Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-100889 — Trusted Domain Project OpenDKIM Decoder util.c dkim_qp_decode off-by-one

A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-o…

opendkim | Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-100888 — Trusted Domain Project OpenDKIM DKIM Signature Header Selection dkim-canon.c dkim_canon_s…

A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature He…

opendkim | Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-100887 — amirsanni Mini-Inventory-and-Sales-Management-System Database Query Builder DB_query_buil…

A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file D…

Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
2.5 LOW
CVE-2026-96284 — Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci sym…

A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when impor…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
10.0 CRITICAL
CVE-2026-100886 — Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication

A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads…

t8232 t8108 t8116 t8108p | Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.5 HIGH
CVE-2026-100885 — Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization

A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-se…

laravel-crm | Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
4.3 MEDIUM
CVE-2026-100884 — Krayin laravel-crm attachment-download Endpoint acl.php resource injection

A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachme…

laravel-crm | Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.5 MEDIUM
CVE-2026-100883 — Krayin laravel-crm acl.php access control

A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to imprope…

laravel-crm | Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.3 LOW
CVE-2026-96283 — Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongo…

By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to s…

enterprise_linux enterprise_linux | Denial of Service
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.1 LOW
CVE-2026-96282 — Flatpak: flatpak: extension metadata path traversal file existence oracle

A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications us…

enterprise_linux flatpak enterprise_linux | Remote | Path Traversal
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.3 LOW
CVE-2026-100882 — Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting

A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the compone…

laravel-crm | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
2.6 LOW
CVE-2026-100881 — zhistaredu StarTraining application.yml cross site scripting

A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enable…

startraining | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.2 MEDIUM
CVE-2026-96281 — Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system ap…

On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper Rem…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.5 HIGH
CVE-2026-96280 — Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent ope…

enterprise_linux flatpak enterprise_linux | Remote | Memory Corruption
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.8 CRITICAL
CVE-2026-101090 — Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oau…

Remote | Injection
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.1 LOW
CVE-2026-101089 — Nezha before 2.2.7 Information Disclosure via /api/v1/profile

Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract pas…

Remote | Information Disclosure
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.0 MEDIUM
CVE-2026-101088 — Nezha before 2.3.1 Denial of Service via Concurrent Server Delete

Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously report…

Remote | Denial of Service
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
5.3 MEDIUM
CVE-2026-101087 — Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6

Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges — specifically…

Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101086 — Nezha Dashboard before 2.3.5 Task Type Validation Bypass

Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types…

Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101085 — Nezha before 2.3.8 Denial of Service via Alert Rule

Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluat…

Remote | Denial of Service
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
Showing 20 of 14035 Results