Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-73246 — Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and…

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authenticatio…

kestra | Remote | Information Disclosure
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-73245 — Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /logger…

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentic…

kestra | Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.8 CRITICAL
CVE-2026-68067 — Mira Hormone Monitor, Mira Android App Weak Authentication

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker…

Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.1 CRITICAL
CVE-2026-67568 — Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction …

Remote | Information Disclosure
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.4 HIGH
CVE-2026-67558 — Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing

The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authenti…

| Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.8 HIGH
CVE-2026-66875 — Mira Hormone Monitor, Mira Android App Missing authentication for critical function

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-con…

| Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.3 MEDIUM
CVE-2026-66340 — Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication a…

The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods t…

Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-66098 — Mira Hormone Monitor, Mira Android App Missing authentication for critical function

The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-servi…

| Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.3 MEDIUM
CVE-2026-64934 — Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision

The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated…

Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.6 CRITICAL
CVE-2026-5917 — libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands…

libgit2 | Remote | Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.5 HIGH
CVE-2026-29036 — cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers…

cjson | Remote | Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-19560 — Google Chrome Blink Use After Free

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-19559 — Google Chrome HTML Use-After-Free Vulnerability

Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-19558 — Google Chrome Extensions Use-After-Free Vulnerability

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafte…

chrome chrome | Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-19557 — Google Chrome TabStrip Use-After-Free Sandbox Escape

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTM…

chrome chrome | Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-19556 — Google Chrome V8 Use-After-Free Vulnerability

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-18710 — Cleartext Storage of Sensitive Information in MongoDB Driver Logging During Client Initia…

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client…

| Information Disclosure
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-71290 — Apache HttpComponents Client: TLS hostname verification silently disabled on the async tr…

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient.…

httpclient | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-66832 — Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query str…

When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier …

Remote | Information Disclosure
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.3 HIGH
CVE-2026-66154 — GMS Insufficient Certificate Validation Vulnerability

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack a…

global_management_system | Misconfiguration
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
Showing 20 of 10827 Results