Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.7 LOW
CVE-2026-15687 — Path traversal via non-tar copyDirectoryFromPod

A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations vi…

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.7 HIGH
CVE-2026-16756 — Allocation of resources without limits in the default aws-smithy-http-server serve() path…

Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial …

Remote | Denial of Service
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
10.0 CRITICAL
CVE-2026-6516 — Remote Code Execution

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

manageengine_adaudit_plus | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-65920 — Diffusers Path Traversal via weight_map Arbitrary File Read

Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malic…

diffusers | Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.7 HIGH
CVE-2026-65919 — Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload

Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly…

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-65918 — PyTorch torchvision GIF Decoder Out-of-bounds Heap Read

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. A…

Remote | Memory Corruption
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.1 MEDIUM
CVE-2026-65763 — Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9 - Improper validation of user inputs lead to a reflective XSS vulnerability.

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.1 MEDIUM
CVE-2026-65762 — Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 1.0.0-6.1.0

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 1.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.8 HIGH
CVE-2026-65702 — Vanna 2.0.2 Path Traversal via FileSystemConversationStore

Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON f…

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.3 CRITICAL
CVE-2026-65701 — SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route

SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltra…

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.8 CRITICAL
CVE-2026-65700 — h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API

h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to t…

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.2 MEDIUM
CVE-2026-65699 — AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation

AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run…

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-47769 — APIFold Vulnerable to Unauthenticated Webhook Event Injection

APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the `/webhooks/:serverS…

Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-47755 — ITFlow Vulnerable to Authenticated Cross-Tenant Credential Disclosure via Unprotected Cre…

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials…

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.9 CRITICAL
CVE-2026-47752 — Tugtainer has Server-Side Template Injection in notification templates that leads to Remo…

Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The …

tugtainer | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.7 HIGH
CVE-2026-47743 — Shopper: Multiple data integrity and disclosure issues in admin Livewire components

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Live…

Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
10.0 CRITICAL
CVE-2026-47668 — DbGate: Unauthenticated Remote Code Execution via JSON Script Runner

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` param…

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.8 MEDIUM
CVE-2026-44210 — Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled P…

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default config…

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.6 MEDIUM
CVE-2026-65010 — Datasets Symlink-following Arbitrary File Write via Extractor.extract()

Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at pred…

| Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.8 HIGH
CVE-2026-63765 — Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant acc…

Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Showing 20 of 9786 Results