Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-88790 — proma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath path traver…

A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath of the file apps/electron/src/main/lib/file-preview-service.ts of the component …

| Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.7 HIGH
CVE-2026-75584 — ION-DTN < 4.2.1-a.1 Denial of Service via canonicalizePayloadBlock() Assertion

ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The cano…

Remote | Denial of Service
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.7 HIGH
CVE-2026-64838 — ICEcoder through 8.1 Path Traversal via oldFileName Parameter

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. At…

Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.8 HIGH
CVE-2026-64837 — ICEcoder through 8.1 OS Command Injection via lib/properties.php

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create d…

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.8 HIGH
CVE-2026-64836 — ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function co…

Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.4 MEDIUM
CVE-2026-12682 — Stored XSS in Ankaref's LIBRID/LIBREF

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRI…

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.1 MEDIUM
CVE-2026-88921 — MISP: Unescaped HTML Injection in PDF Report Element Rendering

MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTM…

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-6285 — Improper Authentication in Ankaref's LIBRID/LIBREF

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF:…

Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
8.6 HIGH
CVE-2026-85217 — Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop

A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow…

fusion | Misconfiguration
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
0.0 NA
CVE-2026-45763 — Suricata lua: sandbox allocation limit not enforced for new allocations

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5,when Lua rule execution is e…

suricata | Misconfiguration
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.4 MEDIUM
CVE-2026-12683 — Stored XSS Yönetim panel in Ankaref's LIBRID/LIBREF

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRI…

Remote | Cross-Site Scripting
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-9166 — LFI in GIS Informatics' GisLab Laboratory Management System

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab L…

Remote | Path Traversal
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
9.8 CRITICAL
CVE-2026-9163 — SQLi in GIS Informatics' GisLab Laboratory Management System

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects Gis…

Remote | Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.3 MEDIUM
CVE-2026-9161 — User Enumeration in DernekPlus' Website Template

Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early …

Remote | Information Disclosure
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
4.8 MEDIUM
CVE-2026-88038 — cookies vulnerable to Set-Cookie attribute injection via unvalidated domain and path opti…

cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that re…

| Injection
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
7.1 HIGH
CVE-2026-85545 — HikCentral Access Control Authorization Bypass

There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.

Remote | Authorization
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
5.2 MEDIUM
CVE-2026-85544 — Hikvision Intercom Improper Encryption Configuration Vulnerability

There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products. This could allow attackers to forge M1 cards.

| Cryptography
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
4.3 MEDIUM
CVE-2026-85543 — Wi-Fi Camera Unauthorized Information Disclosure

Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through t…

Remote | Information Disclosure
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.9 MEDIUM
CVE-2026-17038 — Use of Hard-coded Credentials in drEryk Gabinet

DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacke…

gabinet | Remote | Authentication
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
6.9 MEDIUM
CVE-2026-88896 — EspoCRM before 10.0.4 SSRF via IPv6 Transition Address Bypass

EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::fff…

Remote | Server-Side Request Forgery
Sep 10, 2026 Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Showing 20 of 13938 Results