Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-84285 — OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through …

An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.

Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.1 HIGH
CVE-2026-94368 — Noobaa-core: noobaa-core: presigned put url escalation to copyobject via unsigned x-amz-c…

A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Si…

openshift_data_foundation | Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
4.0 MEDIUM
CVE-2026-94210 — Hyve5 Leantime Kanban Board Tickets.php getAllGrouped cross site scripting

A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. Th…

Remote | Cross-Site Scripting
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
4.3 MEDIUM
CVE-2026-91867 — Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang …

When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the ca…

neethi | Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.5 HIGH
CVE-2026-91866 — Apache Neethi: Crafted policies cause unbounded work during intersection leading to denia…

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to…

neethi | Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.5 HIGH
CVE-2026-91865 — Apache Neethi: Crafted policy references cause exponential expansion during normalization…

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of s…

neethi | Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.5 HIGH
CVE-2026-91864 — Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory…

A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial o…

neethi | Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.5 HIGH
CVE-2026-91863 — Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows de…

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are reco…

neethi | Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.7 HIGH
CVE-2026-89139 — Temporal Server worker deployment compute provider executes a caller-supplied command on …

Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a c…

Remote | Misconfiguration
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.2 HIGH
CVE-2026-87858 — Temporal Server completion callback source header can direct attacker-chosen requests to …

Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could…

Remote | Server-Side Request Forgery
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.7 HIGH
CVE-2026-65654 — temporalio/ringpop-go fails to enforce configured label limits on inbound membership goss…

github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in…

Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.7 HIGH
CVE-2026-65653 — temporalio/tchannel-go zero-chunk call fragment causes process termination

github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then u…

Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.7 HIGH
CVE-2026-65652 — temporalio/tchannel-go malformed checksum type causes process termination

github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard initialization …

Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.7 HIGH
CVE-2026-65651 — temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow dur…

temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's Str…

Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.1 HIGH
CVE-2026-16652 — Temporal Server Schedule exclusion search can cause excessive CPU consumption

Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create or update a Schedule that comb…

Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.7 HIGH
CVE-2026-16651 — temporalio/sqlparser malformed MySQL version comments can cause a panic

temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment d…

Remote | Information Disclosure
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
1.0 LOW
CVE-2026-92612 — Eclipse iceoryx2 StaticString Memory Safety Vulnerability

In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice withou…

| Misconfiguration
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.3 MEDIUM
CVE-2026-77021 — Missing decompression size limit in agent receiver allows memory exhaustion via push agen…

Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust …

Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
6.3 MEDIUM
CVE-2026-94277 — Stored Cross-Site Scripting in MISP Galaxy Matrix Statistics via Unescaped Galaxy Name

MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user hold…

Remote | Cross-Site Scripting
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.8 HIGH
CVE-2026-92574 — Cri-o: cri-o checkpoint restore bypasses destination security context

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may …

Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
Showing 20 of 13801 Results