Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-86251 — h3 before 1.15.9 Path Traversal via Double Decoding

h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (e.g. %252e%252e) to …

h3 | Remote | Path Traversal
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
8.7 HIGH
CVE-2026-86250 — h3 before 2.0.1-rc.18 Denial of Service via Unbounded Chunked Cookie

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cooki…

h3 | Remote | Denial of Service
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
8.1 HIGH
CVE-2026-86242 — Unauthenticated RCE via Custom Plugin HTTP Path on Dynamically Linked Builds

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, gover…

Remote | Misconfiguration
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
4.3 MEDIUM
CVE-2026-86212 — Open5GS AMF/MME improper authorization

A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be…

open5gs | Remote | Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.4 MEDIUM
CVE-2026-86205 — h3 before 2.0.1-rc.18 Open Redirect via redirectBack()

h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers can craft …

h3 | Remote | Misconfiguration
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
8.7 HIGH
CVE-2022-51009 — PocketMine-MP before 4.7.2 Denial of Service via Skin Geometry

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry J…

Remote | Misconfiguration
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.9 MEDIUM
CVE-2022-51008 — PocketMine-MP before 4.12.3 Denial of Service via Unauthenticated Sessions

PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flood the server with u…

Remote | Denial of Service
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.1 HIGH
CVE-2021-48007 — PocketMine-MP before 3.18.1 Denial of Service via MovePlayerPacket

PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-poi…

Remote | Denial of Service
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
4.8 MEDIUM
CVE-2021-48006 — PocketMine-MP before 4.0.3 Operator Privilege Escalation via Case Sensitivity

PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly match…

| Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.1 HIGH
CVE-2020-37277 — PocketMine-MP before 3.15.4 Denial of Service via InventoryTransaction

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryT…

Remote | Denial of Service
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86211 — rabindralamsal inventory-management-system Login index.php sql injection

A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username…

inventory-management-system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86210 — SourceCodester Class and Exam Timetabling System delete_user_account.php sql injection

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Su…

class_and_exam_timetabling_system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86209 — SourceCodester Class and Exam Timetabling System delete_user.php sql injection

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql i…

class_and_exam_timetabling_system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
7.5 HIGH
CVE-2026-86208 — SourceCodester Class and Exam Timetabling System delete_teacher.php sql injection

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID resu…

class_and_exam_timetabling_system | Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
4.8 MEDIUM
CVE-2026-80439 — Redirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execu…

The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's…

redirection_for_contact_form_7 | Remote | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
4.8 MEDIUM
CVE-2026-80437 — Ninja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and R…

The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shor…

ninja_forms | Remote | Authentication
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
4.8 MEDIUM
CVE-2026-19862 — JetFormBuilder < 3.6.5.2 - Unauthenticated Email Header Injection via Send Email Action

The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it…

Remote | Injection
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
6.5 MEDIUM
CVE-2026-19859 — JetFormBuilder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution via 'status' Par…

The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registe…

Remote | Information Disclosure
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.5 MEDIUM
CVE-2026-86183 — diem-project diem dmWidget BasedmWidgetActions.class.php authorization

A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component …

diem | Remote | Authorization
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
5.0 MEDIUM
CVE-2026-86182 — diem-project diem dmConsole actions.class.php executeCommand cross-site request forgery

A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmCons…

diem | Remote | Cross-Site Request Forgery
Sep 06, 2026 Sep 06, 2026
Sep 06, 2026
Sep 06, 2026
Showing 20 of 12307 Results