Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2024-14029 — Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this…

tornado | Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2023-54397 — Tornado before 6.3.3 HTTP Request Smuggling via Content-Length

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests wit…

tornado | Remote | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.1 HIGH
CVE-2026-54077 — ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users

ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privil…

Remote | Server-Side Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.3 MEDIUM
CVE-2026-92082 — Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on…

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic a…

| Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
4.3 MEDIUM
CVE-2026-91842 — OpenBankProject OBP-API Kryo Redis.scala KryoInjection.invert deserialization

A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component K…

Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
2.8 LOW
CVE-2026-91836 — OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with missing fac…

A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomp…

| Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
2.8 LOW
CVE-2026-91835 — OpenClaw ClawScan File Classifier static_scanner.go IsBinaryFile interpretation conflict

A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The ma…

| Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.2 HIGH
CVE-2026-90650 — MotoPress Hotel Booking <= 6.2.4 - Unauthenticated Stored Cross-Site Scripting via Stripe…

The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient …

Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.9 MEDIUM
CVE-2026-90439 — NGINX ngx_http_v3_module vulnerability

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer ov…

nginx_plus nginx_open_source | Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.7 HIGH
CVE-2026-89025 — Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send…

Remote | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-88618 — SmartAdmin Stored Cross-Site Scripting Vulnerability

1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code.

| Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-88617 — SmartAdmin Authorization Bypass Privilege Escalation

SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.

| Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-88616 — RuoYi-Vue-Plus Remote Code Execution Vulnerability

An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process…

| Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-79551 — Tenda NVR Hardcoded Cryptographic Key Vulnerability

Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

| Cryptography
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-79425 — CRMEB Server-Side Request Forgery

An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.

| Server-Side Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
0.0 NA
CVE-2026-79303 — Kaiten SQL Injection Vulnerability

kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and without using parameterized statements or store…

| Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.1 CRITICAL
CVE-2026-63696 — Dell SmartFabric OS10 Insecure Code Update Vulnerability

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit …

Remote | Misconfiguration
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.8 CRITICAL
CVE-2026-63695 — Dell SmartFabric OS10 Session Fixation Vulnerability

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, lea…

Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.0 CRITICAL
CVE-2026-61549 — Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes ba…

Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/bac…

woodpecker | Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
10.0 CRITICAL
CVE-2026-59971 — MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated…

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct …

Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
Showing 20 of 13220 Results