Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-66041 — FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/S…

Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-66040 — FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a…

Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-66039 — FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file…

Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
7.1 HIGH
CVE-2026-66038 — FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a …

Remote | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
7.1 HIGH
CVE-2026-66037 — FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory a…

Remote | Denial of Service
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-66036 — FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whos…

Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
9.3 CRITICAL
CVE-2026-62835 — Azure Portal Information Disclosure Vulnerability

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
5.4 MEDIUM
CVE-2026-57531 — Milkdown < 7.21.3 DOM XSS via innerHTML Assignment

Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host applic…

Remote | Cross-Site Scripting
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
5.4 MEDIUM
CVE-2026-57530 — Milkdown < 7.21.3 Stored XSS via javascript: URL in link href

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to ex…

Remote | Cross-Site Scripting
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.1 HIGH
CVE-2026-54342 — TLS Certificate Verification Disabled on CXF Transport Clients in epa4all

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept…

| Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.3 MEDIUM
CVE-2026-48037 — Hulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDu…

Remote | Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.4 HIGH
CVE-2026-48036 — Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see…

Remote | Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
7.1 HIGH
CVE-2026-48035 — Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS acco…

Remote | Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.5 HIGH
CVE-2026-48034 — HULUMI-H5 bypass via decoy sibling resources targeting a different bucket

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting …

Remote | Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.4 HIGH
CVE-2026-48033 — Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logi…

Remote | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.3 HIGH
CVE-2026-48032 — Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role tru…

Remote | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-48021 — epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname …

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain t…

Remote | Cryptography
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.5 HIGH
CVE-2026-17107 — Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants clus…

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation…

multicluster_engine_for_kubernetes | Remote | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
7.7 HIGH
CVE-2026-66035 — libssh2 Heap Buffer Overflow via ETM Cipher Negotiation

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client …

Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
7.7 HIGH
CVE-2026-66034 — libssh2 Heap Out-of-Bounds Read via publickey subsystem

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of …

Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
Showing 20 of 9485 Results