Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-61824 — Defuddle: XSS via unescaped attribute interpolation in site extractors

Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriat…

defuddle | Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
10.0 CRITICAL
CVE-2026-61539 — Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/mode…

xinference | Remote | Injection
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.2 CRITICAL
CVE-2026-59989 — Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE)

Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the join filter by inserting the raw separator and ar…

Remote | Injection
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
5.1 MEDIUM
CVE-2026-55185 — Miniflux 2: Open Redirect Bypass

Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets containing backslashes because Go URL parsing treats them as path character…

miniflux | Remote | Server-Side Request Forgery
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.5 MEDIUM
CVE-2026-55168 — Runtipi: Authenticated arbitrary file write via backup restore symlink planting

Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and copies them into live application paths during the …

runtipi | Remote | Path Traversal
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.7 HIGH
CVE-2026-54457 — TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal object storage …

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_stor…

Remote | Server-Side Request Forgery
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.3 MEDIUM
CVE-2026-53656 — FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-o…

FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone/server/app.py and the /media route in fiftyone/se…

| Information Disclosure
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
5.9 MEDIUM
CVE-2026-53572 — KEDA: PostgreSQL connection string parameter injection via incomplete whitespace escaping

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection strings from tenant-controlled host, port, userName,…

Remote | Injection
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-50538 — libvncclient Tight decoder has an attacker-controlled heap out-of-bounds write

LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write atta…

libvncserver | Remote | Memory Corruption
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
5.5 MEDIUM
CVE-2026-45271 — picotls has infinite recursion in the minicrypto ASN.1 decoder

Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. Picotls implements its own ASN.1 validation helper, which is used by the minicrypto backe…

picotls | Denial of Service
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.9 MEDIUM
CVE-2026-45099 — Terragrunt: Arbitrary File Deletion via Malicious Module Manifest

Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt trusts paths decoded from a downloaded module's .t…

Remote | Supply Chain
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.3 MEDIUM
CVE-2026-44517 — Buildah: Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub…

Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confine Git repository subdirectories to the downloaded…

| Misconfiguration
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.0 HIGH
CVE-2026-31880 — Combodo iTop: Reflected XSS in universal search

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. This issue has been fixed in version 3.2…

itop | Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.0 HIGH
CVE-2026-31803 — Combodo iTop: Reflected XSS in tag admin

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This issue has been fixed in versio…

itop | Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.0 HIGH
CVE-2026-30890 — Combodo iTop: Reflected XSS in synchro/synchro_import.php

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import script. This issue has been fixed in versio…

itop | Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.1 HIGH
CVE-2026-30865 — Combodo iTop: Reflected XSS in dashboard save

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboard save functionality. This issue has been fixed in…

itop | Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.0 HIGH
CVE-2026-30826 — Combodo iTop: Reflected XSS in run_query.php

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing OQL query functionality. This issue has been fixed…

itop | Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.9 CRITICAL
CVE-2026-77810 — Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector

In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, …

athena_federated_query_neptune_connector | Remote | Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
5.9 MEDIUM
CVE-2026-76876 — Craftplan < 0.5.1 Broken Access Control Information Disclosure via Settings API

Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiting an unconditional authorization policy on the Se…

Remote | Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.6 HIGH
CVE-2026-74252 — Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20,…

Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the g…

Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
Showing 20 of 11538 Results