Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-56453 — HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerabili…

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach th…

dfxanalytics | Remote | Authentication
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.2 CRITICAL
CVE-2026-63306 — stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints

stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private…

Remote | Server-Side Request Forgery
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.2 CRITICAL
CVE-2026-63305 — AVideo through 29.0 OS Command Injection via ffmpeg.json.php

AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Att…

avideo | Remote | Injection
Jul 16, 2026 Jul 17, 2026
Jul 16, 2026
Jul 17, 2026
9.2 CRITICAL
CVE-2026-63304 — AVideo through 29.0 OS Command Injection via listFFmpegProcesses

AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside s…

avideo | Remote | Injection
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.0 CRITICAL
CVE-2026-11386 — ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injec…

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu…

Remote | Injection
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2023-49900 — Origin Validation Error in X-Rite MA-T6

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

Remote | Injection
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2023-49899 — Origin Validation Error in X-Rite MA-T6

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

Remote | Authentication
Jul 16, 2026 Jul 18, 2026
Jul 16, 2026
Jul 18, 2026
9.6 CRITICAL
CVE-2026-22752 — Spring Security Authorization Server Dynamic Client Registration endpoints perform insuff…

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1…

Remote | Authentication
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.2 CRITICAL
CVE-2026-15925 — Improper TLS Hostname Verification in Snowflake Connector for Python

Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTT…

Remote | Misconfiguration
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-12492 — Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp…

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, all…

Remote | Authentication
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-15013 — SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' P…

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability e…

Remote | Authentication
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-55652 — Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unau…

Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-…

Remote | Authentication
Jul 15, 2026 Jul 17, 2026
Jul 15, 2026
Jul 17, 2026
9.3 CRITICAL
CVE-2026-55445 — Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication

Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in back/loaders/express.ts checks /api/user/init but not…

Remote | Authentication
Jul 15, 2026 Jul 18, 2026
Jul 15, 2026
Jul 18, 2026
9.6 CRITICAL
CVE-2026-54458 — AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast…

WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute a…

avideo | Remote | Cross-Site Scripting
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
9.2 CRITICAL
CVE-2026-52893 — Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser …

Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when the OIDC email or username …

Remote | Authentication
Jul 15, 2026 Jul 18, 2026
Jul 15, 2026
Jul 18, 2026
9.9 CRITICAL
CVE-2026-52891 — Wekan: Shell Injection via Avatar Upload

Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection.…

Remote | Injection
Jul 15, 2026 Jul 17, 2026
Jul 15, 2026
Jul 17, 2026
9.8 CRITICAL
CVE-2026-30623 — LiteLLM Remote Code Execution

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary …

Remote | Injection
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-30618 — Fay Remote Code Execution Vulnerability

xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management int…

Remote | Injection
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
9.1 CRITICAL
CVE-2026-26718 — XXL-JOB Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affe…

Remote | Cross-Site Request Forgery
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2025-65720 — GPT Researcher Remote Code Execution Vulnerability

An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.

Remote | Injection
Jul 15, 2026 Jul 16, 2026
Jul 15, 2026
Jul 16, 2026
Showing 20 of 945 Results