Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.7 HIGH
CVE-2026-75608 — Frigate: Viewer-Role User Can Access go2rtc Internal API to obtain sensitive information

Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does n…

frigate | Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.1 HIGH
CVE-2026-75607 — Frigate: WebSocket Missing Authorization — Viewer Can Execute Admin-Only Operations

Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards attacker-selected message topics to the dispatcher without checking the authen…

frigate | Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.5 MEDIUM
CVE-2026-75517 — Novu: Cross-Environment Integration Manipulation (IDOR)

Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use cases including remove-integration, update-integration, auto-configure-integra…

novu | Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.3 MEDIUM
CVE-2026-75511 — Novu: Server-Side Request Forgery (SSRF) via Chat Provider Webhook URLs

Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat webhook URLs from subscriber credentials.webhookUrl, channel endpoint endpoint.url, event …

novu | Remote | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.1 MEDIUM
CVE-2026-75510 — Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme

Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification call-to-action redire…

novu | Remote | Cross-Site Scripting
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-70410 — Apache Calcite Avatica: Unrestricted class initialization when instantiating plugins

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica. Plugin instantiation (via AvaticaUtils#instantiatePlugin and other methods)…

apache_calcite_avatica | Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.3 CRITICAL
CVE-2026-63374 — AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized…

Remote | Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.3 HIGH
CVE-2026-56681 — 9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header

9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the client-supplied X-9r-Real-Ip …

Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.9 MEDIUM
CVE-2026-95754 — MISP: Disabled-user check ineffective in pre-authentication TOTP login branch

In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELEC…

misp | Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.1 MEDIUM
CVE-2026-95703 — MISP OrganisationsController File Existence and Image-Type Oracle via Forged Upload tmp_n…

In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the …

misp | Remote | Information Disclosure
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.1 MEDIUM
CVE-2026-95701 — MISP Path Traversal via Organization Name in Org-Statistics Logo Check

In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization logo image. The orig…

misp | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.3 MEDIUM
CVE-2026-95698 — MISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization Name

The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with a fixed image directory and a file extension, then calls file…

misp | Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.3 MEDIUM
CVE-2026-95697 — MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization M…

MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata fields without…

misp | Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.3 MEDIUM
CVE-2026-95693 — MISP Information Disclosure via Forged Upload Path

In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying…

misp | Remote | Information Disclosure
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.3 MEDIUM
CVE-2026-95685 — MISP Missing Authorization on replaceSuggestionInReport Event Report Action

MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content within an event report, was incorrectly m…

misp | Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.3 MEDIUM
CVE-2026-95683 — MISP Overmind Event View Discloses Report Content Bypassing Report-Level ACL

In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched the report using only the event ID as the lookup condition, …

misp | Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.8 MEDIUM
CVE-2026-95501 — mtrano APENCMS Template weasel.php eval code injection

A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the function eval of the file cms/weasel.php of the component Template Engine. The …

apencms | Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.5 HIGH
CVE-2026-95500 — JosephChuks php-file-manager-with-code-editor Save codeEditor.php file_put_contents unres…

A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The man…

php-file-manager-with-code-editor | Remote | Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.9 MEDIUM
CVE-2026-94570 — CVE-2026-94570

SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker with network reachab…

sglang | Remote | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.8 CRITICAL
CVE-2026-94127 — BIG-IP APM OAuth vulnerability

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unaut…

Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
Showing 20 of 14057 Results