Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-95683 — MISP Overmind Event View Discloses Report Content Bypassing Report-Level ACL

In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched the report using only the event ID as the lookup condition, …

misp | Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.8 MEDIUM
CVE-2026-95501 — mtrano APENCMS Template weasel.php eval code injection

A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the function eval of the file cms/weasel.php of the component Template Engine. The …

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.5 HIGH
CVE-2026-95500 — JosephChuks php-file-manager-with-code-editor Save codeEditor.php file_put_contents unres…

A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The man…

php-file-manager-with-code-editor | Remote | Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.9 MEDIUM
CVE-2026-94570 — CVE-2026-94570

SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker with network reachab…

sglang | Remote | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.8 CRITICAL
CVE-2026-94127 — BIG-IP APM OAuth vulnerability

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Impact: This vulnerability allows an unaut…

big-ip big-ip | Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.9 CRITICAL
CVE-2026-80143 — Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom read

Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authent…

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.1 HIGH
CVE-2026-93344 — MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level a…

Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-93088 — CVE-2026-93088

SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROU…

sglang | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.5 HIGH
CVE-2026-89407 — jackson-core: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumbe…

NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since …

jackson-core | Remote | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.6 CRITICAL
CVE-2026-84388 — Fortinet FortiPAM Chrome Extension UI Redressing Information Disclosure

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to informati…

fortipam_chrome_extension | Remote | Information Disclosure
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
4.7 MEDIUM
CVE-2026-79315 — x-ui Reflected Cross-Site Scripting

A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlig…

Remote | Cross-Site Scripting
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-79314 — x-ui Horizontal Privilege Escalation Vulnerability

A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, ena…

| Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-79313 — web.py Insufficient Session Expiration

webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a …

| Authentication
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.8 HIGH
CVE-2026-65179 — NVIDIA NeMo Insecure Deserialization Vulnerability

NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this…

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.8 HIGH
CVE-2026-65178 — NVIDIA NeMo Arbitrary Code Execution Vulnerability

NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may lead to…

| Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.0 HIGH
CVE-2026-65130 — NVIDIA Infrastructure Controller OS Command Injection Vulnerability

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data t…

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.7 MEDIUM
CVE-2026-65129 — NVIDIA Infrastructure Controller Improper Certificate Validation

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information…

| Cryptography
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.8 HIGH
CVE-2026-65128 — NVIDIA Infrastructure Controller SQL Injection Vulnerability

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tamperin…

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
4.1 MEDIUM
CVE-2026-65127 — NVIDIA Infrastructure Controller Information Disclosure Vulnerability

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful exploit of …

| Information Disclosure
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.0 MEDIUM
CVE-2026-65126 — NVIDIA Infrastructure Controller Improper Behavioral Workflow Enforcement

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead …

Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
Showing 20 of 13956 Results