Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-82853 — Nodemailer before 8.0.5 SMTP Command Injection via CRLF

Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP command…

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82668 — klaussilveira GitList Git Command Line CommandLine.php getDefaultBranch os command inject…

A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by this vulnerability is the function getDefaultBranch of the file src/SCM/System/Git/CommandLine.php of the compon…

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.8 MEDIUM
CVE-2026-82667 — yaojingang GEOFlow GenericHttpEndpointResolver.php DistributionController.isValidHttpEndp…

A vulnerability has been found in yaojingang GEOFlow up to 2.1.0. Impacted is the function DistributionController.isValidHttpEndpoint of the file app/Services/GeoFlow/GenericHttpEndpointResolver.php.…

Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.8 MEDIUM
CVE-2026-82666 — yaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code inj…

A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue affects the function preview of the file app/Http/Controllers/Admin/SiteThemeEditorController.php of the component Superadmin Theme…

geoflow | Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
4.7 MEDIUM
CVE-2026-82665 — yaojingang GEOFlow Image Library Cleanup ImageLibraryController.php unlink path traversal

A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink of the file app/Http/Controllers/Admin/ImageLibraryController.php of the component Image…

geoflow | Remote | Path Traversal
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.0 MEDIUM
CVE-2026-82664 — yaojingang GEOFlow JSON-LD Theme HomeController.php cross site scripting

A security vulnerability has been detected in yaojingang GEOFlow up to 2.1.0. This affects an unknown part of the file app/Http/Controllers/Site/HomeController.php of the component JSON-LD Theme Hand…

geoflow | Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
6.5 MEDIUM
CVE-2026-82662 — Nodemailer before 8.0.8 TLS Certificate Validation Bypass

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in…

Remote | Misconfiguration
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.4 MEDIUM
CVE-2026-82661 — Nodemailer CRLF Injection via List-* Header Comments

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*…

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.4 MEDIUM
CVE-2026-82660 — Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess

Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path o…

Remote | Path Traversal
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.1 HIGH
CVE-2026-82659 — nodemailer before 9.0.1 File Read and SSRF via raw option

nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side reques…

Remote | Path Traversal
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-81624 — Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buf…

Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.4 CRITICAL
CVE-2026-19410 — Google Cloud Build Comment Control Bypass via Webhook Suppression

An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in th…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.3 MEDIUM
CVE-2024-58379 — nodemailer before 6.9.9 ReDoS via attachDataUrls parameter

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send…

Remote | Denial of Service
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
6.4 MEDIUM
CVE-2026-82838 — Default webserver configuration with incorrect CSP

The default docker image shipped for Venueless did not properly ensure that uploaded SVG files could not be delivered with executable JavaScript content. A valid Content Security Policy is now set.

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
2.2 LOW
CVE-2026-82631 — valkey-io valkey Blocked-on-keys blocked.c handleClientsBlockedOnKey use after free

A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The…

valkey | Remote | Memory Corruption
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82630 — PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection…

A vulnerability was identified in PowerJob up to 5.1.2. Impacted is the function MuConnectionManager.getOrCreateConnection of the file powerjob-server/powerjob-server-starter/src/main/java/tech/power…

powerjob | Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.8 MEDIUM
CVE-2026-82629 — jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller…

A vulnerability was determined in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This issue affects the function MyJwWebJwid3Controller.doUpload of the file jeewx-boot-module-we…

jeewx-boot | Remote | Misconfiguration
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.9 MEDIUM
CVE-2026-58301 — Apache Shiro: Server-side POST request may be steered to an alternate host

When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate a connection to an attacker-controlled URL and tra…

shiro | Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.3 CRITICAL
CVE-2026-82628 — Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges management

A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation…

| Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.0 MEDIUM
CVE-2026-82625 — code-projects Simple Inventory System User Registration register.php cross site scripting

A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an unknown part of the file /register.php of the component User Registration. Such manipulation of the argume…

simple_inventory_system | Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
Showing 20 of 11973 Results