Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-107166 — Open5GS GTP-U Receive Path gtp-path.c ogs_pfcp_xact_local_create allocation of resources

A weakness has been identified in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pfcp_xact_local_create of the file src/upf/gtp-path.c of the component GTP-U Receive Path. This mani…

| Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-107210 — ImageMagick: Policy Bypass in MAT decoder when reading highly compressed data

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted highly compressed MAT image can make the MAT decoder create t…

Remote | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.9 MEDIUM
CVE-2026-107209 — ImageMagick: Use-After-Free in RSVG decoder that is build without cairo support

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image t…

Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-107208 — ImageMagick: Denial of service with crafted XMP profile

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a recursion limit that is handled as a …

Remote | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.0 MEDIUM
CVE-2026-106580 — ImageMagick: Policy Bypass in CUT encoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing security-policy check in the CUT encoder allows a crafted loc…

| Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.9 MEDIUM
CVE-2026-92415 — Apache Jackrabbit: DavEx client runs Class.forName + (String)-constructor on server-contr…

— Use of Externally-Controlled Input to Select Classes or Code vulnerability in Apache Jackrabbit's WebDAV/Davex client. A malicious WebDAV/DavEx server, or an attacker able to intercept the connect…

jackrabbit | Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
9.3 CRITICAL
CVE-2026-92414 — Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens

: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/…

jackrabbit | Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.2 MEDIUM
CVE-2026-106579 — ImageMagick: Policy Bypass when using coder as the domain.

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can bypass an ImageMagick security policy that uses cod…

| Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.3 MEDIUM
CVE-2026-107273 — Gophish 0.11.0 through 0.12.1 SSRF via POST /api/import/site

Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attack…

Remote | Server-Side Request Forgery
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
4.7 MEDIUM
CVE-2026-107272 — Gophish through 0.12.1 XSS via Unescaped SMTP Server Error Messages

Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages. Attackers controllin…

Remote | Cross-Site Scripting
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-107271 — Gophish through 0.12.1 Login Rate Limit Bypass via X-Forwarded-For Spoofing

Gophish through 0.12.1 contains a rate limit bypass vulnerability that allows unauthenticated attackers to evade /login throttling by spoofing X-Forwarded-For or X-Real-IP headers. Attackers can send…

Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
7.1 HIGH
CVE-2026-107270 — Gophish through 0.12.1 Object Takeover via Client-Supplied ID on API Create Endpoints

Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Atta…

Remote | Authorization
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-107278 — MISP Object Sync Drops Objects and Attributes When Description Is Empty

MISP contains a validation flaw in its object synchronization logic. When a MISP Object is created without a description, it is stored correctly on the originating instance. However, when that object…

Remote | Misconfiguration
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.9 MEDIUM
CVE-2026-106578 — ImageMagick: Invalid Memory Free in MVG decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and…

imagemagick | Remote | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
3.7 LOW
CVE-2026-107269 — Gophish through 0.12.1 Username Enumeration via POST /login Timing Discrepancy

Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times. Attackers…

gophish | Remote | Authentication
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-106577 — ImageMagick: Code Injection in the postscript coders

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code into output generated by …

imagemagick | Remote | Injection
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-106576 — ImageMagick: Denial of service possible when parsing an XMP profile.

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted XMP profile can trigger excessive work while the parser determines a ration…

imagemagick | Remote | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
6.3 MEDIUM
CVE-2026-107276 — MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Multiple Concurr…

MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate…

misp | Remote | Race Condition
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-106575 — ImageMagick: Unclosed file pointer in magick script

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted Magick script can cause an opened file pointer to remain unclosed, allowing…

imagemagick | Remote | Denial of Service
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
5.3 MEDIUM
CVE-2026-106574 — ImageMagick: Heap Buffer Over-Write in distributed pixel cache server will result in a cr…

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a client connected to the distributed pixel cache server can send crafted pixel data …

imagemagick | Memory Corruption
Oct 07, 2026 Oct 07, 2026
Oct 07, 2026
Oct 07, 2026
Showing 20 of 15451 Results