Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-81945 — PLANET IGS-5225-8P2T4S V1/V2 Admin Stack-Based Buffer Overflow via Web Server

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bfore 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checkin…

Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.7 HIGH
CVE-2026-81944 — PLANET IGS-5225-8P2T4S V1/V2 Stack-Based Buffer Overflow via Web Server

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checki…

Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.4 HIGH
CVE-2026-81943 — PLANET IGS-5225-8P2T4S V1/V2 Debug Mode RCE

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with privi…

| Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.4 MEDIUM
CVE-2026-93685 — Multicluster-observability-addon: multicluster-observability-addon: possible unauthentica…

A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. Th…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
3.2 LOW
CVE-2026-93676 — Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/…

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals …

enterprise_linux enterprise_linux | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.1 HIGH
CVE-2026-93660 — SQLBot through 1.10.1 Improper Access Control via Dashboard Update

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers…

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.3 CRITICAL
CVE-2026-93659 — Concrete CMS Community Store before 2.7.8 Stored XSS

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.3 HIGH
CVE-2026-93658 — uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the pri…

coreutils | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-93657 — hickory-resolver before 0.26.2 DNSSEC Validation Bypass

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successfu…

Remote | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.5 MEDIUM
CVE-2026-93653 — Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidate…

A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an at…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93652 — Integer Overflow or Wraparound in µD3TN

Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93576 — Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-v…

Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.5 MEDIUM
CVE-2026-93573 — Io.netty/netty-codec-http: netty split transfer-encoding fields bypass final-chunked vali…

Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.2 HIGH
CVE-2026-93569 — Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :a…

HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93568 — Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended…

HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93567 — Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http…

HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.5 MEDIUM
CVE-2026-93566 — Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the…

### Summary Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size line containing an embedded bare CR (e.g. `0\rX`) is accepted instead of rejecte…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93565 — Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control …

### Summary `RtspMethods.valueOf()` silently strips trailing control bytes (any character with code point <= 0x20, the full range that `String.trim()` removes) before performing a cache lookup again…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93564 — Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf refer…

HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (incomplete fix of PR #16881)

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93558 — Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserve…

Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
Showing 20 of 14401 Results