Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-69247 — cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through dis…

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reporte…

Remote | Cryptography
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-67977 — F' framework FileDownlink Integer Overflow Denial of Service

An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-67975 — NASA cFS Incorrect Access Control Vulnerability

Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.

| Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-67974 — NASA cFS Software Bus Network Denial of Service Vulnerability

A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted …

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-67973 — NASA cFS CFDP Denial of Service Vulnerability

An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-67970 — NASA cFS Path Traversal Vulnerability

Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.

| Path Traversal
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-67969 — NASA cFS Health and Safety Component Denial of Service Vulnerability

An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
4.8 MEDIUM
CVE-2026-67617 — Microweber CMS 2.0.20 Stored XSS via tag_names Parameter

Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting…

Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
4.3 MEDIUM
CVE-2026-67616 — Camaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint

Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by b…

Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.3 MEDIUM
CVE-2026-48115 — Misskey: Improper Authorization in the Announcements API

Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in the Server Announcements API whe…

Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.9 HIGH
CVE-2026-47746 — Misskey: JSON-LD signature validation + compaction is vulnerable to timing attacks

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction …

Remote | Race Condition
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.1 MEDIUM
CVE-2026-46714 — Misskey: Denial of Service via Uncontrolled Recursion in Theme Compilation

Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey web client to slow down or crash when…

Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.2 CRITICAL
CVE-2026-46713 — Misskey: JSON-LD signature validation + compaction may lead to improper activity handling

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that …

Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
2.3 LOW
CVE-2026-46712 — Misskey: Lack of proper permission checks in Direct Messaging feature

Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certa…

Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
3.1 LOW
CVE-2026-18682 — OpenAkita File Upload API upload cross site scripting

A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload API. The manipulation of the argument File…

Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.2 HIGH
CVE-2026-10849 — Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response bo…

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). T…

zephyr zephyr | Remote | Memory Corruption
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.2 HIGH
CVE-2026-69246 — Guzzle: Noncanonical host can bypass host-based checks

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the …

Remote | Server-Side Request Forgery
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.5 MEDIUM
CVE-2026-69245 — Guzzle: Noncanonical cookie domain keeps subdomain scope

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Do…

Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.1 HIGH
CVE-2026-69244 — AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked …

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a …

Remote | Memory Corruption
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.3 MEDIUM
CVE-2026-69243 — AIOHTTP: HTTP request smuggling via WebSocket upgrade

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If usin…

Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
Showing 20 of 9396 Results