Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.1 LOW
CVE-2026-96282 — Flatpak: flatpak: extension metadata path traversal file existence oracle

A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications us…

enterprise_linux flatpak enterprise_linux | Remote | Path Traversal
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.3 LOW
CVE-2026-100882 — Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting

A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the compone…

laravel-crm | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
2.6 LOW
CVE-2026-100881 — zhistaredu StarTraining application.yml cross site scripting

A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enable…

startraining | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.2 MEDIUM
CVE-2026-96281 — Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system ap…

On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper Rem…

Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.5 HIGH
CVE-2026-96280 — Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent ope…

enterprise_linux flatpak enterprise_linux | Remote | Memory Corruption
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.8 CRITICAL
CVE-2026-101090 — Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oau…

Remote | Injection
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
3.1 LOW
CVE-2026-101089 — Nezha before 2.2.7 Information Disclosure via /api/v1/profile

Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract pas…

Remote | Information Disclosure
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.0 MEDIUM
CVE-2026-101088 — Nezha before 2.3.1 Denial of Service via Concurrent Server Delete

Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously report…

Remote | Denial of Service
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
5.3 MEDIUM
CVE-2026-101087 — Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6

Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges — specifically…

Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101086 — Nezha Dashboard before 2.3.5 Task Type Validation Bypass

Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types…

Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
7.1 HIGH
CVE-2026-101085 — Nezha before 2.3.8 Denial of Service via Alert Rule

Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluat…

Remote | Denial of Service
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.6 CRITICAL
CVE-2026-101084 — obot before v0.21.1 Authorization Bypass via /mcp-connect

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Att…

Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
9.8 CRITICAL
CVE-2026-101065 — Obot Quickstart Docker Deployment Unauthenticated Admin Access

Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080…

Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.3 HIGH
CVE-2026-101064 — Obot before v0.23.0 Server-Side Request Forgery via MCP

Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attac…

Remote | Server-Side Request Forgery
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.9 MEDIUM
CVE-2026-101063 — Obot before v0.23.0 Authentication Bypass via Registry API

Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. Unauthenticated attackers can read registry metadata inclu…

Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
8.8 HIGH
CVE-2026-101062 — Obot before v0.23.0 Authentication Bypass via OAuth Dynamic Client Registration

Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on …

Remote | Authentication
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
4.0 MEDIUM
CVE-2026-100880 — zhistaredu StarTraining Upload Endpoint MimeTypeUtils.java cross site scripting

A weakness has been identified in zhistaredu StarTraining up to 3.8.1. This vulnerability affects unknown code of the file du-common/src/main/java/com/edu/common/utils/file/MimeTypeUtils.java of the …

startraining | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
4.3 MEDIUM
CVE-2026-100879 — zhistaredu StarTraining dataScope Endpoint SysRoleServiceImpl.java checkRoleAllowed autho…

A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The man…

startraining | Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
6.5 MEDIUM
CVE-2026-100878 — zhistaredu StarTraining authRole Endpoint SysUser.java SysUser.isAdmin authorization

A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/Sy…

startraining | Remote | Authorization
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
5.0 MEDIUM
CVE-2026-100877 — mathurvishal CloudClassroom-PHP-Project registrationform.php cross site scripting

A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file regist…

cloudclassroom-php-project | Remote | Cross-Site Scripting
Sep 27, 2026 Sep 27, 2026
Sep 27, 2026
Sep 27, 2026
Showing 20 of 14066 Results