Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-91846 — MISP Collection Element Add Missing Authorization on Referenced Object UUID

Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit expl…

Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-91780 — GNU Binutils elflink.c elf_link_add_object_symbols null pointer dereference

A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. Th…

binutils | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.3 HIGH
CVE-2026-75092 — Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysql…

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --…

Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.9 MEDIUM
CVE-2026-91819 — MISP: HTTP Method Override Bypasses CSRF and Form Validation in BetterSecurityComponent

Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override hea…

Remote | Cross-Site Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.2 HIGH
CVE-2026-91778 — Octopus Server Arbitrary Script Execution Vulnerability

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission vali…

Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.0 MEDIUM
CVE-2026-91091 — GPAC Node Insertion base_scenegraph.c gf_node_list_insert_child memory corruption

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such ma…

Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
3.9 LOW
CVE-2026-91090 — GPAC base_scenegraph.c gf_node_activate_ex stack-based overflow

A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer o…

| Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-91089 — GPAC base_scenegraph.c gf_node_get_name_and_id use after free

A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible…

Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-91779 — GNU Binutils Eh Frame elf-eh-frame.c _bfd_elf_eh_frame_section_offset null pointer derefe…

A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a man…

binutils | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.1 HIGH
CVE-2026-91825 — MISP: Missing Authorization Check for Event Sharing Group When Distribution Field Is Omit…

Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the …

Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
4.8 MEDIUM
CVE-2026-91088 — GPAC URL url.c gf_url_concatenate_ex heap-based overflow

A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based…

| Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-91087 — GPAC Compositor media_object.c gf_mo_get_od_id use after free

A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can l…

Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-91086 — GPAC MPEG Video Reframer reframe_mpgvid.c mpgviddmx_process heap-based overflow

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. …

Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.5 MEDIUM
CVE-2026-91005 — SourceCodester Online Faculty Clearance System Profile Picture Upload edit_picture.php mo…

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture …

Remote | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.1 CRITICAL
CVE-2026-90711 — proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet writ…

| Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.5 MEDIUM
CVE-2026-89141 — AI Engine <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sens…

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' para…

Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-75983 — Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.23 - Authen…

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the …

Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.4 MEDIUM
CVE-2026-18063 — Job Postings <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pos…

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitizati…

Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.4 MEDIUM
CVE-2026-15402 — Eventin <= 4.1.23 - Authenticated (Custom+) Stored Cross-Site Scripting via 'etn_shedule_…

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter …

Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-91004 — SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument I…

Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
Showing 20 of 12960 Results