Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-94640 — Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticate…

A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records …

Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-70410 — Apache Calcite Avatica: Unrestricted class initialization when instantiating plugins

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica. Plugin instantiation (via AvaticaUtils#instantiatePlugin and other methods)…

| Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-88010 — Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enume…

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.go constructs the BasicAuth singleflight key from the submit…

| Information Disclosure
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-75608 — Frigate: Viewer-Role User Can Access go2rtc Internal API to obtain sensitive information

Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does n…

| Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-75607 — Frigate: WebSocket Missing Authorization — Viewer Can Execute Admin-Only Operations

Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards attacker-selected message topics to the dispatcher without checking the authen…

| Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-77637 — Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-On…

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in routers/router.go inherit ScopeAdminRead but omit the RequiredScopes(types.Sc…

| Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-77633 — Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of serv…

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapa…

| Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-79913 — Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IP…

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP w…

| Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.6 HIGH
CVE-2026-95655 — Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel

Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to…

Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.1 CRITICAL
CVE-2026-95654 — Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token

Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a l…

Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.7 HIGH
CVE-2026-95653 — Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token

Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enu…

Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.4 CRITICAL
CVE-2026-80156 — Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validat…

Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management …

Remote | Path Traversal
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
10.0 CRITICAL
CVE-2026-80155 — Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprin…

Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web man…

Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.6 CRITICAL
CVE-2026-80154 — Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass

All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated atta…

Remote | Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.4 CRITICAL
CVE-2026-80152 — Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule

Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authent…

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-92706 — Dark Reader: Ability to request icon-like bitmap data from certain local web servers

Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can cause the browser extension's image inversion pipeline to request an unauthenticate…

| Information Disclosure
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.4 CRITICAL
CVE-2026-80151 — Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download

Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authent…

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.7 HIGH
CVE-2026-80150 — Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter

Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet l…

Remote | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.6 HIGH
CVE-2026-80149 — Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter

Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet l…

Remote | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.6 HIGH
CVE-2026-80148 — Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation

Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet l…

Remote | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
Showing 20 of 13950 Results