Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-77651 — arrayref Supply Chain Compromise

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control se…

Remote | Supply Chain
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.8 CRITICAL
CVE-2026-77650 — append-only-vec Malicious Dependency Arbitrary Code Execution

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-cont…

Remote | Supply Chain
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.8 CRITICAL
CVE-2026-77649 — Internment Rust Crate Arbitrary Code Execution Vulnerability

The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control s…

Remote | Supply Chain
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-43679 — Apple Watch Contacts Access Bypass via Physical Access

This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.

watchos watchos | Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-20679 — Apple macOS Application Denial of Service Vulnerability

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app term…

macos macos | Denial of Service
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.7 HIGH
CVE-2026-16520 — Genians Genian NAC and Genian ZTNA SQL Injection and Authentication Bypass Vulnerability

Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, and Genians Genian ZTNA V6.0 allows SQL Injecti…

genian_nac genian_ztna | Remote | Injection
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
2.2 LOW
CVE-2026-77648 — OpenStack Glance Server-Side Request Forgery

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF),…

glance | Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.8 CRITICAL
CVE-2026-77647 — SPIP Remote Code Execution Vulnerability

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_exp…

Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.7 MEDIUM
CVE-2026-77113 — Path Traversal Vulnerability in apport-unpack

Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via …

apport | Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.7 HIGH
CVE-2026-77646 — Server Side Request Forgery (SSRF) vulnerability reported in Windchill

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

windchill_pdmlink flexplm | Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.2 CRITICAL
CVE-2026-77645 — Critical Remote Code Execution (RCE) vulnerability reported in Windchill

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

windchill_pdmlink flexplm | Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.3 CRITICAL
CVE-2026-77644 — Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability …

A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
4.4 MEDIUM
CVE-2026-77643 — Xapian Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). …

xapian-core | Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-77642 — Tor Out-of-Bounds Write Vulnerability

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially majo…

tor | Remote | Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.5 HIGH
CVE-2026-72860 — 9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Map…

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/…

Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-72848 — langchain-community SitemapLoader Does Not Apply restrict_to_same_domain to Nested Sitema…

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cros…

Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.4 MEDIUM
CVE-2026-72846 — Lightdash Scheduled Delivery Webhook URLs Are Not Validated, Allowing Server-Side Request…

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/c…

Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.8 CRITICAL
CVE-2026-72843 — EverShop Missing Authorization on PATCH /api/customers/:id Allows Unauthenticated Account…

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to …

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-72818 — NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+…

Remote | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-70105 — Microsoft Word Information Disclosure Vulnerability

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
Showing 20 of 11683 Results