Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-71577 — Multicluster-global-hub: multicluster-global-hub: spec-topic read acl leaks bootstrap kub…

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised ma…

Remote | Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.5 MEDIUM
CVE-2026-63623 — Libvirt: information disclosure via world-readable storage volume images during clone/con…

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with ove…

enterprise_linux enterprise_linux | Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.5 HIGH
CVE-2026-71576 — Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source…

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a man…

Remote | Authentication
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-72731 — Discourse: Strip SQL comments and use non-recursive parameter interpolation in Data Explo…

Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a parameterized Data Explorer query, including non-…

| Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.5 MEDIUM
CVE-2026-72726 — Discourse: Unauthorized eavesdropping on private AI bot conversations.

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on private AI bot conversations through the AI bot reply st…

Remote | Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.4 MEDIUM
CVE-2026-72725 — Discourse: Stored XSS in staff action logs injects staff UI

Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that could inject stored cross-site scripting into the …

Remote | Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
4.3 MEDIUM
CVE-2026-72724 — Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID Misma…

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/chat/onebox_handler.rb resolves Chat::Thread by route thread_id independently of…

Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.3 MEDIUM
CVE-2026-72723 — Discourse: Anonymous sidebar serialization exposes descriptions of category-restricted ta…

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymous_default_navigation_menu_tags serializes tags from SiteSetting.default_na…

Remote | Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
4.3 MEDIUM
CVE-2026-72722 — Discourse: Duplicate lookup reveals restricted topic titles through canonicalized URLs

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_from, TopicLink.ensure_entry_for, and TopicLink.duplicate_lookup do not consist…

Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.3 MEDIUM
CVE-2026-72721 — Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChecker.is_blocked? compares hostnames and SiteSetting.blocked_onebox_domains entri…

Remote | Misconfiguration
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.4 MEDIUM
CVE-2026-72720 — Discourse: HTML injection in PrettyText.format_for_email from cooked-attribute reparsing

Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has HTML injection in PrettyText.format_for_email because cooked attribute val…

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.7 MEDIUM
CVE-2026-72719 — Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter

Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts thr…

Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.0 HIGH
CVE-2026-72718 — goose: Arbitrary command execution in goose CLI via `goose review` via git core.fsmonitor

goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather the diff for review without stripping attacker-cont…

| Misconfiguration
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.8 CRITICAL
CVE-2026-66738 — SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization an…

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
4.3 MEDIUM
CVE-2026-56620 — HCL BigFix Mobile is vulnerable to information disclosure

HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting.

Remote | Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.3 CRITICAL
CVE-2026-48158 — use-context-selector was vulnerable to malicious code execution via compromised commits

use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits 9d8481a513b7b0d1c0941b220c69b25…

Remote | Supply Chain
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.5 HIGH
CVE-2026-48048 — XWiki Platform's Livetable results still allow reconstructing password hashes using 768 r…

XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and …

Remote | Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.3 CRITICAL
CVE-2026-47754 — unauthenticated path traversal in Metacat 2.x

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archi…

Remote | Path Traversal
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-72730 — Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript username as HTML, allowing stored cross-site scri…

| Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-72729 — Discourse: Stored XSS in discourse-local-dates plugin

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a …

| Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
Showing 20 of 9966 Results