Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-17106 — Tar extraction in moby/go-archive can write outside the destination directory via link fo…

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extrac…

desktop engine sandboxes | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.7 MEDIUM
CVE-2025-9211 — Cross-site scripting in Otalio Ship Property Management System

Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site s…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.1 HIGH
CVE-2025-9210 — Missing JSON Web Token signature validation in Otalio Ship Property Management System

Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs

Remote | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.5 MEDIUM
CVE-2026-47630 — NVIDIA Triton Inference Server Path Traversal Vulnerability

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution.

triton_inference_server | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.5 HIGH
CVE-2026-47629 — NVIDIA Triton Inference Server Improper Input Validation Vulnerability

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.

triton_inference_server | Remote | Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.5 HIGH
CVE-2026-47628 — NVIDIA Triton Inference Server Resource Exhaustion Vulnerability

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.

triton_inference_server | Remote | Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.8 CRITICAL
CVE-2026-47627 — NVIDIA Triton Inference Server Path Traversal Vulnerability

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.

triton_inference_server | Remote | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.5 MEDIUM
CVE-2026-47606 — NVIDIA Triton Inference Server Absolute Path Traversal

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosur…

triton_inference_server | Remote | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.1 CRITICAL
CVE-2026-75625 — Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass

Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validat…

kraken | Remote | Misconfiguration
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.0 CRITICAL
CVE-2026-75130 — Context7 2.1.2 Prompt Injection via Custom AI Instructions

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Cus…

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.9 MEDIUM
CVE-2026-74046 — Wazuh 4.4.0 < 4.14.7 DoS via fdecompress_files() Zip Bomb

Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a mal…

Remote | Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.0 HIGH
CVE-2026-74044 — Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster Hello

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the clust…

Remote | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.1 HIGH
CVE-2026-74039 — Wazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_context

Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting arbitrarily de…

Remote | Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.1 HIGH
CVE-2026-74038 — Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollment

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." t…

Remote | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.3 MEDIUM
CVE-2026-73502 — kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request a…

kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares …

Remote | Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.6 HIGH
CVE-2026-71880 — Server-side template injection in Integrated Publishing Toolkit

Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state via templa…

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.1 CRITICAL
CVE-2026-71879 — Authentication bypass in Integrated Publishing Toolkit

Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain adminis…

Remote | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.2 CRITICAL
CVE-2026-71878 — Authentication bypass in Integrated Publishing Toolkit

Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers t…

Remote | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.8 HIGH
CVE-2026-71551 — Super Productivity: Arbitrary OS Command Execution via IPC EXEC Handler with Persistent W…

Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in electron/ipc-handlers/exec.ts accepts a command st…

| Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.5 MEDIUM
CVE-2026-69160 — OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use strings.HasPrefix(requested_path, user.BasePath) wit…

Remote | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
Showing 20 of 11279 Results