Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.0 HIGH
CVE-2026-78553 — Insecure Flask Secret-Key File Permissions Allow Local Administrator Session Forgery in R…

RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was created using the process's default permissions and umask, resulting in p…

| Misconfiguration
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-78551 — RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authen…

RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and …

Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.3 MEDIUM
CVE-2026-78430 — sworddut mcp-ffmpeg-helper Tool handlers.ts handleToolCall os command injection

A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulatio…

| Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
4.3 MEDIUM
CVE-2026-77923 — Dolibarr 21.0.0 < 24.0.0 Authorization Bypass via clonetasks Mass Action

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler …

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.3 MEDIUM
CVE-2026-77310 — jackson-databind: Eager DNS resolution (SSRF) still present in InetAddress deserializatio…

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective rele…

Remote | Server-Side Request Forgery
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
3.5 LOW
CVE-2026-76816 — Netty: MQTT Topic Name and Client ID Validation Bypass

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and P…

| Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-76098 — Mistune has Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens f…

Remote | Denial of Service
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.5 MEDIUM
CVE-2026-75509 — joserfc claim-validation bypass via array-typed single-string claims (iss/sub/jti)

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to li…

Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-75369 — SpaceDot AcubeSAT OBC Out-of-Bounds Read

An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS)…

| Denial of Service
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-75368 — SpaceDot AcubeSAT OBC Stack Overflow

A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted ECSS TC message.

| Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.3 MEDIUM
CVE-2026-72714 — Rocq Prover through 9.2.0 Universe Checking State Desynchronised After Module Close

Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local Unset Universe Checking inside a module is expected…

| Misconfiguration
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.3 MEDIUM
CVE-2026-72711 — Lean 4 before 4.32.2 Kernel Accepts Opaque Declaration With an Unbound Free Variable

The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and theorem paths perform, so a …

| Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.3 MEDIUM
CVE-2026-72705 — Rocq Prover before 9.2.0 Guard Checker Accepts Fixpoint Passed as a Higher-Order Argument

The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass itself as a higher-order argument to a second fixpoint, which then applie…

| Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.3 MEDIUM
CVE-2026-72704 — Rocq Prover through 9.2.0 Guard Checker Trusts Corrupted Recursive Tree After Transport

The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by transport. A fixpoint may apply a rewrite a…

| Misconfiguration
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.3 MEDIUM
CVE-2026-72703 — Rocq Prover 8.20 before 9.2.0 Guard Checker Accepts Non-Terminating Fixpoint via Unchecke…

The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that fixpoint. find_uniform_parameters in kernel/ind…

| Misconfiguration
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.5 MEDIUM
CVE-2026-71511 — Dolibarr < 24.0.0 Members REST API Sensitive Data Exposure via Member Endpoints

Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by qu…

Remote | Information Disclosure
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.5 MEDIUM
CVE-2026-71510 — Dolibarr < 24.0.0 Users REST API SQL Injection via filter parameter

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter …

Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.6 MEDIUM
CVE-2026-63693 — Dell BIOS Improper Link Resolution Arbitrary Write Vulnerability

Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, le…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.8 HIGH
CVE-2026-61419 — Dell ThinOS Improper Access Control Vulnerability

Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to …

thinos | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.3 MEDIUM
CVE-2020-37268 — Coq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Para…

Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a fun…

| Misconfiguration
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11531 Results