Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.7 HIGH
CVE-2026-92470 — Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticate…

gitlab | Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.9 CRITICAL
CVE-2026-89078 — Double Free in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authentic…

gitlab | Remote | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
8.6 HIGH
CVE-2026-82370 — Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service

Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative switch CLI commands and issue container…

sannav sannav | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
5.0 MEDIUM
CVE-2026-96680 — ByteDance Coze Scraper Extension External Message index.js chrome.runtime.onMessageExtern…

A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.addListener of the file static/background…

coze_scraper_extension | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-96678 — weiqingwen spring-boot-forum Avatar Upload NewUserFormValidator.java validate path traver…

A security vulnerability has been detected in weiqingwen spring-boot-forum up to 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f. Affected is the function validate of the file src/main/java/com/qingwenwei/u…

spring-boot-forum | Remote | Path Traversal
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.5 MEDIUM
CVE-2026-96676 — Fast FAC1900R uhttpd get_alias_name stack-based overflow

A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impacted element is the function get_alias_name of the component uhttpd. Such manipulation leads to stack-based buffer overflow. Th…

fac1900r | Remote | Memory Corruption
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.5 MEDIUM
CVE-2026-96606 — LB-Link BL-CPE600EU Configuration Backup Mifi_config.bin information disclosure

A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13. This vulnerability affects unknown code of the file Mifi_config.bin of the component Configuration Backup Handler. The manipulation …

bl-cpe600eu | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-70125 — Microsoft Outlook Remote Code Execution Vulnerability

Microsoft Outlook Remote Code Execution Vulnerability

Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
6.3 MEDIUM
CVE-2026-59980 — hpack: Unbounded variable integer decoding can cause run-away computation on malformed in…

hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blo…

Remote | Denial of Service
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-96604 — SoftNews Media Group DataLife Engine Search search.php strip_data sql injection

A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulatio…

datalife_engine | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-96603 — Abdurrab5 online-makeup-store Admin functions.php confirm_user authorization

A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of…

online-makeup-store | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-96602 — Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection

A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument user…

online-makeup-store | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-96601 — Abdurrab5 online-makeup-store Admin Login index.php sql injection

A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of the argument id/passwor…

online-makeup-store | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
9.8 CRITICAL
CVE-2026-93352 — Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist…

Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-86583 — Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege E…

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. T…

import_and_export_users_and_customers | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-81537 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.

datastage_on_cloud_pak_for_data | Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.7 HIGH
CVE-2026-81536 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

datastage_on_cloud_pak_for_data | Remote | XML External Entity
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.7 HIGH
CVE-2026-81208 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnera…

datastage_on_cloud_pak_for_data | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.8 HIGH
CVE-2026-80423 — DataStage on Cloud Pak for Data has several vulnerabilities

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.

datastage_on_cloud_pak_for_data | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-75887 — Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handl…

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` e…

openshift_container_platform | Remote | Path Traversal
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14294 Results