Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-61784 — xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS

xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values when serializi…

Remote | Cross-Site Scripting
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.5 HIGH
CVE-2026-61782 — @rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and…

Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds to all network interf…

Remote | Information Disclosure
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.3 CRITICAL
CVE-2026-61742 — DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution

DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started with the documented HTTP tra…

Remote | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.3 CRITICAL
CVE-2026-61741 — http4s-scala-xml has an XML External Entity (XXE) processing issue

http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory…

Remote | XML External Entity
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
10.0 CRITICAL
CVE-2026-61732 — Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output c…

Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutr…

Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
9.3 CRITICAL
CVE-2026-61604 — ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass

The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification meth…

Remote | Authorization
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.2 MEDIUM
CVE-2026-57179 — social-auth-core has a Session Fixation issue

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it …

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
7.4 HIGH
CVE-2026-57178 — social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when …

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
4.3 MEDIUM
CVE-2026-57177 — social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using t…

Remote | Cross-Site Request Forgery
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.8 MEDIUM
CVE-2026-57176 — social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend sho…

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.4 MEDIUM
CVE-2026-57175 — social-auth-core has an Improper Authentication issue

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying tha…

Remote | Authentication
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-54461 — Habitica: Regex Injection / ReDoS in Member Search

Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized b…

Remote | Injection
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-97521 — gfs2: fix quota init duplicate scan

In the Linux kernel, the following vulnerability has been resolved: gfs2: fix quota init duplicate scan gfs2_quota_init() checks for duplicate quota_change IDs while holding qd_lock and the quota h…

linux_kernel | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-97520 — gfs2: move quota_init qc iterator increment

In the Linux kernel, the following vulnerability has been resolved: gfs2: move quota_init qc iterator increment Move qc++ from the loop body into the for-loop increment expression in gfs2_quota_ini…

Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-97519 — drm/xe: Fix null pointer dereference in devcoredump cleanup

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix null pointer dereference in devcoredump cleanup In xe_devcoredump_snapshot_free(), ss->gt may be NULL when the snapsh…

linux_kernel | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-97518 — wifi: cfg80211: reject duplicate wiphy cipher suite entries

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject duplicate wiphy cipher suite entries Duplicate entries in wiphy->cipher_suites do not describe any additio…

linux_kernel | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-97517 — wifi: nl80211: reject beacons with bad HE operation

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject beacons with bad HE operation The HE operation element not only needs to be longer than the fixed part, but…

linux_kernel | Misconfiguration
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-97516 — wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result()

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result() It was recently reported that rtw_fw_adaptivity_resu…

linux_kernel | Memory Corruption
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-97515 — i3c: master: svc: Prevent IRQ storm from false SLVSTART on NPCM845

In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: Prevent IRQ storm from false SLVSTART on NPCM845 On NPCM845, when a target on the I3C bus gets stuck holding SD…

linux_kernel | Denial of Service
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
0.0 NA
CVE-2026-97514 — media: chips-media: wave5: Fix Reports from Kernel Lock Validator

In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix Reports from Kernel Lock Validator handle_dynamic_resolution change requires that the state_lock b…

linux_kernel | Race Condition
Sep 24, 2026 Sep 24, 2026
Sep 24, 2026
Sep 24, 2026
Showing 20 of 14577 Results