Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-63089 — WireGuard Easy Weak Token Generation Information Disclosure via OTL Route

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGua…

Remote | Cryptography
Jul 16, 2026 Jul 18, 2026
Jul 16, 2026
Jul 18, 2026
9.1 CRITICAL
CVE-2026-15422 — SCTP needs to better-check INIT ACK chunk parameters

The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chunk. Since this lookup runs during packet classific…

illumos-gate smartos | Remote | Memory Corruption
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.3 CRITICAL
CVE-2026-46515 — Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backu…

Remote | Information Disclosure
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.9 CRITICAL
CVE-2026-46512 — Frogman: Dialplan template parameters interpolated into extensions_custom.conf without es…

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, and Tools/Dial…

Remote | Injection
Jul 16, 2026 Jul 18, 2026
Jul 16, 2026
Jul 18, 2026
10.0 CRITICAL
CVE-2026-45336 — HireFlow: Use of Hard-coded Credentials

HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used…

Remote | Authentication
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.8 CRITICAL
CVE-2026-63087 — Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint

Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install…

Remote | Authentication
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.1 CRITICAL
CVE-2026-57074 — XML::Bare versions through 0.53 for Perl have an unbounded character lookahead

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such…

Remote | Memory Corruption
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.1 CRITICAL
CVE-2026-57073 — HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead

HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators suc…

Remote | Memory Corruption
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.1 CRITICAL
CVE-2026-46621 — Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection

Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through …

Remote | Authentication
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-46562 — Yamcs: Remote Code Execution via Mission Database algorithm override

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorit…

Remote | Injection
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.9 CRITICAL
CVE-2026-45568 — zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths

zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to ur…

zrok | Remote | Server-Side Request Forgery
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.1 CRITICAL
CVE-2026-44632 — Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorith…

Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFacto…

yamcs | Remote | Injection
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.8 CRITICAL
CVE-2026-44596 — Yamcs: No Rate Limiting on Authentication Endpoint

Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any…

yamcs | Remote | Authentication
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.8 CRITICAL
CVE-2026-3031 — Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg libr…

Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fast JPEG thumbnail library th…

Remote | Supply Chain
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.3 CRITICAL
CVE-2026-59866 — Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clie…

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both gen…

kiota | Remote | Path Traversal
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.3 CRITICAL
CVE-2026-59865 — Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota …

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version valu…

kiota | Remote | Injection
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.3 CRITICAL
CVE-2026-59864 — Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values fro…

kiota | Remote | Path Traversal
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.3 CRITICAL
CVE-2026-54733 — moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoi…

The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integratio…

Remote | Authentication
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-45695 — Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-passw…

Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTT…

Remote | Misconfiguration
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.1 CRITICAL
CVE-2026-14890 — CVE-2026-14890

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attac…

Remote | Authentication
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
Showing 20 of 945 Results