Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.3 HIGH
CVE-2026-90772 — Amundsen Frontend through 4.3.0 Stored XSS via Description

Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject maliciou…

Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.3 MEDIUM
CVE-2026-90771 — joi before 17.13.8 and 18.2.9 Prototype Pollution via messages

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys i…

Remote | Misconfiguration
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.8 HIGH
CVE-2026-90770 — Spug through 3.4.0 Remote Code Execution via ping_check

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authent…

Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.3 HIGH
CVE-2026-90769 — Open Notebook before 1.11.0 Server-Side Request Forgery via link-source

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply …

open-notebook | Remote | Server-Side Request Forgery
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.6 HIGH
CVE-2026-90768 — CAPEv2 through commit 471ee4b REST API Task Endpoints Missing Ownership Check

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all ta…

Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.1 HIGH
CVE-2026-90767 — Froxlor before 2.3.12 SSH Key Injection via authorized_keys

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inje…

froxlor | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
9.2 CRITICAL
CVE-2026-90562 — LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administ…

langbot | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
9.3 CRITICAL
CVE-2026-90561 — Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich…

strapi | Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90514 — SourceCodester School Registration and Fee System save_stud.php sql injection

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Sta…

school_registration_and_fee_system | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.9 MEDIUM
CVE-2026-90513 — simalexan api-lambda-send-email-ses API Gateway Endpoint template.yml SES.sendEmail missi…

A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component AP…

api-lambda-send-email-ses | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
6.5 MEDIUM
CVE-2026-90511 — GongShengyue OnlineBooks listSplit BooksServlet.java sql injection

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.jav…

onlinebooks | Remote | Injection
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
8.3 HIGH
CVE-2026-90510 — dromara orion-visor HostKeyServiceImpl.java HostKeyServiceImpl.encryptKey hard-coded key

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-v…

orion-visor | Remote | Cryptography
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90509 — dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded crede…

A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation ca…

orion-visor | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
3.4 LOW
CVE-2026-90508 — Chengdu Qilu Technology Ludashi Message Dispatch ProtectFilter64.sys MessageNotifyCallbac…

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the …

ludashi | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90507 — vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access control

A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the c…

warp-clash-api | Remote | Authorization
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.0 MEDIUM
CVE-2026-90506 — vvbbnn00 WARP-Clash-API Save Account Job race condition

A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes …

warp-clash-api | Remote | Race Condition
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
5.0 MEDIUM
CVE-2026-90505 — vvbbnn00 WARP-Clash-API doUpdateLicenseKey race condition

A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The atta…

warp-clash-api | Remote | Race Condition
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
7.5 HIGH
CVE-2026-90504 — vvbbnn00 WARP-Clash-API authorized missing authentication

A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY …

warp-clash-api | Remote | Authentication
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
2.3 LOW
CVE-2026-90503 — Chengdu Qilu Technology Ludashi ComputerZ_x64.sys sub_11008 information disclosure

A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument Phy…

ludashi | Information Disclosure
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
4.0 MEDIUM
CVE-2026-90502 — stilleshan ServerStatus Stats Generation main.cpp cross site scripting

A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the ar…

serverstatus | Remote | Cross-Site Scripting
Sep 13, 2026 Sep 13, 2026
Sep 13, 2026
Sep 13, 2026
Showing 20 of 13127 Results