Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-103233 — AdithyaYelloju Restaurant-Management-System Admin Area admin authorization

A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the c…

Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-46711 — Soft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfil…

Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Mach…

| Path Traversal
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.1 CRITICAL
CVE-2026-75969 — PTZOptics Missing Authentication in Firmware Upload

Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware up…

Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-55177 — CloudTAK: Authenticated full-read SSRF in /api/esri* routes — user-controlled URL fetched…

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.10.0, every route in the ESRI helper family (api/routes/esri.ts) takes a f…

| Server-Side Request Forgery
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.1 LOW
CVE-2026-103444 — Stored XSS through system messages in WikiForum

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS. This issue affects MediaWiki …

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.4 CRITICAL
CVE-2026-102490 — Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

Remote | Authorization
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
9.4 CRITICAL
CVE-2026-102489 — Undisclosed RCE in Zammad v6.3 and higher

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.…

Remote | Authentication
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
1.1 LOW
CVE-2026-103443 — API permits session-seeded javascript URL XSS

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script Elements.…

Remote | Cross-Site Scripting
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
0.0 NA
CVE-2026-80490 — Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length…

Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING ty…

| Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.6 HIGH
CVE-2026-19553 — SSLContext.wrap_bio() missing validation of server_hostname parameter

ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname ar…

cpython cpython | Remote | Misconfiguration
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.9 MEDIUM
CVE-2026-55174 — UltrafastSecp256k1: ECDSA adaptor verification accepts non-adaptable pre-signatures due t…

UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp2…

Remote | Cryptography
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.5 MEDIUM
CVE-2026-47604 — NVIDIA GPU Display Driver Improper Authorization Vulnerability

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization check…

Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
5.5 MEDIUM
CVE-2026-47603 — NVIDIA GPU Display Driver Improper Authorization Vulnerability

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization check…

Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.1 HIGH
CVE-2026-47602 — NVIDIA GPU Display Driver Null Pointer Dereference

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user can cause the driver to dereference an untrusted pointer. A successful exploit of…

Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.8 HIGH
CVE-2026-47601 — NVIDIA GPU Display Driver DMA-BUF Improper Access Control Privilege Escalation

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of mem…

geforce tesla tesla geforce | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.8 HIGH
CVE-2026-47600 — NVIDIA GPU Display Driver Kernel Mode Improper Resource Initialization Vulnerability

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploi…

geforce tesla tesla geforce | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.8 HIGH
CVE-2026-47599 — NVIDIA GPU Display Driver Improper Memory Access Permission Handling

NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DM…

geforce tesla tesla geforce | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.0 HIGH
CVE-2026-47598 — NVIDIA GPU Display Driver Use-After-Free Vulnerability

NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module event delivery path where an unprivileged local user could cause a use-after-free through a race between …

Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.8 HIGH
CVE-2026-47597 — NVIDIA GPU Display Driver Use-After-Free Vulnerability

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module Resource Server where an unprivileged local user could cause a use-after-free through a missi…

geforce tesla tesla geforce | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
7.0 HIGH
CVE-2026-47596 — NVIDIA GPU Display Driver for Linux Memory Permission Improper Validation Vulnerability

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A su…

geforce tesla tesla geforce | Memory Corruption
Sep 30, 2026 Sep 30, 2026
Sep 30, 2026
Sep 30, 2026
Showing 20 of 14951 Results