Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-94194 — Mint HTTP/1 client applies chunked framing when chunked is not the final transfer coding,…

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint clien…

mint | Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.3 MEDIUM
CVE-2026-92103 — Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max_frame_size

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should r…

mint | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.2 HIGH
CVE-2026-91043 — HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_size and exha…

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause a denial of service. Mint.HTTP2…

mint | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.1 MEDIUM
CVE-2026-87752 — HTML Injection in Rolantis Information Technologies' Agentis

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targetin…

Remote | Cross-Site Scripting
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.8 HIGH
CVE-2026-78424 — OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution …

Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key …

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-19444 — Kubernetes kubectl cp path traversal on Windows allows arbitrary file writes

A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a t…

| Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.8 HIGH
CVE-2026-12264 — Authenticated File Write via HA Failover Config Upload leads to RCE

Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.

Remote | Misconfiguration
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.5 MEDIUM
CVE-2026-101054 — Thinkware U3000 TCP Service wpa_supplicant.conf get_file access control

A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file /tmp/wpa_supplicant.conf of the component TCP Service. The manipulation leads to imprope…

Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-101053 — Thinkware U3000 TCP Service wpa_supplicant.conf PUT_FILE access control

A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa_supplicant.conf of the component TCP Service. Executing a manipulation of the …

Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-101052 — refly-ai refly JWT Token app.config.ts hard-coded credentials

A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component JWT Token H…

Remote | Information Disclosure
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
0.0 NA
CVE-2026-91006 — Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)

Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (…

karaf | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.4 CRITICAL
CVE-2026-81867 — Deserialization of Untrusted Data in Application Integration allows Remote Code Execution

A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user wit…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.3 HIGH
CVE-2026-81375 — Confused Deputy in Application Integration allows Internal File Read

A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and e…

Remote | Path Traversal
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.4 CRITICAL
CVE-2026-19759 — Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution

An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud u…

Remote | Authorization
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.8 HIGH
CVE-2026-12269 — Authenticated File Write to RCE via keepalived in DDI Central

Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-leve…

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
8.8 HIGH
CVE-2026-12268 — Authenticated PowerShell Injection leads to RCE

ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.2 HIGH
CVE-2026-12267 — Authenticated PowerShell Injection in DNS Query Resolution Policy leads to RCE

ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.

Remote | Injection
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.8 MEDIUM
CVE-2026-101040 — Ricoh SP 330DN/SP 221/SP C252SF/Aficio SP 3500SF HTTP Multipart Form-Data denial of servi…

A security flaw has been discovered in Ricoh SP 330DN, SP 221, SP C252SF and Aficio SP 3500SF up to 20260813. This affects an unknown part of the component HTTP Multipart Form-Data Parser. Performing…

sp_c252sf sp_330dn sp_221 aficio_sp_3500sf | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
10.0 CRITICAL
CVE-2026-101039 — FAST FAC1900R devdiscover Service copy_msg_element stack-based overflow

A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to stack-based bu…

fac1900r | Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.9 CRITICAL
CVE-2026-101038 — FAST FAC1200R MmtAtePrase stack-based overflow

A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-base…

Remote | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
Showing 20 of 14135 Results