Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-73244 — kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory …

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/src/main/java/cn/keking/web/controller/FileControlle…

| Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-66146 — GMS Cross-Site Scripting Vulnerability

Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.

| Cross-Site Scripting
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-66145 — GMS Arbitrary File Write Vulnerability

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary fil…

| Information Disclosure
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-73243 — kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView is omitted from TrustHostFilter and TrustDirFilter …

| Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.1 HIGH
CVE-2026-18844 — Pulsetto Vagus Nerve Stimulator Hidden Functionality

The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, a…

| Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-73242 — FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decryp…

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled…

| Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-73241 — FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accep…

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU whil…

| Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-73235 — FreeCAD: XXE file read and SSRF via external entity injection in Document.xml SAX parser

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp by Base::XMLReader::XMLReader() parses attacker-con…

| XML External Entity
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-73234 — FreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute …

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data att…

| Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-73233 — FreeCAD: FEM formula incomplete escape

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/Mod/Fem/Gui/TaskFemConstraintDisplacement.cpp passes the xDis…

| Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-13457 — InstaWP Connect <= 0.1.3.6 - Unauthenticated Cryptographic Key Disclosure

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.1.3.6 via the (top-level script) function. Thi…

| Information Disclosure
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-19091 — GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_t…

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_…

| Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-16230 — Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Sign…

The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6.…

| Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.6 MEDIUM
CVE-2026-73036 — Bash-it barbuk Theme 3.2.0 Terminal Escape Sequence Injection via pyproject.toml

Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt segment that allows local attackers to inject arbitrary terminal control seque…

| Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-73232 — ffuf denial of service (OOM) via HTTP response decompression bomb

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go chec…

| Denial of Service
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.8 CRITICAL
CVE-2026-73034 — DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences i…

Remote | Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
2.3 LOW
CVE-2026-65655 — Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminati…

When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Se…

Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-73231 — Faker: helpers.fake exploitable into arbritary code execution

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to acc…

| Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-45618 — LiquidJS is Vulnerable to Remote Code Execution

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.

| Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.3 MEDIUM
CVE-2026-71474 — Insights-client-rhel9: insights-client: pull-secret bearer token written to logs on non-2…

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with acce…

advanced_cluster_management_for_kubernetes | Remote | Information Disclosure
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
Showing 20 of 10925 Results