Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-84851 — Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6

An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the appl…

ion-c | Remote | Denial of Service
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-84394 — fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority

fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is ne…

fast-uri | Remote | Server-Side Request Forgery
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.5 MEDIUM
CVE-2026-84857 — sigoden aichat API Endpoint serve.rs memory allocation

A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. This manipulation causes uncontrolled memory allocation.…

aichat | Remote | Memory Corruption
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.5 MEDIUM
CVE-2026-84856 — rowboatlabs rowboat Composio Webhook Endpoint route.ts req.json denial of service

A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component…

rowboat | Remote | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.4 MEDIUM
CVE-2026-84852 — Reader Tools PDF Reader App File ActSplashNew.handleDeeplink path traversal

A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the function ActSplashNew.handleDeeplink of the component File Handler. The manipula…

pdf_reader_app | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.6 HIGH
CVE-2026-84452 — Windows ML CLI: CORS misconfig enables localhost RCE

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI…

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.5 HIGH
CVE-2026-84292 — fast-uri vulnerable to authority injection via an unvalidated port in serialize

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port va…

fast-uri | Remote | Injection
Sep 02, 2026 Sep 03, 2026
Sep 02, 2026
Sep 03, 2026
8.6 HIGH
CVE-2026-82524 — UnoPim File Upload RCE via TinyMCE Image Upload Endpoint

UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing…

unopim | Remote | Misconfiguration
Sep 02, 2026 Sep 03, 2026
Sep 02, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-78662 — Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, w…

crypto | Remote | Denial of Service
Sep 02, 2026 Sep 03, 2026
Sep 02, 2026
Sep 03, 2026
6.9 MEDIUM
CVE-2026-75137 — UpSignOn < 7.19.0 Sensitive Data Exposure in Process Memory after Lock

UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been…

| Information Disclosure
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.9 MEDIUM
CVE-2026-75136 — UpSignOn < 7.19.0 Biometric Key Exposure via Windows PasswordVault

UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows PasswordVault API witho…

| Information Disclosure
Sep 02, 2026 Sep 03, 2026
Sep 02, 2026
Sep 03, 2026
6.9 MEDIUM
CVE-2026-75135 — UpSignOn < 7.19.0 Sensitive Key Retention in Memory

UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup …

| Information Disclosure
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.4 MEDIUM
CVE-2026-75134 — SEOWriting WordPress Plugin 1.12.5 Stored XSS via iframe onload

SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permi…

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-56855 — Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests…

crypto | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.4 HIGH
CVE-2023-20577 — SMM Module Heap Overflow Vulnerability

A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.

instinct_mi300a | Memory Corruption
Sep 02, 2026 Sep 03, 2026
Sep 02, 2026
Sep 03, 2026
7.7 HIGH
CVE-2023-20576 — AMD AGESA Insufficient Data Authenticity Verification Vulnerability

Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.

| Authentication
Sep 02, 2026 Sep 03, 2026
Sep 02, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-84841 — tsi-coop tsi-dpdp-cms client-side enforcement of server-side security

A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The att…

tsi-dpdp-cms | Remote | Misconfiguration
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-84840 — tsi-coop tsi-dpdp-cms Bootstrap Setup Endpoint InterceptingFilter.java missing authentica…

A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part of the file InterceptingFilter.java of the component Bootstrap Setup Endpoint. The manipulation leads…

tsi-dpdp-cms | Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.5 MEDIUM
CVE-2026-84839 — tsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing authentication

A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. Affected by this issue is some unknown functionality of the file web.xml of the component Admin Console/DPO Compliance Console. Ex…

tsi-dpdp-cms | Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.5 HIGH
CVE-2026-84382 — HTTPX2: Streaming response decompression does not bound peak memory (decompression amplif…

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before i…

Remote | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
Showing 20 of 12613 Results