Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-76718 — HPE OneView - Cross-site scripting vulnerability

A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions.

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
3.7 LOW
CVE-2026-4523 — Missing Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthen…

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.0 HIGH
CVE-2026-19547 — Local Privilege Escalation in Ghostscript for Windows

Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths und…

ghostscript | Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.0 CRITICAL
CVE-2026-15390 — Out-of-bounds write in Das U-Boot

Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by s…

| Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.1 MEDIUM
CVE-2026-11796 — Asset Suite Improper Access Control Vulnerability

Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service condi…

asset_suite asset_suite | Remote | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.3 MEDIUM
CVE-2026-10518 — Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticate…

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.0 MEDIUM
CVE-2026-102474 — Dash: dash: heap out-of-bounds write in conv_escape via undersized unicode escape reserva…

A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an …

enterprise_linux enterprise_linux | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.5 MEDIUM
CVE-2026-102473 — Dash: dash: super-polynomial backtracking in pmatch when libc fnmatch is disabled

A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwi…

enterprise_linux enterprise_linux | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.1 HIGH
CVE-2026-96440 — Flowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Directory(Path…

Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote au…

agentflow | Remote | Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.3 CRITICAL
CVE-2026-96431 — Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type

Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute…

agentflow | Remote | Misconfiguration
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.7 HIGH
CVE-2026-96430 — Flowring Agentflow 4.0 - Exposed Dangerous Method or Function

Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands v…

agentflow | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.3 CRITICAL
CVE-2026-96429 — Flowring Agentflow 4.0 - SQL Injection

SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter.

agentflow | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.3 CRITICAL
CVE-2026-96428 — Flowring Agentflow 4.0 - SQL Injection

SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words paramet…

agentflow | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-92142 — Apache Karaf: Authorization bypass in JMX MBean lifecycle operations

Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server…

karaf | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-91085 — Apache Karaf: config:install missing ACL entry allows privilege escalation to admin

Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles…

karaf karaf_decanter | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-91048 — Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege es…

The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenti…

karaf karaf_decanter | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-91012 — Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalati…

org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from call…

karaf karaf_decanter | Path Traversal
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.9 CRITICAL
CVE-2026-84154 — Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPE…

A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the s…

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.7 HIGH
CVE-2026-101169 — Octopus Server Insecure Deserialization Remote Code Execution

In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of …

octopus_server | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.7 HIGH
CVE-2026-86158 — Missing Authentication in the local .NET backend of Progress Telerik Fiddler Everywhere

Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the…

| Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14348 Results