Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-108750 — OpenDocMan 2.4.0 through 2.10.0 Decompression Bomb DoS via Upload Text Extraction

OpenDocMan 2.4.0 through 2.10.0 contains a decompression bomb vulnerability that allows authenticated users to exhaust PHP memory by uploading crafted office documents. Attackers can upload a small O…

opendocman | Remote | Denial of Service
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.3 MEDIUM
CVE-2026-108749 — docling-serve 1.14.0 through 1.36.0 Missing Authentication via Memory Management Endpoints

docling-serve 1.14.0 through 1.36.0 contains a missing authentication vulnerability that allows unauthenticated attackers to access /v1/memory/stats and /v1/memory/counts because they omit the requir…

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.9 MEDIUM
CVE-2026-108748 — Quarkus LangChain4j 1.9.0 through 1.14.1 Memory Exhaustion via /_chat/routes WebSocket

Quarkus LangChain4j 1.9.0 through 1.14.1 contains a missing release of memory vulnerability in the chat-scopes WebSocket /_chat/routes endpoint that allows unauthenticated remote clients to exhaust s…

Remote | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.2 MEDIUM
CVE-2026-108747 — Lightdash through 2.556.0 Authorization Bypass via Personal Access Token Deletion

Lightdash through 2.556.0 contains an authorization bypass vulnerability that allows authenticated organization members to delete other users' personal access tokens by supplying their UUID. Attacker…

lightdash | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.8 HIGH
CVE-2026-108746 — Vearch 3.5.2 through 3.5.9 Incorrect Authorization via Role.HasPermissionForResources

Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Au…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
3.1 LOW
CVE-2026-108745 — CloudBeaver through 25.3.5 Missing Authorization via /api/sql-result-value Servlet

CloudBeaver through 25.3.5 contains a missing authorization vulnerability in WebSQLResultServlet that allows any web session holder to read other users' LOB export files from a shared folder. Attacke…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.3 HIGH
CVE-2026-108744 — pbi-cli 3.10.1 through 3.12.0 OS Command Injection via Desktop Sync

pbi-cli 3.10.1 through 3.12.0 contains an OS command injection vulnerability in desktop_sync.py that passes unquoted .pbip paths to cmd /c start when reopening projects. Attackers can lure victims in…

| Injection
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108742 — CloudBeaver through 25.3.5 Missing Authorization via initConnection GraphQL Mutation

CloudBeaver through 25.3.5 contains a missing authorization vulnerability in the initConnection GraphQL mutation that lets view-only shared-project members persist credentials without datasource-edit…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
3.1 LOW
CVE-2026-108741 — Shepherd through 0.3.1 SSRF via DNS Rebinding in Citation Checker

Shepherd (shepherd-ai) through 0.3.1 contains a server-side request forgery guard bypass in the citation-checker extra because the public_url guard validates a resolved address but fetch re-resolves …

Remote | Server-Side Request Forgery
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.3 HIGH
CVE-2026-108740 — GoatCounter through 2.7.0 Privilege Escalation via /user/pref Mass Assignment

GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded req…

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.7 HIGH
CVE-2026-108739 — OpenAgents Workspace through launcher-v1.0.17 Unauthenticated Credential Exposure via /v1…

OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers c…

openagents | Remote | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.2 MEDIUM
CVE-2026-108738 — Traccar 5.7 through 6.16.0 Login CSRF via OpenID Connect Callback

Traccar 5.7 through 6.16.0 contains a cross-site request forgery vulnerability that allows attackers to log victims into attacker-controlled accounts because the OpenID Connect callback never validat…

traccar | Remote | Cross-Site Request Forgery
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.6 HIGH
CVE-2026-108737 — Traccar through 6.16.0 Weak Password Recovery via TokenManager Token Purpose Confusion

Traccar through 6.16.0 contains a weak password recovery vulnerability that allows attackers to reuse password reset tokens as session credentials because TokenManager does not bind tokens to a purpo…

traccar | Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.3 MEDIUM
CVE-2026-108736 — Speedtest Tracker through 1.15.0 IP Allowlist Bypass via X-Forwarded-For Spoofing

Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For …

Remote | Misconfiguration
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108735 — Miniflux 2.3.0 through 2.3.3 SSRF via Per-Feed Proxy URL

Miniflux 2.3.0 through 2.3.3 contains a server-side request forgery vulnerability that allows authenticated users to reach internal addresses by setting a feed's proxy_url. Attackers can point proxy_…

miniflux | Remote | Server-Side Request Forgery
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108734 — Frappe CRM 1.49.0 through 1.87.0 Missing Authorization via get_linked_docs_of_document

Frappe CRM 1.49.0 through 1.87.0 contains a missing authorization vulnerability in crm.api.doc.get_linked_docs_of_document that allows authenticated users to read linked documents without permission …

frappe_crm | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108733 — Frappe HR (hrms) before 16.11.0 Missing Authorization via expire_allocation

Frappe HR (hrms) before 16.11.0, including all 14.x and 15.x releases through 15.64.3, contains a missing authorization vulnerability in the whitelisted expire_allocation method that allows authentic…

frappe_hr | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108732 — Frappe HR (hrms) before 16.11.0 Missing Authorization via get_account_and_amount

Frappe HR (hrms) before 16.11.0, including all 14.x and 15.x releases through 15.64.3, contains a missing authorization vulnerability in the whitelisted get_account_and_amount method that lets authen…

frappe_hr | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108731 — Raven 2.0.0 through 3.0.0 Missing Authorization via join_workspace Invite-Only Bypass

Raven 2.0.0 through 3.0.0 contains a missing authorization vulnerability that allows authenticated users to join invite-only Public workspaces by ignoring the can_only_join_via_invite setting. Attack…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108730 — Raven 2.0.0 through 3.0.0 Missing Authorization via Legacy Message and File APIs

Raven 2.0.0 through 3.0.0 contains a missing authorization vulnerability in legacy methods in raven/api/raven_message.py that skip the workspace membership check. Authenticated non-members can call g…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 13696 Results