Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-16876 — NEC UNIVERGE IX-R/IX-V Authentication Bypass Vulnerability

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and s…

Remote | Authentication
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
5.0 MEDIUM
CVE-2026-86238 — projectworlds Online Examination System Feedback Form feedback.php cross site scripting

A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipul…

online_examination_system | Remote | Cross-Site Scripting
Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
5.5 MEDIUM
CVE-2026-86237 — openagents-org openagents http.py test_default_model server-side request forgery

A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manip…

openagents | Remote | Server-Side Request Forgery
Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86236 — itsourcecode Sales and Inventory System pro_transac.php add sql injection

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of the argum…

sales_and_inventory_system | Remote | Injection
Sep 07, 2026 Sep 11, 2026
Sep 07, 2026
Sep 11, 2026
6.5 MEDIUM
CVE-2026-86235 — itsourcecode Sales and Inventory System pos_transac.php add sql injection

A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the argument Customer…

sales_and_inventory_system | Remote | Injection
Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86234 — itsourcecode Sales and Inventory System cust_transac.php add sql injection

A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname re…

sales_and_inventory_system | Remote | Injection
Sep 07, 2026 Sep 09, 2026
Sep 07, 2026
Sep 09, 2026
6.5 MEDIUM
CVE-2026-86233 — itsourcecode Sales and Inventory System us_del.php sql injection

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulati…

sales_and_inventory_system | Remote | Injection
Sep 07, 2026 Sep 08, 2026
Sep 07, 2026
Sep 08, 2026
9.8 CRITICAL
CVE-2026-86304 — MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass bec…

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authe…

Remote | Authentication
Sep 06, 2026 Sep 08, 2026
Sep 06, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-86232 — itsourcecode Sales and Inventory System sup_del.php sql injection

A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing a man…

sales_and_inventory_system | Remote | Injection
Sep 06, 2026 Sep 08, 2026
Sep 06, 2026
Sep 08, 2026
3.7 LOW
CVE-2026-86231 — mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation

A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the ar…

jsch | Remote | Misconfiguration
Sep 06, 2026 Sep 11, 2026
Sep 06, 2026
Sep 11, 2026
4.3 MEDIUM
CVE-2026-86228 — JeecgBoot AiragModelController.java exportXls access control

A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/o…

jeecgboot | Remote | Authorization
Sep 06, 2026 Sep 08, 2026
Sep 06, 2026
Sep 08, 2026
3.1 LOW
CVE-2026-86227 — valkey-io valkey kvstore.c kvstoreGetHashtable out-of-bounds

A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bou…

valkey | Remote | Memory Corruption
Sep 06, 2026 Sep 09, 2026
Sep 06, 2026
Sep 09, 2026
Showing 20 of 15432 Results