Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.3 HIGH
CVE-2026-93962 — Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Rec…

Remote | Memory Corruption
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
6.9 MEDIUM
CVE-2026-93961 — Dromara UJCMS UserController UserController.java usernameExist improper authorization

A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api/UserController.jav…

Remote | Authorization
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-93960 — Pixelfed OAuth Scope ApiV1Controller.php instancePeers missing authentication

A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of the component OAuth Scope Handler. Such ma…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
8.8 HIGH
CVE-2026-86553 — A password reset vulnerability in ZTE SmartLife APP

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker c…

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
5.4 MEDIUM
CVE-2026-86552 — A vulnerability that skips email ownership verification for account registration in ZTE S…

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly …

Remote | Authentication
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
7.5 HIGH
CVE-2026-93959 — SourceCodester Online Reviewer Management System btn_functions.php sql injection

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php.…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.4 CRITICAL
CVE-2026-94084 — Suricata Http2ThreadMultiBuf Use-After-Free

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

suricata | Remote | Memory Corruption
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.4 CRITICAL
CVE-2026-94083 — Suricata DoH2 Type Confusion Vulnerability

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 reques…

suricata | Remote | Memory Corruption
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
9.1 CRITICAL
CVE-2026-93958 — D-Link R95 DHMAPI ssi system os command injection

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results…

Remote | Injection
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.3 MEDIUM
CVE-2026-93957 — olivier-ls PHP-FTS Filter Matching SearchEngine.php matchesSingleFilter comparison

A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleFilter of the file src/SearchEngine.php of the component Filter Matching. The ma…

Remote | Misconfiguration
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
3.3 LOW
CVE-2026-86551 — Wi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX7…

The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure data…

| Information Disclosure
Sep 20, 2026 Sep 20, 2026
Sep 20, 2026
Sep 20, 2026
4.0 MEDIUM
CVE-2026-94057 — Exim SMTP Smuggling Vulnerability

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
7.5 HIGH
CVE-2026-94056 — Exim Information Disclosure Vulnerability

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

Remote | Memory Corruption
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
3.7 LOW
CVE-2026-94055 — Exim Use-After-Free Vulnerability

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

Remote | Memory Corruption
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
7.0 HIGH
CVE-2026-94054 — Exim Proxy-Protocol Out-of-Bounds Write

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

Remote | Memory Corruption
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.8 HIGH
CVE-2026-93993 — Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a cr…

Remote | Authentication
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.1 HIGH
CVE-2026-93992 — Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft maliciou…

Remote | Path Traversal
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.3 HIGH
CVE-2026-93991 — Argo Workflows 4.1.0 through 4.1.3 Cross-Namespace Disclosure via Negated Selector

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field s…

Remote | Authorization
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
8.7 HIGH
CVE-2026-93990 — Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone hi…

Remote | Injection
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
3.1 LOW
CVE-2026-93989 — vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token …

vllm | Remote | Memory Corruption
Sep 19, 2026 Sep 19, 2026
Sep 19, 2026
Sep 19, 2026
Showing 20 of 13844 Results