Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.5 CRITICAL
CVE-2026-88062 — OmniRoute ACP Custom-Agent Remote Code Execution (RCE)

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-…

Remote | Misconfiguration
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.8 MEDIUM
CVE-2026-88061 — career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowing…

career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api routes…

Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-84432 — Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog contr…

Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action cre…

concrete_cms | Remote | Cross-Site Request Forgery
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.8 HIGH
CVE-2026-55416 — Pimcore Custom Reports Bundle SQL Injection Vulnerability

# Security Advisory: SQL Injection in Custom Reports via Malicious Report Configuration ## Summary ### Impact A SQL injection vulnerability exists in the Custom Reports bundle (`bundles/CustomRepo…

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-9338 — IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple …

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excess…

websphere_application_server | Remote | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.5 MEDIUM
CVE-2026-9336 — IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple …

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit t…

websphere_application_server | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.9 CRITICAL
CVE-2026-89049 — Server-side request forgery in the Session Manager port forwarding functionality in AWS S…

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agen…

amazon_ssm_agent | Remote | Server-Side Request Forgery
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-88060 — Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in F…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side renderin…

angular | Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
4.0 MEDIUM
CVE-2026-88059 — Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaP…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common Ht…

angular | Remote | Information Disclosure
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-88058 — Angular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Con…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side renderin…

angular | Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-88057 — Angular: Sanitization bypass via directive host bindings on concrete host elements in @an…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runti…

angular | Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-88056 — Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Renderin…

angular | Remote | Server-Side Request Forgery
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.3 HIGH
CVE-2026-88036 — GridFS data disclosure and deletion via query-operator injection in file IDs in the Mongo…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query con…

c_driver | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.7 MEDIUM
CVE-2026-88035 — Heap buffer overflow via wrapped size check during SASL username canonicalization in Mong…

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able …

c_driver | Memory Corruption
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.3 HIGH
CVE-2026-88034 — GridFS data disclosure and deletion via query-operator injection in file IDs in the Mongo…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query c…

c_driver c\+\+_driver | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.3 HIGH
CVE-2026-88033 — GridFS data disclosure and deletion via query-operator injection in file IDs in the Mongo…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query …

java_driver | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.2 HIGH
CVE-2026-88032 — Application denial of service via cancellation race in reactive client-side encryption in…

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the …

java_driver | Remote | Memory Corruption
Sep 10, 2026 Sep 11, 2026
Sep 10, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-88021 — Consul vulnerable to an authorization bypass in the Connect service mesh

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy …

consul | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.7 HIGH
CVE-2026-87993 — Consul-template vulnerable to an information disclosure issue in error handling

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downst…

terraform_provider | Information Disclosure
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.4 MEDIUM
CVE-2026-87107 — Consul vulnerable to an authorization bypass in the catalog deregistration path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{ser…

consul | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Showing 20 of 13425 Results