Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-68583 — luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator v…

luci | Remote | Cross-Site Scripting
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
9.3 CRITICAL
CVE-2026-68582 — Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpo…

Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
8.6 HIGH
CVE-2026-68581 — Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a gen…

Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.7 HIGH
CVE-2026-68580 — FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPac…

Remote | Memory Corruption
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
9.6 CRITICAL
CVE-2026-68579 — FreeRDP before 3.30.0 Heap Overflow via CliprdrStream_Read

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. e…

Remote | Memory Corruption
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.7 HIGH
CVE-2026-68578 — ArcadeDB before 26.7.3 Authentication Bypass via MCP Transport

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can per…

Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.7 HIGH
CVE-2026-67357 — ArcadeDB before 26.7.3 Information Disclosure via get_server_settings

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can…

Remote | Information Disclosure
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
8.8 HIGH
CVE-2026-67356 — ArcadeDB before 26.7.3 Privilege Escalation via JavaScript Trigger

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. A…

Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
9.3 CRITICAL
CVE-2025-71401 — better-auth before 1.4.1 basePath Modification DoS

better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to th…

Remote | Misconfiguration
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.1 HIGH
CVE-2025-71400 — better-auth passkey before 1.4.0 IDOR via delete-passkey

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID…

Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
8.8 HIGH
CVE-2025-71399 — Better Auth before 1.4.4 Path Normalization Bypass via rou3

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same…

Remote | Path Traversal
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.4 MEDIUM
CVE-2026-12231 — Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Sit…

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insuf…

Remote | Cross-Site Scripting
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.5 MEDIUM
CVE-2026-18573 — Keycloak-services: keycloak-services: client access-type policy condition bypass during c…

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client polic…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.5 MEDIUM
CVE-2026-18572 — Keycloak-services: keycloak-services: uma claim token can override authorization time-pol…

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discove…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.6 MEDIUM
CVE-2026-18571 — Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add t…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
5.4 MEDIUM
CVE-2026-18570 — Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass…

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
0.0 NA
CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and…

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve t…

| Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
0.0 NA
CVE-2026-16292 — Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF

The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in…

| Cross-Site Request Forgery
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
0.0 NA
CVE-2026-16291 — ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR

The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete …

| Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
0.0 NA
CVE-2026-16285 — WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any atta…

| Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
Showing 20 of 9258 Results