Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-86073 — n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind it…

| Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.6 CRITICAL
CVE-2026-82533 — DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers to gain full agent control by supplying a spoofed Host …

Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.9 MEDIUM
CVE-2026-81531 — Unauthenticated Account Information Disclosure in Multiple Omada Controllers

An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-r…

omada_software_controller oc200 oc220 oc300 oc400 | Remote | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-75156 — Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated —…

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is …

| Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-86668 — aircheng-org iWebShop-5 pic.php uploadFile cross site scripting

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument ou…

| Cross-Site Scripting
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.0 MEDIUM
CVE-2026-78216 — AshLua eval read operations can read field-policy-protected fields via aggregates

AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named fi…

ash_lua | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
2.5 LOW
CVE-2026-84392 — Fortinet FortiOS, FortiPAM, and FortiProxy NULL Pointer Dereference Vulnerability

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, …

fortios fortiproxy fortios fortipam | Remote | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.7 MEDIUM
CVE-2026-22575 — Fortinet FortiManager Improper Access Control Vulnerability

An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiM…

Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.9 MEDIUM
CVE-2026-84391 — Fortinet FortiAnalyzer Uninitialized Variable Vulnerability

A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>

fortianalyzer fortianalyzer fortianalyzer | Remote | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.3 HIGH
CVE-2026-84393 — Fortinet FortiOS and FortiProxy Certificate Validation Vulnerability

A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert …

fortios fortiproxy fortios | Remote | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.9 HIGH
CVE-2026-26084 — Fortinet FortiSandbox Improper Access Control Vulnerability

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 m…

Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.9 MEDIUM
CVE-2026-84385 — Fortinet FortiSOAR Privilege Escalation Vulnerability

A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.0 MEDIUM
CVE-2026-78230 — AshAi aggregate tool can read field-policy-protected fields

AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and retur…

ash_ai | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
2.8 LOW
CVE-2026-84389 — Fortinet FortiSIEM Open Redirect Vulnerability

A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or command…

fortisiem | Remote | Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.7 MEDIUM
CVE-2026-84387 — Fortinet FortiSandbox Command Injection Vulnerability

A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 …

fortisandbox fortisandbox | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.7 MEDIUM
CVE-2026-84386 — Fortinet FortiClient Windows Improper Access Control Vulnerability

A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector he…

forticlientwindows | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-86667 — aircheng-org iWebShop-5 member.php member_list sql injection

A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of the argument Search cau…

| Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-86853 — Repeated external URL scheme launches could potentially cause a denial of service in Fire…

A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is clos…

Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-86840 — Bifrost Unauthorized Channel Commission Attribution Allows Commission Diversion

The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` …

| Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.3 CRITICAL
CVE-2026-86738 — Snipe-IT before 8.7.0 CSS Injection via Custom CSS

Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Su…

Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
Showing 20 of 12673 Results