Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-107325 — Application denial of service via missing BSON array length validation in MongoDB Go Driv…

Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bson.RawArray.Validate or bsoncore.Array.Validate on a…

go_driver | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.2 MEDIUM
CVE-2026-107388 — music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion…

music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the ID3v2 parser trusts the syncsafe tag-size field and allocates the complete tag body before checking whether …

music-metadata | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.5 HIGH
CVE-2026-84276 — IBM Guardium Data Protection Denial of Service

IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service…

guardium_data_protection | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.2 MEDIUM
CVE-2026-107387 — music-metadata: Uncontrolled memory allocation in APEv2 parser

music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the APEv2 parser reads an attacker-controlled tag-item size and allocates a Uint8Array for a binary item before …

music-metadata | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.2 HIGH
CVE-2026-84278 — IBM Guardium Data Protection Command Injection

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper component. An authenticated high-privileged user can inject arbitrary commands t…

guardium_data_protection | Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-107324 — Application denial of service via integer overflow in BSON value-length validation in Mon…

An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application validates or accesses a malformed BSON document. An unauthenticated actor who …

go_driver | Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.1 MEDIUM
CVE-2026-84290 — Security vulnerability affects the Windows S-TAP component as part of IBM Guardium Data P…

IBM Guardium Data Protection 12.0, 12.1, 12.2 is affected by an improper validation of user-supplied pointers in the WfpMonitor kernel driver. Certain METHOD_NEITHER IOCTL handlers dereference user-c…

guardium_data_protection | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.3 MEDIUM
CVE-2026-106434 — Unrecognized payload acceptance in explicit decryption in MongoDB libmongocrypt

The explicit decryption component of MongoDB libmongocrypt can return an unrecognized encrypted payload unchanged instead of returning a decryption error. An actor who can modify stored encrypted fie…

libmongocrypt | Remote | Cryptography
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.8 HIGH
CVE-2026-106433 — Heap corruption via duplicate masterKey fields in MongoDB libmongocrypt

Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An aut…

libmongocrypt | Remote | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-107386 — amqp091-go: Pre-negotiation frame limit is not enforced to 4KB

amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFra…

| Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-106429 — Application denial of service via malformed KMS endpoint in MongoDB libmongocrypt

An integer underflow in the KMS endpoint-parsing logic of MongoDB libmongocrypt can cause an allocation failure that terminates the application process. This can occur when an authenticated user modi…

libmongocrypt | Remote | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-105452 — Docker Sandboxes egress proxy could forward unrecognized client credentials to managed ho…

Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sent…

sandboxes docker_sandboxes | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.1 HIGH
CVE-2026-40804 — WordPress aBlocks plugin <= 2.16.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC aBlocks ablocks allows Reflected XSS.This issue affects aBlocks: from n/a through 2.1…

Remote | Cross-Site Scripting
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-101998 — Fail-open response masking in Docker Sandboxes can expose proxy-managed credentials

Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes…

sandboxes docker_sandboxes | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.7 MEDIUM
CVE-2026-105570 — Docker Sandboxes OAuth response masking could be bypassed with a case-variant token host

Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. U…

sandboxes docker_sandboxes | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-106430 — Query and rename target confusion via embedded NUL truncation in MongoDB C++ Driver

The MongoDB C++ Driver discards content after an embedded NUL byte in certain field and collection names accepted by the collection API. This can cause the driver and the calling application to inter…

c_driver c\+\+_driver | Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.0 MEDIUM
CVE-2026-106438 — Silent Decimal128 value corruption via incorrect exactness check in MongoDB C Driver

An incorrect calculation in Decimal128 string parsing in the MongoDB C Driver can accept certain over-precision inputs containing leading zeros instead of rejecting them. This produces a value differ…

c_driver | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.2 MEDIUM
CVE-2026-106437 — Out-of-bounds read and write via undersized BSON buffer reservation in MongoDB C Driver

The BSON buffer-reservation API in the MongoDB C Driver can record a length smaller than the five-byte BSON minimum. Later append or comparison operations can underflow unsigned length calculations a…

c_driver | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.7 MEDIUM
CVE-2026-106431 — One-byte heap buffer overflow in BSON bulk document writer in MongoDB C Driver

An off-by-one error in the BSON bulk document writer in the MongoDB C Driver can write one zero byte immediately past a heap allocation when a document ends at a specific buffer boundary. An actor wh…

c_driver | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.8 HIGH
CVE-2026-107322 — OS command injection in Amazon Agent Plugins for AWS databases-on-aws

An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands …

databases-on-aws | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 14541 Results