Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-81176 — Svelte devalue: DoS via malformed input

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. Prior to 5.9.2, devalue.parse does not reject out-of-bounds indices that a…

| Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.8 HIGH
CVE-2026-92729 — SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints

SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions …

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
0.0 NA
CVE-2026-75516 — RabbitMQ Java client: Frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats fra…

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySi…

| Memory Corruption
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
0.0 NA
CVE-2026-46352 — Suricata defrag: fragmented encapsulated traffic with fragments can lead to deadlock

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, Suricata's IP defragmentati…

suricata | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
4.7 MEDIUM
CVE-2026-75025 — Mattermost Desktop local network access from server-rendered content

Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks t…

Remote | Server-Side Request Forgery
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.3 CRITICAL
CVE-2026-92720 — Kubero through 3.1.1 Unauthenticated Notifications API Access

Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs. Attackers can retrieve store…

Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.7 HIGH
CVE-2026-92719 — Quickwit through 0.9.0 SSRF via SQS queue_url Parameter

Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. Attack…

Remote | Server-Side Request Forgery
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.3 HIGH
CVE-2026-92718 — Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cache

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious co…

nuclei | Supply Chain
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.3 CRITICAL
CVE-2026-92717 — Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can …

covenant | Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.6 CRITICAL
CVE-2026-92716 — Shuffle through 2.2.1 API Key Reset Cross-Tenant Privilege Escalation

Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users i…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-92605 — IRIS through 2.4.29 Unauthorized Comment Access via Object ID

IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumera…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.1 HIGH
CVE-2026-92604 — Scirius through 3.8.0 Arbitrary File Write via PCAP Upload

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem …

Remote | Path Traversal
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.3 MEDIUM
CVE-2026-92416 — Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request ass…

A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component PFCP Session Repor…

Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.0 MEDIUM
CVE-2026-92413 — Artifex MuPDF PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dereference

A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xre…

mupdf | Remote | Memory Corruption
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.5 HIGH
CVE-2026-92406 — SourceCodester Inventory and Monitoring System btn_functions.php add sql injection

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. …

Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
0.0 NA
CVE-2026-88593 — kkFileView Reflected Cross-Site Scripting

kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates…

| Cross-Site Scripting
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
2.0 LOW
CVE-2026-85387 — Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST AP…

Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authoriza…

Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.4 MEDIUM
CVE-2026-84397 — Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Ma…

experience_manager | Remote | Cross-Site Scripting
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
6.5 MEDIUM
CVE-2026-69147 — vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, an…

vllm | Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
0.0 NA
CVE-2026-51990 — Sogou Input Method Remote Code Execution Vulnerability

An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

| Memory Corruption
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
Showing 20 of 14716 Results