Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-107586 — Allocation of Resources Without Limits or Throttling in hMailServer

Uncontrolled eviction in the browser session table of the REST API in Progressive Robot hMailServer 6.2.28 through 6.3.5 allows a remote authenticated user to end other users' sessions. The table of …

Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-107585 — Allocation of Resources Without Limits or Throttling in hMailServer

Uncontrolled eviction in the pending sign-in tables of the REST API in Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to make other users' OpenID Connect, SAML…

Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.1 MEDIUM
CVE-2026-107565 — Luksmeta: incomplete gap-boundary and overlap checks in luks1 metadata allocator allow da…

A flaw was found in luksmeta. A local attacker with administrative privileges can cause data corruption when saving metadata to a Linux Unified Key Setup (LUKS) device. Due to incorrect boundary calc…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.5 HIGH
CVE-2026-107286 — Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends …

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limit_model_con…

pydantic_ai | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.3 HIGH
CVE-2026-105833 — EspoCRM before 10.0.5 IDOR via PersonalAccount Service Exposes IMAP Passwords

EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. …

espocrm | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-105832 — EspoCRM before 10.0.6 Two-Factor Authentication Bypass on Unauthenticated Routes

EspoCRM before 10.0.6 contains an authentication bypass vulnerability that accepts a login stopped at the second factor on routes not requiring authentication. Attackers knowing a 2FA-enabled user's …

espocrm | Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-105831 — EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form

EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stor…

espocrm | Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.7 HIGH
CVE-2026-105830 — league/commonmark 2.0.0 before 2.10.2 Quadratic DoS via TableStartParser

league/commonmark from 2.0.0 before 2.10.2 contains a quadratic-time denial of service vulnerability in the GitHub Flavored Markdown Table extension's TableStartParser::tryStart() block-start scan. U…

commonmark | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.1 MEDIUM
CVE-2026-105829 — League CommonMark 1.3.0 before 2.10.2 Stored XSS via DisallowedRawHtml Bypass

League CommonMark from 1.3.0 before 2.10.2 contains a cross-site scripting vulnerability that allows users posting Markdown to bypass the DisallowedRawHtml extension by ending raw HTML with a bare di…

commonmark | Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.3 MEDIUM
CVE-2026-105828 — Parse Server 9.0.0 before 9.10.1-alpha.12 Class Name Disclosure via GraphQL Errors

Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an information disclosure vulnerability in which GraphQL validation error messages reveal hidden class names when public int…

parse-server | Remote | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.9 MEDIUM
CVE-2026-105827 — ImageMagick before 7.1.2-30 Stack Overflow in CALS Decoder

ImageMagick before 7.1.2-30 and 6.9.13-55 contains an uncontrolled recursion vulnerability in the CALS decoder due to a missing depth check. Attackers can supply a crafted CALS image that triggers un…

imagemagick | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.9 MEDIUM
CVE-2026-105826 — ImageMagick before 7.1.2-30 Security Policy Bypass via MAT Decoder

ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a security policy bypass in the MAT decoder, which does not enforce configured temporary file size limits when reading highly compressed …

imagemagick | Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.9 MEDIUM
CVE-2026-105825 — ImageMagick before 7.1.2-30 Denial of Service via Crafted XMP Profile

ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a denial of service vulnerability in its handling of XMP profiles, where a crafted profile terminates the process instead of raising an e…

imagemagick | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.2 HIGH
CVE-2026-105824 — ImageMagick before 7.1.2-30 Use-After-Free in RSVG Decoder Without Cairo

ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, triggered when a limit is hit during decoding. Attac…

imagemagick | Remote | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.0 MEDIUM
CVE-2026-105823 — ImageMagick before 7.1.2-31 Policy Bypass in CUT Encoder

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy check in the CUT encoder, allowing configured security policies to be bypassed. Attackers can supply crafted input process…

imagemagick | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.2 HIGH
CVE-2026-105405 — ImageMagick before 7.1.2-31 Invalid Memory Free in MVG Decoder

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains an invalid memory free vulnerability in the MVG decoder. Attackers can supply a crafted MVG image for processing to trigger the invalid f…

imagemagick | Remote | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.0 MEDIUM
CVE-2026-105404 — ImageMagick before 7.1.2-31 Code Injection via PostScript Coders

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains a code injection vulnerability in its PostScript coders, because some values are not properly escaped or trimmed when written to output. …

imagemagick | Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.9 MEDIUM
CVE-2026-105403 — ImageMagick before 7.1.2-31 Security Policy Bypass via Coder Domain

ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 allows a security policy bypass when a policy uses coder, rather than module, as its domain. An attacker can supply a crafted image to evade coder…

imagemagick | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.9 MEDIUM
CVE-2026-105402 — ImageMagick before 7.1.2-31 Denial of Service via XMP Profile Parsing

ImageMagick before 7.1.2-31 contains a denial of service vulnerability that allows attackers to disrupt processing by supplying a crafted XMP profile. Attackers can embed a malicious XMP profile that…

imagemagick | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.0 MEDIUM
CVE-2026-105401 — ImageMagick before 7.1.2-31 Heap Buffer Overflow in Distributed Pixel Cache Server

ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in the distributed pixel cache server that allows connecting clients to overwrite heap memory by sending crafted data. Attack…

imagemagick | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 14559 Results