Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-47659 — Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /j…

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a ca…

Remote | Path Traversal
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.5 MEDIUM
CVE-2026-19243 — HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection

A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component She…

nanobot | Remote | Injection
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-19113 — Unauthenticated denial of service via unbounded request body processing

Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to…

consul | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.8 MEDIUM
CVE-2026-19017 — Consul vulnerable to partial arbitrary file read via Vault Connect CA provider

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentic…

consul | Remote | Misconfiguration
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.2 MEDIUM
CVE-2026-19016 — Authorization bypass for session deletion in the transaction API

Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An auth…

consul | Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-19015 — Uncontrolled resource consumption in the Consul Connect CA roots endpoint

Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow…

consul | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.3 MEDIUM
CVE-2026-19014 — Uncontrolled resource consumption in the Consul Connect authorization endpoint

Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow …

consul | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-19012 — Authenticated denial of service in Consul Enterprise-to-Community Edition downgrade path

Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an author…

consul | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-15972 — Unauthenticated denial of service via unbounded external gRPC connection acceptance

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A re…

consul | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.2 MEDIUM
CVE-2026-15970 — L7 intention authorization bypass via custom public listener

Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authent…

consul | Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.8 MEDIUM
CVE-2026-71852 — pypdf: Possible long runtimes/large memory usage for large CID font width ranges

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_w…

pypdf | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.0 CRITICAL
CVE-2026-71851 — crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJ…

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry …

crypto-js | Remote | Cryptography
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
4.8 MEDIUM
CVE-2026-71850 — Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure

Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later re…

hono | Remote | Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
3.7 LOW
CVE-2026-71849 — Hono: Proxy Helper does not remove response headers listed in the `Connection` header

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by …

hono | Remote | Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-71848 — Hono: Algorithmic Complexity DoS in Language Middleware

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service…

hono | Remote | Denial of Service
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
8.7 HIGH
CVE-2026-71847 — Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and cras…

Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and …

javascript_object_notation | Remote | Memory Corruption
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.5 MEDIUM
CVE-2026-70561 — TestLink 1.9.20 and prior Authenticated IDOR via attachmentdownload.php

TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by suppl…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.9 MEDIUM
CVE-2026-69127 — Kirby: System path exposure from error messages in the REST API

Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem pa…

kirby | Remote | Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
2.3 LOW
CVE-2026-66000 — Frappe: Unrestricted access to Document Follow APIs

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing us…

frappe | Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.3 HIGH
CVE-2026-48098 — NexTOR IP Changer Unsafely Uses sudo and shell=True

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using `sudo` and `shell=…

| Misconfiguration
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
Showing 20 of 9837 Results