Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-19763 — DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path trav…

A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This mani…

taier | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
0.0 NA
CVE-2026-19762 — DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal

A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the component Chunk-Check Endpoint. The manipulation …

taier | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
0.0 NA
CVE-2026-19761 — DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename p…

A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the file UploadController.java of the component Upload Controller. The manipulatio…

taier | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-19758 — dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal

A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of the component chunk-check endpoint. Executing a m…

lamp-cloud | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-19756 — Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal

A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Such manipulation of the argu…

lamp-cloud | Remote | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.5 HIGH
CVE-2026-19753 — Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side requ…

A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing …

Remote | Server-Side Request Forgery
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-19757 — Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversal

A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the component File-Upload Controller. Performing a manip…

lamp-cloud | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
9.6 CRITICAL
CVE-2026-73843 — OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gatewa…

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable …

| Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
9.0 CRITICAL
CVE-2026-73842 — OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not r…

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ …

| Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-73841 — OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo opench…

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go…

Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.3 MEDIUM
CVE-2026-73840 — OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook si…

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webho…

Remote | Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-73667 — OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates en…

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ i…

Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.2 HIGH
CVE-2026-73666 — OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog dat…

OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.gue…

Remote | Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
9.3 CRITICAL
CVE-2026-73665 — FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass an…

FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the…

Remote | Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.6 HIGH
CVE-2026-73664 — FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module

FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/ast…

Remote | Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
9.3 CRITICAL
CVE-2026-73663 — FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name l…

FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in …

Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.6 HIGH
CVE-2026-73662 — Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files

FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConf…

Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.6 HIGH
CVE-2026-73661 — FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup

FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() i…

Remote | Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.5 HIGH
CVE-2026-73660 — FreePBX: Authenticated TTS AGI Command Injection Through TTS Name

FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage…

Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.1 HIGH
CVE-2026-73659 — Trigger.dev: Cross-tenant object read/write via path traversal in packet presign API

Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controll…

Remote | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
Showing 20 of 10656 Results