Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-96260 — Mattermost server missing request body size limit on plugin routes allows denial of servi…

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authe…

mattermost_desktop | Remote | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.5 MEDIUM
CVE-2026-96259 — Mattermost server-side request forgery via OAuth endpoints configurable by a System Admin…

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administra…

mattermost_desktop | Remote | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.2 HIGH
CVE-2026-95815 — OpenClaw iOS before 2026.8.11 Credential Exposure via Deep-Link URL Logging

OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrot…

openclaw | Information Disclosure
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.6 HIGH
CVE-2026-95814 — Vaultwarden through 1.37.3 Authorization Bypass via Missing Status Check

Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, …

vaultwarden | Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.1 MEDIUM
CVE-2026-95813 — e621ng before 26.09.16 Open Redirect via URL Parameters

e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and controller navigation links, allowing attackers to redirect pagination and naviga…

Remote | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.1 MEDIUM
CVE-2026-95812 — ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters

ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. Attackers can c…

clipbucket | Remote | Cross-Site Scripting
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.7 HIGH
CVE-2026-94450 — Potential denial of service when configured to send Retry packets in s2n-quic

Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via…

s2n-quic | Remote | Denial of Service
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.8 HIGH
CVE-2026-91018 — Double Free in lwIP (lightweight IP)

lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

| Memory Corruption
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.1 MEDIUM
CVE-2026-88020 — Improper Neutralization of Input During Web Page Generation in OpenPLC Runtime v3

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string pa…

Remote | Cross-Site Scripting
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
9.3 CRITICAL
CVE-2026-77987 — GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did …

enterprise_server | Remote | Server-Side Request Forgery
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.4 HIGH
CVE-2026-77912 — Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attrib…

A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because …

enterprise_server | Remote | Cross-Site Scripting
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
7.1 HIGH
CVE-2026-77426 — Unleash: Missing await on permission check + cross-project IDOR in admin API

Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/admin/segments/strategies assigns the Promise retur…

Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
4.3 MEDIUM
CVE-2026-77425 — Unleash: A project member can reorder activation strategies belonging to any other projec…

Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-co…

Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
5.3 MEDIUM
CVE-2026-76910 — Unleash: Clone-feature lets a user copy a feature from a project they cannot read

Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:projectId/features/:featureName/clone authorize creation in the destination pro…

Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
2.1 LOW
CVE-2026-76909 — Unleash: CR-approval email renders user-controlled raw HTML

Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache render…

Remote | Cross-Site Scripting
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
6.0 MEDIUM
CVE-2026-75101 — Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private…

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private reposito…

enterprise_server | Remote | Authorization
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
8.8 HIGH
CVE-2026-67615 — openEQUELLA < 2026.1.0 Authenticated RCE via Java Deserialization in HTTP Invoker

openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbitrary code by exploiting Java deserialization in …

Remote | Injection
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
2.3 LOW
CVE-2026-62364 — wlc may disclose API tokens to project-configured URLs

wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unsco…

wlc | Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-94574 — CVE-2026-94574

A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged use…

| Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
0.0 NA
CVE-2026-89282 — CVE-2026-89282

The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits w…

| Misconfiguration
Sep 22, 2026 Sep 22, 2026
Sep 22, 2026
Sep 22, 2026
Showing 20 of 14201 Results