CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2026-38345

    Last Modified: 2 Sept 2026

    A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 27 Aug 2026
    9.8
    Critical

    CVE-2026-37072

    Last Modified: 3 Sept 2026

    Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.

    Published: 27 Aug 2026
    5.3
    Medium

    CVE-2026-37073

    Last Modified: 2 Sept 2026

    Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header.

    Published: 27 Aug 2026
    5.3
    Medium

    CVE-2026-37069

    Last Modified: 3 Sept 2026

    Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint.

    Published: 27 Aug 2026
    6.5
    Medium

    CVE-2026-37066

    Last Modified: 3 Sept 2026

    Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.

    Published: 27 Aug 2026
    9.8
    Critical

    CVE-2026-37004

    Last Modified: 1 Sept 2026

    BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.

    Published: 27 Aug 2026
    9.8
    Critical

    CVE-2026-30612

    Last Modified: 2 Sept 2026

    An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components

    Published: 27 Aug 2026
    9.8
    Critical

    CVE-2026-35868

    Last Modified: 1 Sept 2026

    A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30047

    Last Modified: 28 Aug 2026

    A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.

    Published: 27 Aug 2026
    4.7
    Medium

    CVE-2026-81893

    Last Modified: 1 Sept 2026

    A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4

    Published: 27 Aug 2026
    5.4
    Medium

    CVE-2026-81668

    Last Modified: 27 Aug 2026

    A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules belonging to a Content View Filter in another organization by supplying that filter's identifier. This can result in unauthorized disclosure of filter-rule information and unauthorized changes to unpublished Content View filter configuration.

    Published: 27 Aug 2026
    8.8
    High

    CVE-2026-75419

    Last Modified: 2 Sept 2026

    go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz middleware always allows requests. Any authenticated user (regardless of role or tenant) can invoke administrative APIs such as deleting users, resetting passwords, and creating tenants.

    Published: 27 Aug 2026
    9.8
    Critical

    CVE-2026-75357

    Last Modified: 2 Sept 2026

    An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.

    Published: 27 Aug 2026
    7.2
    High

    CVE-2026-75417

    Last Modified: 28 Aug 2026

    A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated directly into a FIND_IN_SET() SQL clause without proper sanitization. This allows an authenticated administrator to execute arbitrary SQL queries via boolean-based blind injection, potentially leading to full database compromise.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-38347

    Last Modified: 31 Aug 2026

    A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-38349

    Last Modified: 28 Aug 2026

    An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-38344

    Last Modified: 31 Aug 2026

    A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

    Published: 27 Aug 2026
    6.5
    Medium

    CVE-2026-37070

    Last Modified: 3 Sept 2026

    Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.

    Published: 27 Aug 2026
    8.1
    High

    CVE-2026-37068

    Last Modified: 3 Sept 2026

    Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint.

    Published: 27 Aug 2026
    5.3
    Medium

    CVE-2026-37067

    Last Modified: 29 Aug 2026

    Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.

    Published: 27 Aug 2026
    6.5
    Medium

    CVE-2026-37009

    Last Modified: 31 Aug 2026

    A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL commands via an unsanitized sql_query argument.

    Published: 27 Aug 2026
    9.8
    Critical

    CVE-2026-37006

    Last Modified: 29 Aug 2026

    A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.

    Published: 27 Aug 2026
    9.8
    Critical

    CVE-2026-35869

    Last Modified: 1 Sept 2026

    A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command execution context. An attacker can exploit this vulnerability by injecting specially crafted shell metacharacters or payloads into the vulnerable parameter, resulting in the execution of arbitrary operating system commands.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30073

    Last Modified: 2 Sept 2026

    An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30072

    Last Modified: 31 Aug 2026

    A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30069

    Last Modified: 31 Aug 2026

    A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30063

    Last Modified: 31 Aug 2026

    An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted snssais query.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30059

    Last Modified: 31 Aug 2026

    An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration Request message.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30051

    Last Modified: 31 Aug 2026

    An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PUT request.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30057

    Last Modified: 28 Aug 2026

    An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-26459

    Last Modified: 2 Sept 2026

    ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmentation fault when processing malformed COAP messages with insufficient option data.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-26457

    Last Modified: 2 Sept 2026

    ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_dump_msg() function when processing COAP messages containing options with zero length.

    Published: 27 Aug 2026
    6.5
    Medium

    CVE-2026-81658

    Last Modified: 27 Aug 2026

    A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template contents belonging to another organization or location by supplying the corresponding audit ID. This can result in unauthorized disclosure of historical template contents, which may contain sensitive configuration information, credentials, or other secrets. The REST API revision endpoints correctly restrict this lookup.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30070

    Last Modified: 31 Aug 2026

    An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30067

    Last Modified: 31 Aug 2026

    An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30050

    Last Modified: 28 Aug 2026

    An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30056

    Last Modified: 28 Aug 2026

    A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted NGAP messages during the initialization of a new RAN connection.

    Published: 27 Aug 2026
    9.8
    Critical

    CVE-2026-26897

    Last Modified: 2 Sept 2026

    An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30045

    Last Modified: 31 Aug 2026

    An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30046

    Last Modified: 28 Aug 2026

    A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-30062

    Last Modified: 28 Aug 2026

    An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-37012

    Last Modified: 2 Sept 2026

    A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user telemetry data via hardcoded API credentials.

    Published: 27 Aug 2026
    8.8
    High

    CVE-2026-26899

    Last Modified: 2 Sept 2026

    An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-26456

    Last Modified: 31 Aug 2026

    A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5. The issue is caused by a race condition between the request dispatch thread and the session cleanup thread when accessing shared session list nodes without proper synchronization.

    Published: 27 Aug 2026
    7.5
    High

    CVE-2026-26453

    Last Modified: 2 Sept 2026

    ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_handle_session() function when processing COAP messages containing URI_PATH options with NULL data pointers. When the server searches for a URI_PATH option matching the string "separate", it directly calls strncmp() on option_list[i].data without checking if the pointer is NULL. This causes a segmentation fault when the option's data field is NULL.

    Published: 27 Aug 2026
    6.5
    Medium

    CVE-2026-38343

    Last Modified: 31 Aug 2026

    An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

    Published: 27 Aug 2026
    5.3
    Medium

    CVE-2026-47874

    Last Modified: 2 Sept 2026

    The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

    Published: 26 Aug 2026
    6.3
    Medium

    CVE-2026-47861

    Last Modified: 2 Sept 2026

    An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

    Published: 26 Aug 2026
    5.5
    Medium

    CVE-2026-81421

    Last Modified: 27 Aug 2026

    A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 26 Aug 2026
    5.9
    Medium

    CVE-2026-47863

    Last Modified: 1 Sept 2026

    In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier

    Published: 26 Aug 2026