Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-18770 — vibesurf-ai VibeSurf Python Validation code code injection

A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. Th…

| Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.7 HIGH
CVE-2026-68494 — jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incompl…

The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining…

jackson-core | Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-67618 — marimo < 0.23.15 API Key Exfiltration via Malicious Notebook PEP-723 Metadata

marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata…

Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-69251 — Flowise RCE via TypeORM DataSource

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSourc…

flowise | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-11368 — Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer

The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a …

zephyr zephyr | Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.9 MEDIUM
CVE-2026-18401 — jackson-core: Number length constraint bypass in non-blocking (async) JSON parser leads t…

The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSO…

jackson-core | Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-69250 — Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unau…

flowise | Server-Side Request Forgery
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-70368 — Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel ser…

enterprise_linux enterprise_linux | Remote | Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.4 MEDIUM
CVE-2026-70367 — Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified…

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions b…

enterprise_linux enterprise_linux | Remote | Server-Side Request Forgery
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.8 HIGH
CVE-2026-17070 — Vault Credential Confusion via Authorization Bypass in HAVELSAN's Liman MYS

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
4.6 MEDIUM
CVE-2026-14337 — Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripti…

Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.

Remote | Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-18766 — chetans9 core-php-admin-panel customers.php sql injection

A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-…

| Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.7 HIGH
CVE-2026-67200 — Perspective 5.0.0 Path Traversal via cwd_static_file_handler

Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments in HTTP req…

Remote | Path Traversal
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-67199 — Perspective 5.0.0 DoS via Loop Expression Evaluation

Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or wh…

Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.7 HIGH
CVE-2026-67198 — Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher

Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or …

Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.4 MEDIUM
CVE-2026-67196 — Perspective 5.0.0 XSS via Debug Plugin innerHTML Interpolation

Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell values containing unes…

Remote | Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.8 HIGH
CVE-2026-67195 — Perspective 5.0.0 RCE via eval() Expression Injection

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the P…

Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.8 HIGH
CVE-2026-18650 — Missing Authorization Leading to Root Code Execution in HAVELSAN's Liman MYS

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.8 CRITICAL
CVE-2026-61514 — Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming pack…

Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.8 CRITICAL
CVE-2026-61515 — Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a…

Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
Showing 20 of 9433 Results