Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-48098 — NexTOR IP Changer Unsafely Uses sudo and shell=True

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using `sudo` and `shell=…

| Misconfiguration
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-48097 — NexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command Execution

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of…

| Injection
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-17435 — File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlink…

File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link to a missing file, and the touch option…

| Path Traversal
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.1 HIGH
CVE-2025-71409 — No Authentication for Very High Frequency Data Link messages used in CPDLC

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. T…

Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.0 MEDIUM
CVE-2025-71410 — Malicious Link Control Frames Can Cause Loss of CPDLC Functions

Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.3 HIGH
CVE-2026-11430 — Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit

Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookToken is configured, a compound conditional short-c…

Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.0 MEDIUM
CVE-2025-71411 — In CPDLC, Broadcast Control Frames Can Disconnect Multiple Aircraft Simultaneously

Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio …

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.1 HIGH
CVE-2025-71412 — In CPDLC, False Emergency or Status Messages Will be Accepted as Legitimate

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and groun…

Remote | Injection
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.0 MEDIUM
CVE-2025-71413 — In CPDLC, Malformed or Out of Sequence Frames Can Cause Resets

Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced situational awareness. This t…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-71852 — pypdf: Possible long runtimes/large memory usage for large CID font width ranges

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_w…

| Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-71851 — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJ…

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry …

| Cryptography
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-71850 — Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure

Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later re…

| Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-71849 — Hono: Proxy Helper does not remove response headers listed in the `Connection` header

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by …

| Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-71848 — Hono: Algorithmic Complexity DoS in Language Middleware

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service…

| Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-69127 — Kirby: System path exposure from error messages in the REST API

Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem pa…

kirby | Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-71847 — Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and cras…

Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and …

| Memory Corruption
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-19231 — SourceCodester Simple Doctors Appointment System ajax.php delete_appointment sql injection

A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipul…

| Injection
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.1 HIGH
CVE-2026-70561 — TestLink 1.9.20 and prior Authenticated IDOR via attachmentdownload.php

TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by suppl…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-66000 — Frappe: Unrestricted access to Document Follow APIs

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing us…

| Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-66058 — Frappe: Unrestricted access to a Document Follow API

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixe…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
Showing 20 of 10074 Results