Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-85640 — Privilege Escalation

Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component

Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.8 MEDIUM
CVE-2026-85201 — Eclipse Ankaios Agent Unbounded Memory Allocation Vulnerability

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workl…

| Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.8 MEDIUM
CVE-2026-82325 — OpenVPN ovpn-dco-win Use-After-Free Vulnerability

A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages

ovpn-dco-win | Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.0 MEDIUM
CVE-2026-77699 — Privilege Escalation

Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.

manageengine_endpoint_central | Misconfiguration
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.3 MEDIUM
CVE-2026-77697 — Privilege Escalation

Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction

manageengine_endpoint_central | Misconfiguration
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.7 HIGH
CVE-2026-19204 — Jetty WebSocket Memory Exhaustion Vulnerability

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory allocation and potentially exhaust the JVM heap. This …

jetty | Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
3.5 LOW
CVE-2025-52657 — HCL MyXalytics is affected by multiple security vulnerabilities.

HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system performance or availability.

Remote | Denial of Service
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
3.5 LOW
CVE-2025-52652 — HCL MyXalytics is affected by multiple security vulnerabilities.

HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a trusted source, potentially le…

Remote | Information Disclosure
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
3.5 LOW
CVE-2025-52651 — HCL MyXalytics is affected by multiple security vulnerabilities.

HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.

Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.1 HIGH
CVE-2026-86347 — MISP Missing Authorization on Template File Upload Allows Authenticated Disk Exhaustion

Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role …

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.5 MEDIUM
CVE-2026-86293 — SourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing au…

A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. E…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86292 — SourceCodester Simple Traffic Offense System User Creation saveuser.php missing authentic…

A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.5 MEDIUM
CVE-2026-86291 — itsourcecode Sales and Inventory System us_edit1.php sql injection

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/us_edit1.php. Such manipulation of the argument ID leads…

sales_and_inventory_system | Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.3 HIGH
CVE-2026-84173 — Eclipse Ankaios Control Interface Improper Authorization Vulnerability

In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated…

| Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.7 MEDIUM
CVE-2026-77698 — Privilege Escalation

Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.

Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.3 MEDIUM
CVE-2026-86342 — MISP Freetext Feed Preview Improper Authorization Exposes Restricted Event and Feed Infor…

Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying t…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
6.5 MEDIUM
CVE-2026-86332 — Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user

A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns th…

openshift_ai | Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86290 — SourceCodester Online Voting System ajax.php save_category sql injection

A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Catego…

online_voting_system | Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.0 MEDIUM
CVE-2026-86289 — Ollama GGUF Decoder gguf.go readGGUFV1String integer overflow

A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in inte…

Remote | Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86288 — ModelCloud GPTQModel Triton dequantization kernel tritonv2.py out-of-bounds

A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization…

Remote | Memory Corruption
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
Showing 20 of 12480 Results