — ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal

ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the…

apostrophecms | Remote | Path Traversal
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
8.5 HIGH
CVE-2026-57485 — Stirling-PDF: Internal Service Account API Key Disclosure via Pipeline Endpoint

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software…

stirling_pdf | Remote | Information Disclosure
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
8.1 HIGH
CVE-2026-57233 — Notepad++: Path Traversal (Zip Slip) in WinGup Plugin Extraction

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowin…

notepad\+\+ | Remote | Path Traversal
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
7.8 HIGH
CVE-2026-54758 — Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrs

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEditor/src/WinControls/StaticDialog/RunDlg/RunDlg.cpp copies a Notepad++ variable…

notepad\+\+ | Memory Corruption
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
5.1 MEDIUM
CVE-2026-52886 — Notepad++: session.xml backupFilePath starts_with Bypass

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::wstring::starts_with against the expected backup di…

notepad\+\+ | Path Traversal
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-19650 — Cross-Site Request Forgery (CSRF) in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could hav…

gitlab | Remote | Authentication
Aug 17, 2026 Sep 02, 2026
Aug 17, 2026
Sep 02, 2026
9.4 CRITICAL
CVE-2026-19478 — Improper Control of Generation of Code ('Code Injection') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could all…

gitlab | Remote | Authorization
Aug 17, 2026 Sep 02, 2026
Aug 17, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-75011 — kylecui NetForensicMCP index.js execAsync command injection

A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executing a manipulation of the argument interface/protocol can lead to command injecti…

netforensicmcp | Remote | Injection
Aug 17, 2026 Aug 20, 2026
Aug 17, 2026
Aug 20, 2026
8.7 HIGH
CVE-2026-74238 — TIER IV Nebula 1.2.0 Heap Out-of-Bounds Read via VLP32 UDP Decoder

TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end…

Remote | Memory Corruption
Aug 17, 2026 Aug 20, 2026
Aug 17, 2026
Aug 20, 2026
9.9 CRITICAL
CVE-2026-66792 — Multicloud-operators-subscription: multicloud-operators-subscription: isclusteradmin() tr…

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, craft…

Aug 17, 2026 Aug 27, 2026
Aug 17, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-50776 — Pronis Loisirs Billetterie CSE Directory Traversal Vulnerability

Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code.

Remote | Path Traversal
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
Showing 20 of 14652 Results