Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-86220 — SourceCodester Class and Exam Timetabling System modal_add_course.php mysqli_query sql in…

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of th…

class_and_exam_timetabling_system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-86219 — Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentica…

Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the …

| Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-82209 — domain-scoped PSL domain cookie

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host tha…

curl | Misconfiguration
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-82208 — wolfSSL CA-cache hit overrides callback

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A…

curl | Misconfiguration
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-80255 — secure cookie attribute bypass with tab

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The…

curl | Misconfiguration
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-80231 — native CA store conn reuse

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection …

curl | Misconfiguration
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-80230 — OpenSSL pinning bypass

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public…

curl | Misconfiguration
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-80229 — OpenSSL provider use-after-free

When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library…

curl | Memory Corruption
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-19931 — Negotiate ambient user conn reuse

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's…

curl | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-18924 — HTTP/2 server push UAF

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

curl | Memory Corruption
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-13608 — OpenLDAP SASL authentication bypass

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-…

curl | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
0.0 NA
CVE-2026-86221 — SourceCodester Class and Exam Timetabling System modal_add_course1.php mysqli_query sql i…

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the arg…

Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
8.3 HIGH
CVE-2026-82751 — Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and spon…

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have t…

mpp | Remote | Misconfiguration
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
8.3 HIGH
CVE-2026-82750 — Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cos…

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have t…

mpp | Remote | Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.4 MEDIUM
CVE-2026-83534 — PostgreSQL Anonymizer: Privilege escalation to superuser via anon.anonymize_database_para…

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed i…

Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.4 MEDIUM
CVE-2026-19634 — PostgreSQL Anonymizer: SQL injection in import_database_rules() and import_roles_rules() …

PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequentl…

Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
8.8 HIGH
CVE-2026-19633 — PostgreSQL Anonymizer: unprivileged masked users can execute code via operators, domain c…

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions.…

Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.1 HIGH
CVE-2026-86283 — MISP UiBeta Collection View Bypasses Event ACL, Exposing Unauthorized Event Data

MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The Col…

misp | Remote | Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.5 MEDIUM
CVE-2026-86217 — code-projects Hotel and Tourism Reservation in PHP Database Backup hotel_db%20(1).sql inf…

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. Th…

hotel_and_tourism_reservation_in_php | Remote | Information Disclosure
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.0 MEDIUM
CVE-2026-86216 — code-projects Hotel and Tourism Reservation in PHP details.php cross site scripting

A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument ro…

hotel_and_tourism_reservation_in_php | Remote | Cross-Site Scripting
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
Showing 20 of 12354 Results