Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-63209 — Integer Overflow or Wraparound and Out-of-bounds Write in compress

compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a …

Remote | Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.1 MEDIUM
CVE-2026-49243 — Webmin: Reflected XSS in the Configuration module

Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability tha…

webmin | Remote | Cross-Site Scripting
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.1 MEDIUM
CVE-2026-22101 — Sensitive information leak through hidden menu

The access to the service menu is obfuscated, but possible with only physical access. This menu exposes sensitive information such as serial numbers, MAC addresses, and WiFi network and password.

| Information Disclosure
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
9.3 CRITICAL
CVE-2026-22094 — Weak root password in EVbee DC 80

The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as root using the SSH daemon that is exposed to the network.

Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.0 HIGH
CVE-2026-102570 — ClipBucket v5 through 5.5.3-#197 SQL Injection via language_id Parameter

ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function where the language_id parameter is concatenated unescaped into the WHERE claus…

clipbucket | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.0 HIGH
CVE-2026-102569 — ClipBucket v5 through 5.5.3-#197 SQL Injection via videoid Parameter

ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an UPDATE statement without …

clipbucket | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.8 MEDIUM
CVE-2026-102568 — Pardus Parental Control before 0.7.0 Incorrect Authorization via PPCActivator.py

Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can in…

| Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.9 MEDIUM
CVE-2026-102567 — CTranslate2 before 4.8.1 Out-of-Bounds Read via Model Deserialization

CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model fi…

| Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.5 HIGH
CVE-2026-102566 — CTranslate2 before 4.8.1 Heap Buffer Overflow via model.bin

CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model file…

| Memory Corruption
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.5 HIGH
CVE-2026-102491 — mahonelau kykms SqlInjectionUtil QueryGenerator.java QueryGenerator.doMultiFieldsOrder sq…

A vulnerability was identified in mahonelau kykms up to 8f130c2d85842d5b44caae78cc46d65e505949f7. The impacted element is the function QueryGenerator.doMultiFieldsOrder of the file QueryGenerator.jav…

kykms | Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.7 MEDIUM
CVE-2026-102371 — wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments

In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token pa…

| Information Disclosure
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
6.8 MEDIUM
CVE-2025-33207 — NVIDIA ConnectX and Bluefield Improper Access Control Vulnerability

NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command …

connectx-5 | Denial of Service
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
8.7 HIGH
CVE-2015-20122 — Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp

Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote atta…

Remote | Injection
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-97395 — Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO re…

Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.…

polaris | Server-Side Request Forgery
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
7.5 HIGH
CVE-2026-86450 — Sensitive Data Exposure in Parla Auto's DetaWix Mobile Web Portal

Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by A…

Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.3 MEDIUM
CVE-2026-81569 — Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized…

An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow…

dolphinscheduler | Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
5.3 MEDIUM
CVE-2026-78214 — Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths

An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against prot…

dolphinscheduler | Remote | Authentication
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
0.0 NA
CVE-2026-71899 — Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads t…

A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to acc…

dolphinscheduler | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.3 MEDIUM
CVE-2026-71898 — Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute…

An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /project…

dolphinscheduler | Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
4.3 MEDIUM
CVE-2026-71897 — Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and b…

An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the requ…

dolphinscheduler | Remote | Authorization
Sep 29, 2026 Sep 29, 2026
Sep 29, 2026
Sep 29, 2026
Showing 20 of 14492 Results