Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2026-48098 — NexTOR IP Changer Unsafely Uses sudo and shell=True

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using `sudo` and `shell=…

| Misconfiguration
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.8 HIGH
CVE-2026-48097 — NexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command Execution

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of…

| Injection
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-19231 — SourceCodester Simple Doctors Appointment System ajax.php delete_appointment sql injection

A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipul…

simple_doctors_appointment_system | Remote | Injection
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.0 MEDIUM
CVE-2026-19230 — SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cross site scri…

A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /social/ajax.php?action=save_upload of the component Comment Input Box. The manipula…

photo_share_website | Remote | Cross-Site Scripting
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-17435 — File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlink…

File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link to a missing file, and the touch option…

| Path Traversal
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.3 HIGH
CVE-2026-11430 — Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit

Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookToken is configured, a compound conditional short-c…

Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2025-71413 — In CPDLC, Malformed or Out of Sequence Frames Can Cause Resets

Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced situational awareness. This t…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.1 HIGH
CVE-2025-71412 — In CPDLC, False Emergency or Status Messages Will be Accepted as Legitimate

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and groun…

Remote | Injection
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2025-71411 — In CPDLC, Broadcast Control Frames Can Disconnect Multiple Aircraft Simultaneously

Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio …

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2025-71410 — Malicious Link Control Frames Can Cause Loss of CPDLC Functions

Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.1 HIGH
CVE-2025-71409 — No Authentication for Very High Frequency Data Link messages used in CPDLC

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. T…

Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2025-63235 — Sol Broker Resource Exhaustion Denial of Service

In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeate…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-66058 — Frappe: Unrestricted access to a Document Follow API

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixe…

frappe | Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.9 HIGH
CVE-2026-64638 — WordPress Reflected Cross-Site Scripting Vulnerability

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be es…

wordpress | Remote | Cross-Site Scripting
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.9 CRITICAL
CVE-2026-64637 — Plesk XML-RPC API Privilege Escalation

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.

Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.7 HIGH
CVE-2026-64636 — Plesk SQL Injection Vulnerability

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.

Remote | Injection
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.5 MEDIUM
CVE-2026-56818 — Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the ma…

netty | Remote | Denial of Service
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
6.5 MEDIUM
CVE-2026-47364 — Datadog Android Information Disclosure via Firebase Crashlytics

In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash…

Remote | Information Disclosure
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
6.3 MEDIUM
CVE-2026-47363 — Datadog Android Application Improper Intent Handling and Session Injection Vulnerability

In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no…

Remote | Authentication
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
4.6 MEDIUM
CVE-2026-47362 — Datadog Android Application Sensitive Data Exposure via Unencrypted SQLite Databases

In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, reci…

| Misconfiguration
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
Showing 20 of 9930 Results