Common Vulnerabilities and Exposures (CVE)

CVE-2026-104019

Oct 6, 2026 17:52:47 UTC

OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4....

CVE-2026-19954

Oct 6, 2026 17:52:09 UTC

Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apa...

CVE-2026-77802

Oct 6, 2026 17:51:15 UTC

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting value...

CVE-2026-77803

Oct 6, 2026 17:50:34 UTC

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-...

CVE-2026-106115

Oct 6, 2026 17:50:15 UTC

ImageSharp is a 2D graphics library. From 2.1.0 until 4.1.2, the TIFF CCITT Group 4 encoder allocates Width times rowsPerStrip bytes even though T6BitCompressor.CompressStrip can emit encoded row data and two 12-bit end-of-facsimile-block c...

CVE-2026-77804

Oct 6, 2026 17:49:23 UTC

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certif...

CVE-2026-92931

Oct 6, 2026 17:48:45 UTC

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially expos...

CVE-2026-106113

Oct 6, 2026 17:47:17 UTC

ImageSharp is a 2D graphics library. From 2.0.0 until 4.1.2, decoding an attacker-supplied 32-bit floating-point TIFF as Image<HalfVector4> and applying HistogramEqualization can produce a non-finite or out-of-range luminance in ColorNumeri...

CVE-2026-79311

Oct 6, 2026 17:43:15 UTC

webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().

CVE-2026-88416

Oct 6, 2026 17:43:09 UTC

MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature.

CVE-2026-88360

Oct 6, 2026 17:43:04 UTC

libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length is not a multiple of four bytes, the mmap-based loader can expose pixel data at an address that is not properly al...

CVE-2026-52001

Oct 6, 2026 17:42:56 UTC

An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts

CVE-2026-88355

Oct 6, 2026 17:42:50 UTC

An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-argument functions, the function allocates less memory than sizeof(te...

CVE-2026-88366

Oct 6, 2026 17:42:44 UTC

NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc commands. A specially crafted SVG document containing extreme arc radius values can cause intermediate arc calculation...

CVE-2026-88371

Oct 6, 2026 17:42:37 UTC

ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing specially crafted Code 128 input, decode_e() can return -1 for an invalid edge pattern, and decode6() subsequently left-sh...