Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-91132 — Discourse: Wildcard iframe origin allowlist bypass via authority separators

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildcard patterns in the allowed_iframes setting could accept a crafted iframe URL wh…

| Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-91122 — Discourse: Chat MessageBus delivers read-restricted messages to unauthorized users

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an…

| Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-56744 — `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient out…

`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and…

| Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-91123 — Discourse: Reject literal backslash path separators in iframe src traversal guard

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src traversal guard did not treat literal backslashes as path separators after decoded…

| Path Traversal
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-91133 — Discourse: Escape LIKE metacharacters in upload paths to prevent disclosure

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated users could supply unescaped SQL LIKE metacharacters to upload-resolution patterns,…

| Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-91134 — Discourse: Block post iframes whose encoded userinfo bypasses the allowed_iframes allowli…

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post sanitizer allowed a stored cross-origin iframe to bypass the allowed_iframes p…

| Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-84302 — Discourse: Non-participant moderators can read, edit, and delete PM content through Disco…

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review qu…

| Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-26054 — SumatraPDF: Heap out-of-bounds read in MOBI header parser.

SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp validates a record using kMobiHeaderMinLen but DecodeMobiDocHeader constructs a dec…

sumatrapdf | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-91161 — OpenWA: VIEWER API keys can read WhatsApp group invite codes

OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the GET /api/sessions/{sessionId}/groups/{groupId}/invite-code endpoint and the GroupGetInviteCode MCP tool have no O…

| Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-97231 — volotat Anagnorisis Socket.IO Connect app.py missing authentication

A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Interface. The manipulation results in missin…

| Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-91160 — OpenWA: A read-only API key can receive a session pairing QR over the WebSocket event str…

OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers the session.qr event to a VIEWER API key that subscribes by event name or thro…

| Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-62368 — Snipe-IT: Stored XSS via Custom Field name in asset-list column headers

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns t…

| Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-63493 — Snipe-IT: 2FA bypass via the API token flow

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before complet…

| Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-56738 — phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion

phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `INSERT` statement using `sprintf()` and inserts the user-supplied stop word value…

| Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-63498 — Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management acc…

| Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-94281 — Out-of-bounds read in libXi's XListInputDevices() class parsing

An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

libxi | Remote | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-94606 — authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient addr…

authentik | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-94609 — authentik: Privilege Escalation to Superuser via Group Hierarchy

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser statu…

authentik | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-93545 — Out-of-bounds read in libXi's XListInputDevices()

An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

libxi | Remote | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-94611 — authentik: Stored credentials are readable with view permission alone

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected config…

authentik | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
Showing 20 of 14560 Results