Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.1 LOW
CVE-2026-55825 — Contao: Possible path traversal in job download URIs

Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segments and make the job attac…

contao | Remote | Authorization
Jul 31, 2026 Aug 01, 2026
Jul 31, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-53599 — Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to…

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with m…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.9 MEDIUM
CVE-2026-53551 — free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server Function) does not validate the supiOrSuci field in UE authentication requests…

free5gc | Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.1 HIGH
CVE-2026-53510 — Savon::Model evaluates WSDL operation names as Ruby source

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code exe…

Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-38711 — TOTOLINK Routers Command Injection Vulnerability

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulner…

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.4 HIGH
CVE-2026-18394 — Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration

Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LL…

strands_agents_tools | Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.1 LOW
CVE-2026-57232 — Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Mo…

Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderController::getResponse() to…

contao | Remote | Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
2.6 LOW
CVE-2026-55824 — Contao crawler leaks auth credentials to external hosts

Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP…

contao | Remote | Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-53505 — Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform …

Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-53504 — Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing…

Remote | Denial of Service
Jul 31, 2026 Aug 01, 2026
Jul 31, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-53503 — Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> valu…

Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.7 HIGH
CVE-2026-53502 — Thumbor has path traversal via post-validation URL decoding bypass in file_loader

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_L…

Remote | Path Traversal
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.2 HIGH
CVE-2026-53501 — Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signat…

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the UR…

Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.2 HIGH
CVE-2026-53500 — Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypa…

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at …

Remote | Misconfiguration
Jul 31, 2026 Aug 01, 2026
Jul 31, 2026
Aug 01, 2026
3.7 LOW
CVE-2026-25552 — Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header

Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a miscon…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.3 HIGH
CVE-2026-18481 — Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative cont…

aws_ops_wheel | Remote | Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.7 MEDIUM
CVE-2026-18321 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec

Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd

ntpsec | Memory Corruption
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.7 HIGH
CVE-2026-55100 — hashi-vault-js has a path traversal and query parameter injection

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and versi…

Remote | Path Traversal
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.3 HIGH
CVE-2026-54737 — @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merg…

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filterin…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.7 HIGH
CVE-2026-54729 — dssrf: any users using 1.1.1.1 DNS is impacted by SSRF

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN…

Remote | Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
Showing 20 of 9421 Results