Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-74583 — net/sched: cls_route: fix fastmap use-after-free on filter

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix fastmap use-after-free on filter The route4 classifier maintains a 16-slot fastmap cache that stores ra…

| Race Condition
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-74582 — packet: use consistent hard_header_len in non-ring send paths

In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring send paths packet_snd() reads dev->hard_header_len multiple times while alloca…

| Memory Corruption
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-74581 — net: ipv6: clear suppressed fib6 rule result

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves re…

| Memory Corruption
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-74580 — vhost: reset the vring metadata cache on vring reconfiguration

In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring metadata cache on vring reconfiguration vq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring …

| Memory Corruption
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.2 CRITICAL
CVE-2026-39909 — llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handler

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by s…

Remote | Memory Corruption
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.5 HIGH
CVE-2026-75933 — Jet Admin Stored XSS

Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the context of any visiting user's domain.

Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.2 CRITICAL
CVE-2026-75932 — Jet Admin tenant isolation failure

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once…

Remote | Authentication
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.9 MEDIUM
CVE-2026-75928 — Brushfire unauthenticated information disclosure

The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information…

Remote | Information Disclosure
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
10.0 CRITICAL
CVE-2026-69502 — Azure SQL Database Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.5 HIGH
CVE-2026-54789 — mod_auth_openidc has out-of-bounds read and write in state cookie parsing

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an ou…

mod_auth_openidc | Remote | Memory Corruption
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.1 HIGH
CVE-2026-49114 — ONNX symlink-following and path-traversal arbitrary file write

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a…

| Path Traversal
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.5 HIGH
CVE-2026-22681 — OpenViking < 0.3.4 SSRF via /api/v1/resources

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the …

openviking | Remote | Server-Side Request Forgery
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.7 HIGH
CVE-2026-77815 — Infinite Image Browsing Resolves Paths With normpath, Allowing Symlink Escape From Scanne…

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory t…

Remote | Path Traversal
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.7 HIGH
CVE-2026-77814 — Infinite Image Browsing is_path_trusted Prefix Comparison Omits the Trailing Path Separat…

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name m…

Remote | Path Traversal
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.4 CRITICAL
CVE-2026-77812 — Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE

DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the d…

mavic_3 mini_2 | Information Disclosure
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.6 CRITICAL
CVE-2026-77087 — Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that…

Remote | Authentication
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-75501 — CVE-2026-75501

A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port‑forwarding rules via the UPnP WANIPConnection servi…

| Misconfiguration
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.9 CRITICAL
CVE-2026-63343 — Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access a…

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incu…

Remote | Path Traversal
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.9 CRITICAL
CVE-2026-63125 — Incus vulnerable to root RCE via image backup.yaml symlink

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_i…

Remote | Path Traversal
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.9 CRITICAL
CVE-2026-62941 — Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in con…

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the sour…

Remote | Misconfiguration
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
Showing 20 of 11703 Results