Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-18255 — Quay: quay: global read-only superuser can view robot account tokens

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuse…

quay | Remote | Authorization
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.6 MEDIUM
CVE-2026-18257 — Improper Certificate Validation in S2OPC

Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered trusted

Remote | Cryptography
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.4 HIGH
CVE-2026-13697 — undici vulnerable to cross-user information disclosure and parse-time crash via degenerat…

undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private …

| Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-54574 — `proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar…

proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/in…

| Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.7 HIGH
CVE-2026-8339 — SQL Injection in Coverity Connect SOAP API

A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted pay…

Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-64559 — s390/pkey: Check length in PKEY_VERIFYPROTK ioctl

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer length request structure provided by user-space and…

| Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-64558 — s390/pkey: Check length in pkey_pckmo handler implementation

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler implementation Explicitly check the length of the target buffer in the pkey_pckmo i…

| Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-20316 — Cisco Secure Firewall Management Center Software Static Credential Vulnerability

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged a…

Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.9 MEDIUM
CVE-2026-67193 — Xlight FTP Server < 3.9.5 Information Disclosure via USER Command

Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command wit…

Remote | Information Disclosure
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.2 CRITICAL
CVE-2026-67192 — Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher

Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a …

Remote | Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.8 CRITICAL
CVE-2026-67191 — Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser

Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malfor…

Remote | Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.8 CRITICAL
CVE-2026-60113 — AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthen…

Remote | Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.8 CRITICAL
CVE-2026-60112 — AIT-GUI < 2.5.1 Missing Authentication via Sessions.create()

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecra…

Remote | Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
10.0 CRITICAL
CVE-2026-54735 — prebid-server's request forgery vulnerability allows for possible host environment data e…

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters…

Remote | Server-Side Request Forgery
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.5 MEDIUM
CVE-2026-54082 — veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing U…

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity vulnerability in PDFAValidator…

Remote | XML External Entity
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.9 MEDIUM
CVE-2026-54081 — veraPDF Parser DoS via PostScript Type 1 Font Programs

veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/type1/Type1F…

Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.9 MEDIUM
CVE-2026-54080 — veraPDF Parser DoS via PostScript CMap Streams

veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/cmap/CMapPar…

Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.7 HIGH
CVE-2026-54079 — veraPDF Validation XXE via XFA

veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulner…

Remote | XML External Entity
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.7 HIGH
CVE-2026-54078 — veraPDF Validation XXE via Rich Text

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validat…

Remote | XML External Entity
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.9 MEDIUM
CVE-2026-50558 — Penelope unsafe tar extraction allows arbitrary local file write via crafted session arch…

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_fold…

Remote | Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
Showing 20 of 9598 Results