Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-85396 — rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attack…

Remote | Path Traversal
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-85395 — UnoPim before 2.1.3 Missing Authorization on Integration Management Routes

UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges …

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.3 CRITICAL
CVE-2026-85394 — python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC Secret

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's pub…

Remote | Cryptography
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.7 HIGH
CVE-2026-85393 — node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Pad…

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorith…

forge | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-85392 — Peppermint through 0.5.5 Authorization Bypass on the User Logout Endpoint

Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessions for any user by supplyi…

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.8 CRITICAL
CVE-2026-85391 — Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml

Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published s…

Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-85390 — Checkmate through 3.11.0 Missing Authorization on Maintenance Window, Notification, and C…

Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attacker…

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-85389 — Worklenz before 3.0.0 Authorization Bypass on Task-Scoped Endpoints

Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data. Attackers can query t…

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.6 HIGH
CVE-2026-85388 — Worklenz through 3.0.0 SQL Injection via the sort-field Query Parameter

Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY …

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
0.0 NA
CVE-2026-33630 — c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely trigg…

c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while t…

| Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.1 HIGH
CVE-2026-82302 — Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modification

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

kibana | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-82299 — Incorrect Authorization in Kibana Leading to Information Disclosure

Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

kibana | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
4.3 MEDIUM
CVE-2026-82298 — Incorrect Authorization in Kibana Leading to Denial of Service

Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).

kibana | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
4.3 MEDIUM
CVE-2026-78596 — Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Operations

Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege Abuse (CAPEC-122).…

kibana | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
4.3 MEDIUM
CVE-2026-78595 — Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Data Disclosure

Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An …

kibana | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
4.3 MEDIUM
CVE-2026-78593 — Improper Control of Generation of Code in Kibana Leading to Privilege Escalation

An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a …

kibana | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.1 HIGH
CVE-2026-78583 — Incorrect Authorization in Kibana Leading to Privilege Escalation

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration package…

kibana | Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.3 HIGH
CVE-2026-15431 — HP Support Assistant – Potential Escalation of Privilege

A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escala…

support_assistant | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-85187 — itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate s…

A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=e…

online_medicine_delivery_system | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.5 HIGH
CVE-2026-85012 — OS command injection in the Amazon CodeCatalyst blueprints SDK

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with…

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Showing 20 of 12640 Results