Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-90830 — GNU Binutils Section Merge merge.c _bfd_write_merged_section null pointer dereference

A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to n…

binutils | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.3 MEDIUM
CVE-2026-90829 — GNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer dereference

A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulat…

binutils | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.3 HIGH
CVE-2026-81900 — Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (vWidth/vHeigh…

Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stor…

Remote | Cross-Site Scripting
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
2.6 LOW
CVE-2026-77191 — All of the CVEs covered in this advisory apply to affected platforms running Arista EOS w…

An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completio…

eos | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
2.6 LOW
CVE-2026-75945 — A race condition may cause a supplicant to remain in an authorized state after a clear do…

A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.

eos | Race Condition
Sep 14, 2026 Sep 15, 2026
Sep 14, 2026
Sep 15, 2026
5.6 MEDIUM
CVE-2026-75944 — A race condition during supplicant re-authentication may leave a stale ACL entry that per…

A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants…

eos | Race Condition
Sep 14, 2026 Sep 15, 2026
Sep 14, 2026
Sep 15, 2026
2.6 LOW
CVE-2026-75943 — A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant…

A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this windo…

eos | Misconfiguration
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.3 HIGH
CVE-2026-18116 — Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Name via Workfl…

Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waitin…

Remote | Cross-Site Scripting
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.8 MEDIUM
CVE-2026-14986 — Out-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transaction

The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size data->targe…

zephyr zephyr | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.5 MEDIUM
CVE-2026-91181 — Data Retention Teams Endpoint Leaks Private Team Invite ID

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated…

Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.1 MEDIUM
CVE-2026-91146 — Takahe through 0.11.0 Cross-Site Scripting via javascript: URL Scheme

Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federa…

Remote | Cross-Site Scripting
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.1 HIGH
CVE-2026-91145 — Activiti through 7.1.0.M6 Expression Injection via Mail Task

Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{…

Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.7 HIGH
CVE-2026-91144 — ZFile through 5.0.5 Share Entry Filter Bypass via Download Endpoint

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query par…

Remote | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.2 HIGH
CVE-2026-91143 — goproxy through 15.3 Authentication Bypass via CONNECT

goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT request…

goproxy | Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.3 MEDIUM
CVE-2026-90828 — GNU Binutils ELF Orphan Section ldelf.c elf_orphan_compatible null pointer dereference

A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing …

binutils | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
3.3 LOW
CVE-2026-90827 — GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free

A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after …

gpac | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
2.8 LOW
CVE-2026-90826 — GPAC MP4Box base_scenegraph.c gf_node_del out-of-bounds

A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bo…

gpac | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
3.3 LOW
CVE-2026-90825 — GPAC MP4Box base_scenegraph.c gf_node_unregister use after free

A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results…

gpac | Memory Corruption
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.5 MEDIUM
CVE-2026-76081 — ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions

ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user …

Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.9 MEDIUM
CVE-2026-73449 — On affected platforms running Arista EOS with both 802.1X port authentication and the RAD…

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segm…

eos | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
Showing 20 of 12966 Results