Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.4 MEDIUM
CVE-2026-25684 — File Type Control rule bypass

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

Remote | Misconfiguration
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.3 MEDIUM
CVE-2026-93492 — Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size

A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93491 — Io.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.…

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This actio…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93488 — Io.netty/netty-codec-http: netty: denial of service via unbounded concurrent spdy streams

A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides …

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.8 MEDIUM
CVE-2026-28199 — Sensitive File Disclosure via Relative Path Traversal in NetBackup Flex OS Shell

An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagn…

| Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.4 CRITICAL
CVE-2026-28198 — Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS…

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a…

Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.4 CRITICAL
CVE-2026-28197 — Privilege Escalation via Argument Injection in NetBackup Flex OS Shell

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbi…

Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
3.1 LOW
CVE-2026-21806 — HCL BigFix Service Management was affected with Admin Session Concurrency vulnerability (…

HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative accou…

Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.9 MEDIUM
CVE-2026-93578 — Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp cl…

Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass

build_of_apache_camel_for_spring_boot | Remote | Cryptography
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93575 — Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder

### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder checks if the MQTT packet's `Remaining Length` exceeds `maxBytesInMessage`, but fails to validate the `Properties Length` agains…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93572 — Io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers multiply patc…

## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis resource-exhaustion advisories. The limits are independent, but the allocator re…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93563 — Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtprespo…

Unbounded multi-line response accumulation in SmtpResponseDecoder leads to memory-exhaustion DoS

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.5 MEDIUM
CVE-2026-93561 — Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch…

Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.7 MEDIUM
CVE-2026-81627 — Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smr…

A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.1 MEDIUM
CVE-2026-92976 — Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0

A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. An authenticated user could inject malicious HTML or JavaScript content into the…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.4 MEDIUM
CVE-2026-90884 — WP Recipe Maker <= 10.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via …

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 due to insufficient input sanitization and…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.2 HIGH
CVE-2026-87915 — Popup Maker <= 1.24.0 - Unauthenticated Stored Cross-Site Scripting via values[Name] Para…

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all …

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-87743 — Quarkus-vertx-http: authorization bypass via path normalization discrepancy in quarkus ht…

A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.2 HIGH
CVE-2026-18405 — Jeg Kit for Elementor <= 3.2.16 - Unauthenticated Stored Cross-Site Scripting via Comment…

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up t…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.4 MEDIUM
CVE-2026-15797 — Popup Maker <= 1.24.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post…

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up …

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
Showing 20 of 14435 Results