Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-18577 — Incomplete patch leads to administrative account takeover

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

n-central | Remote | Authentication
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.0 HIGH
CVE-2026-10848 — Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message…

zephyr zephyr | Remote | Memory Corruption
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.1 HIGH
CVE-2026-9856 — Path Traversal in huggingface/transformers

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreT…

transformers | Remote | Path Traversal
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
9.8 CRITICAL
CVE-2026-65321 — PyAthena 3.35.4 SQL Injection via DefaultParameterFormatter DELETE/CTAS

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format…

Remote | Injection
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
2.4 LOW
CVE-2026-10774 — PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS

Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PS…

zephyr zephyr | Misconfiguration
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
5.4 MEDIUM
CVE-2026-68583 — luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator v…

luci | Remote | Cross-Site Scripting
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.5 MEDIUM
CVE-2026-68582 — Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpo…

vikunja | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
8.1 HIGH
CVE-2026-68581 — Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a gen…

vikunja | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.5 HIGH
CVE-2026-68580 — FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPac…

freerdp | Remote | Memory Corruption
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
9.6 CRITICAL
CVE-2026-68579 — FreeRDP before 3.30.0 Heap Overflow via CliprdrStream_Read

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. e…

freerdp | Remote | Memory Corruption
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.5 HIGH
CVE-2026-68578 — ArcadeDB before 26.7.3 Authentication Bypass via MCP Transport

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can per…

Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.5 HIGH
CVE-2026-67357 — ArcadeDB before 26.7.3 Information Disclosure via get_server_settings

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can…

Remote | Information Disclosure
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
8.8 HIGH
CVE-2026-67356 — ArcadeDB before 26.7.3 Privilege Escalation via JavaScript Trigger

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. A…

Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
5.9 MEDIUM
CVE-2025-71401 — better-auth before 1.4.1 basePath Modification DoS

better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to th…

better-auth\/oauth-provider | Remote | Misconfiguration
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
7.1 HIGH
CVE-2025-71400 — better-auth passkey before 1.4.0 IDOR via delete-passkey

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID…

better-auth\/oauth-provider | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
8.6 HIGH
CVE-2025-71399 — Better Auth before 1.4.4 Path Normalization Bypass via rou3

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same…

better-auth\/oauth-provider | Remote | Path Traversal
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.4 MEDIUM
CVE-2026-12231 — Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Sit…

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insuf…

exclusive_addons_for_elementor | Remote | Cross-Site Scripting
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.5 MEDIUM
CVE-2026-18573 — Keycloak-services: keycloak-services: client access-type policy condition bypass during c…

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client polic…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.5 MEDIUM
CVE-2026-18572 — Keycloak-services: keycloak-services: uma claim token can override authorization time-pol…

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discove…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
6.6 MEDIUM
CVE-2026-18571 — Keycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add t…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 02, 2026 Aug 02, 2026
Aug 02, 2026
Aug 02, 2026
Showing 20 of 9152 Results