Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-15618 — mosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection mechanism

A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecCommand of the file tools/tool_exec.go of the component exec Safety Guard. The manip…

clawlet | Remote | Misconfiguration
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
6.8 MEDIUM
CVE-2026-58489 — HedgeDoc: CSRF in GitHub Gist export callback

HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2  state  value but only checked that it was present rathe…

hedgedoc | Remote | Cross-Site Request Forgery
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
8.3 HIGH
CVE-2026-58486 — HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bomb due to unsafe processing of the note frontmatte…

hedgedoc | Remote | Denial of Service
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
9.1 CRITICAL
CVE-2026-58102 — Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a…

Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via extensions(), extensions_by…

crypt\ | Remote | Memory Corruption
Jul 13, 2026 Aug 11, 2026
Jul 13, 2026
Aug 11, 2026
7.5 HIGH
CVE-2026-58101 — Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL poin…

Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns NULL when an extension's DER value fails to parse. basicC, ia5st…

crypt\ | Remote | Denial of Service
Jul 13, 2026 Aug 11, 2026
Jul 13, 2026
Aug 11, 2026
8.8 HIGH
CVE-2026-57856 — Cockpit CMS Path Traversal via Bucket Name in Bucket File Storage API

Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg…

cockpit | Remote | Path Traversal
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
8.8 HIGH
CVE-2026-57855 — Cockpit CMS Missing Authorization in Bucket File Storage API

Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls…

cockpit | Remote | Authorization
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
4.3 MEDIUM
CVE-2026-15607 — tanstack db Alias Path select.ts select prototype pollution

A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the file src/query/compiler/select.ts of the component Alias Path Handler. The manipu…

db | Remote | Misconfiguration
Jul 13, 2026 Jul 15, 2026
Jul 13, 2026
Jul 15, 2026
3.1 LOW
CVE-2026-15605 — wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity V…

wandb | Remote | Cryptography
Jul 13, 2026 Jul 14, 2026
Jul 13, 2026
Jul 14, 2026
Showing 20 of 11049 Results