Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-88047 — Tesseract: ReadNormProtos stack buffer overflow

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istrea…

| Memory Corruption
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-88046 — rclone: source object names can escape the configured root on upload

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.R…

rclone | Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-88045 — rclone: S3 multipart declared-length memory exhaustion

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.…

rclone | Remote | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.1 CRITICAL
CVE-2026-88044 — rclone: RC per-server auth-proxy bypass

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthPr…

rclone | Remote | Misconfiguration
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.1 CRITICAL
CVE-2026-85228 — Integer overflow in tensor buffer validation in Deep Java Library

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain inform…

Remote | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-73699 — FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()

FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perm…

filerun | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-73698 — FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the…

filerun | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-73694 — FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition

FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-contro…

filerun | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.8 HIGH
CVE-2026-73693 — FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler

FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading…

filerun | Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.9 CRITICAL
CVE-2026-68488 — Plesk Time-of-Check Time-of-Use Privilege Escalation

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

Remote | Race Condition
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.9 CRITICAL
CVE-2026-68487 — Plesk Backup Manager Path Traversal Arbitrary File Write

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.5 CRITICAL
CVE-2026-65639 — ConfigServer Security & Firewall OS Command Injection Vulnerability

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to i…

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.2 CRITICAL
CVE-2026-65638 — ConfigServer Security & Firewall Shell Command Injection Vulnerability

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection.…

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.8 CRITICAL
CVE-2026-52098 — Flowise Remote Code Execution

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.8 MEDIUM
CVE-2026-52097 — AppFlowy Remote Code Execution Vulnerability

An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) compon…

| Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.8 HIGH
CVE-2026-88959 — Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Ma…

Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify exist…

anchor_cms | Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.9 MEDIUM
CVE-2026-88940 — knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can t…

Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.7 HIGH
CVE-2026-88939 — knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoin…

Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.1 HIGH
CVE-2026-88938 — knowns through 0.33.0 Path Traversal via code.find MCP tool

knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply abso…

Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.8 HIGH
CVE-2026-88937 — knowns through 0.33.0 Path Traversal via Template Engine

knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Atta…

Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Showing 20 of 13418 Results