Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-62982 — Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by neste…

Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdli…

glances | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-59903 — Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary hea…

netty | Remote | Information Disclosure
Aug 17, 2026 Sep 10, 2026
Aug 17, 2026
Sep 10, 2026
7.5 HIGH
CVE-2026-59902 — Netty: Memory Exhaustion in SctpMessageCompletionHandler

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and …

netty | Remote | Denial of Service
Aug 17, 2026 Sep 10, 2026
Aug 17, 2026
Sep 10, 2026
6.2 MEDIUM
CVE-2026-59894 — sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped b…

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and …

sqlparse | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.5 HIGH
CVE-2026-59893 — sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial…

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted lit…

sqlparse | Remote | Denial of Service
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.7 HIGH
CVE-2026-54284 — sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS bef…

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by grou…

sqlparse | Remote | Denial of Service
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.1 CRITICAL
CVE-2026-51346 — Stud.IP SQL Injection Vulnerability

SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.

Remote | Injection
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-50772 — Squirro Cognitive Search Remote Code Execution

An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.

Remote | Authentication
Aug 17, 2026 Aug 31, 2026
Aug 17, 2026
Aug 31, 2026
6.1 MEDIUM
CVE-2026-50771 — Squirro Cognitive Search Cross-Site Scripting Vulnerability

Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions.

Remote | Cross-Site Scripting
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-50770 — Squirro Cognitive Search Privilege Escalation

An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request.

Remote | Authorization
Aug 17, 2026 Aug 31, 2026
Aug 17, 2026
Aug 31, 2026
9.8 CRITICAL
CVE-2026-50769 — Brainformatik CRM+ SQL Injection

The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action…

Remote | Injection
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-50768 — T-Systems International GmbH ImageMaster Arbitrary Code Execution via File Upload

File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document…

Remote | Misconfiguration
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
5.8 MEDIUM
CVE-2026-48053 — Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViews…

Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs from the Kolibri se…

Remote | Server-Side Request Forgery
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.4 HIGH
CVE-2026-46345 — compliance-trestle - jinja has an Arbitrary File Write via Path Traversal

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the int…

| Path Traversal
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.1 HIGH
CVE-2026-33437 — Stirling PDF: Stored XSS in Info Summary

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/src/main/resources/templates/security/get-info-on-…

stirling_pdf | Remote | Cross-Site Scripting
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.8 HIGH
CVE-2026-9771 — Missing device-pointer validation in flash_copy() syscall allows userspace privilege esca…

The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode …

zephyr zephyr | Authentication
Aug 17, 2026 Aug 26, 2026
Aug 17, 2026
Aug 26, 2026
8.8 HIGH
CVE-2026-68518 — Glances: Command injection bypass of action-template sanitizer via cross-field shell-oper…

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing…

glances | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-68517 — Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — By…

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membersh…

glances | Remote | Misconfiguration
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
8.9 HIGH
CVE-2026-61666 — websocket-driver: Denial of service via malformed Host header

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without ca…

websocket-driver | Remote | Misconfiguration
Aug 17, 2026 Sep 10, 2026
Aug 17, 2026
Sep 10, 2026
7.1 HIGH
CVE-2026-40145 — Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deployme…

A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protec…

| Misconfiguration
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
Showing 20 of 14717 Results