Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-73073 — Vim: Arbitrary Ex Command Execution in C Omni-Completion

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref…

| Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-71477 — mise: Incorrect file ownership, when installed by the root user using `install.sh`

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and packaging/standalone/install.envsubst extr…

mise | Misconfiguration
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.7 HIGH
CVE-2026-75915 — CodeWhale before 0.8.64 Environment Variable Leak via js_execution

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. Atta…

Remote | Information Disclosure
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.7 HIGH
CVE-2026-75914 — CodeWhale before 0.8.64 Path Traversal via image_analyze symlink

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks poi…

Remote | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.3 CRITICAL
CVE-2026-75913 — CodeWhale before 0.8.64 Argument Injection via git_show

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the…

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.3 HIGH
CVE-2026-75912 — CodeWhale before 0.8.64 Argument Injection via git_blame

CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev para…

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.5 HIGH
CVE-2026-75911 — CodeWhale before 0.8.64 Remote Code Execution via allow_shell

CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committ…

| Misconfiguration
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-19500 — SureForms contains an uncontrolled resource consumption vulnerability

The Entries component in Brainstorm Force SureForms version, less than 2.1.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, whi…

| Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.8 MEDIUM
CVE-2026-75904 — libmodplug <= 0.8.9.1 - Out-of-Bounds Read in pat_smplooped via Crafted MIDI File

libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one b…

libmodplug | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.7 HIGH
CVE-2026-75859 — CodeWhale before 0.8.64 Arbitrary File Read via instructions

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config…

Remote | Path Traversal
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.5 HIGH
CVE-2026-75858 — CodeWhale rlm_eval before 0.8.64 Remote Code Execution

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRe…

| Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.3 HIGH
CVE-2026-75857 — CodeWhale before 0.8.64 Privilege Escalation via exec_shell_interact

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides t…

| Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.2 CRITICAL
CVE-2026-75856 — CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS response…

Remote | Server-Side Request Forgery
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-19501 — CVE-2026-19501

CSV export functionality in Brainstorm Force SureForms version, <= 2.1.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which a…

| Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-62684 — File Browser: Share API exposes the password hash and bypass token

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized direct…

| Information Disclosure
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-62357 — DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-controlled heap …

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose width times depth times sizeof(int64_t) overflow…

dragonfly | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.5 HIGH
CVE-2026-75898 — RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canv…

ragflow | Remote | Server-Side Request Forgery
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.9 MEDIUM
CVE-2026-75872 — HTML Injection in MailerUp double opt-in verification email

HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-…

Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
10.0 CRITICAL
CVE-2026-75784 — TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipula…

tew-wlc100 | Remote | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.3 MEDIUM
CVE-2026-75032 — Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetoot…

enterprise_linux enterprise_linux | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
Showing 20 of 11469 Results