Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-73501 — kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticat…

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenti…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.7 HIGH
CVE-2026-73500 — etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connec…

Remote | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.1 HIGH
CVE-2026-73499 — etcd: Watch API authorization bypass via open-ended range requests

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC AP…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.7 HIGH
CVE-2026-73498 — MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path val…

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to ope…

Remote | Path Traversal
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.4 HIGH
CVE-2026-73495 — blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-e…

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.head…

Remote | Misconfiguration
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.5 HIGH
CVE-2026-73493 — http4s-blaze-server: Unbounded WebSocket message aggregation

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with …

Remote | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
2.3 LOW
CVE-2026-73492 — Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character refer…

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject j…

Remote | Misconfiguration
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-71846 — Insights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch …

A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a …

Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.5 HIGH
CVE-2026-71473 — Acm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enable…

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configura…

Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.0 CRITICAL
CVE-2026-71471 — Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated…

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerabilit…

advanced_cluster_management_for_kubernetes | Remote | Misconfiguration
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.5 HIGH
CVE-2026-71469 — Acm-search-v2-api-rhel9: search-v2-api: unbounded tokenreviews cache allows unauthenticat…

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded toke…

advanced_cluster_management_for_kubernetes | Remote | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.8 HIGH
CVE-2026-19003 — MongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dia…

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems fr…

| Memory Corruption
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-18750 — CVE-2026-18750

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-a…

| Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-18749 — CVE-2026-18749

The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retriev…

| Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
0.0 NA
CVE-2026-18744 — CVE-2026-18744

Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership of kwargs['me…

| Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-18727 — Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing

A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsin…

enterprise_linux enterprise_linux | Denial of Service
Aug 12, 2026 Aug 13, 2026
Aug 12, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-18726 — Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted…

enterprise_linux enterprise_linux | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.2 HIGH
CVE-2026-17485 — IBM i is Affected By Denial of Service Vulnerability []

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.

i i | Remote | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.4 HIGH
CVE-2026-10534 — IBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parser

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

db2 | Memory Corruption
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
10.0 CRITICAL
CVE-2024-27253 — IBM Engineering Requirements Management DOORS Next is impacted by vulnerability in Review…

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

doors_next | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
Showing 20 of 11038 Results