Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.0 MEDIUM
CVE-2026-66074 — RabbitMQ: ReDoS via management API ?name= filter

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, match_value/3 passes the user-supplied ?name= regular expression to re:run with no match_lim…

rabbitmq_server | Remote | Denial of Service
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.0 MEDIUM
CVE-2026-66072 — RabbitMQ: Atom table exhaustion via stream `chunk_selector`

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, get_chunk_selector/1 calls binary_to_atom on the raw client-supplied <<"chunk_selector">> pr…

rabbitmq_server | Remote | Denial of Service
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
2.3 LOW
CVE-2026-66069 — RabbitMQ: Monitoring-tag DELETE of auth-attempt metrics

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_authorized_monitor for all methods. DELETE resets rabbit_core_metrics:reset_auth_atte…

rabbitmq_server | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.6 MEDIUM
CVE-2026-66068 — RabbitMQ: Shovel DEBUG log of full state exposes decrypted URIs

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, ?LOG_DEBUG("shutting down Shovel '~ts', ... Shovel state: ~tp", [Name, State]) formats the e…

rabbitmq_server | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.0 MEDIUM
CVE-2026-66067 — RabbitMQ: Stream protocol skips per vhost per user connection limits

RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The stream open handler calls only check_vhost_access; it omits the node/vhost/user connection-limit checks that rabbi…

rabbitmq_server | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.8 HIGH
CVE-2026-96889 — Librsvg: use-after-free when xml includes have duplicated entities

A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability aris…

enterprise_linux enterprise_linux | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.6 HIGH
CVE-2026-96826 — WordPress W4 Post List plugin <= 3.0.6 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind SQL Injection. This issue affects W4 Post List: f…

w4_post_list | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
3.1 LOW
CVE-2026-96552 — sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt

A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the file ssm_pro/src/main/java/cn/sfturing/uti…

hosp_order | Remote | Cryptography
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.0 MEDIUM
CVE-2026-96551 — sfturing hosp_order CommonUserController.java cross-site request forgery

A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserContr…

hosp_order | Remote | Cross-Site Request Forgery
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
3.7 LOW
CVE-2026-96550 — sfturing hosp_order MailUtil.java getProperties cleartext transmission

A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the function getProperties of the file ssm_pro/src/main/java/cn/sfturing/utils/Mail…

hosp_order | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.4 HIGH
CVE-2026-94183 — Address bar spoofing risk in affected Android versions of Arc Search

Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit t…

Remote | Cross-Site Scripting
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
9.4 CRITICAL
CVE-2026-87900 — WP Toolkit for cPanel Argument Injection

Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
9.4 CRITICAL
CVE-2026-87899 — cPanel Arbitrary Code Execution via Privilege Escalation

Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
9.4 CRITICAL
CVE-2026-87898 — Plesk OS Command Injection Vulnerability

OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-86065 — Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, p…

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/api/websocket/routes.go accepts unauthenticated WebSocket cl…

Remote | Denial of Service
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.6 HIGH
CVE-2026-86064 — Klever-Go: /log controls global node logging

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.g…

Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.2 HIGH
CVE-2026-85475 — Automation-controller: automation-controller-container: automation-controller: rsyslog co…

A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, L…

ansible_automation_platform | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.6 MEDIUM
CVE-2026-84724 — Automation-controller: automation-controller: systemjob extra_vars.days argument injectio…

An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable with…

ansible_automation_platform | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.4 MEDIUM
CVE-2026-84721 — Automation-controller: automation-controller: email notification backend allows ssrf via …

A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a …

ansible_automation_platform | Remote | Server-Side Request Forgery
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-84720 — Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks pr…

A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between w…

ansible_automation_platform | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14377 Results