Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.7 HIGH
CVE-2026-45562 — FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module

FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrar…

freepbx | Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.3 MEDIUM
CVE-2026-101913 — ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing S…

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the co…

ip-address | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.3 MEDIUM
CVE-2026-101912 — ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as …

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings w…

ip-address | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.3 MEDIUM
CVE-2026-101911 — ip-address: Address6 builds a parse diagnostic proportional to the input with no length b…

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded…

ip-address | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.9 MEDIUM
CVE-2026-101910 — ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing S…

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 loc…

ip-address | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.3 HIGH
CVE-2026-101909 — Axios: Prototype Pollution Gadget in axios toFormData Options

Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplie…

axios | Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.9 MEDIUM
CVE-2026-101908 — Axios: Prototype pollution gadget in fetch adapter can alter outbound requests

Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original…

axios | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.0 HIGH
CVE-2026-101907 — Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF

Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter wit…

axios | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.2 HIGH
CVE-2026-101906 — Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted red…

Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy applies a quadratic trailing-dot regular expression to redirect hostnames. HTTP_PRO…

axios | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.6 HIGH
CVE-2026-101905 — Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inhe…

Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection valu…

axios | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.9 MEDIUM
CVE-2026-101904 — Axios: Header Injection via Inherited headers After Minimal Interceptor

Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request config…

axios | Remote | Information Disclosure
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.2 HIGH
CVE-2026-101903 — Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)

Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An appli…

axios | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.9 MEDIUM
CVE-2026-101902 — Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototy…

Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value …

axios | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.2 HIGH
CVE-2026-101901 — Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initia…

Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session…

axios | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.9 MEDIUM
CVE-2026-101900 — Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders

Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormDat…

axios | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.0 HIGH
CVE-2026-101898 — Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls

Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy…

axios | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-101102 — deepseek-ai deepseek-harness Code Mode Sandbox run_code sandbox

A vulnerability was found in deepseek-ai deepseek-harness up to 0.1.0-rc.7. Impacted is the function run_code of the component Code Mode Sandbox. The manipulation results in sandbox issue. The attack…

deepseek-harness | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-101101 — ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception

A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads t…

ag-ui | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.5 MEDIUM
CVE-2026-101100 — ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup

A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddleware of the file sdks/typescript/packages/client/src/middleware/filter-too…

ag-ui | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-101099 — ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition

A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. Performing a manipulation results i…

ag-ui | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
Showing 20 of 14293 Results