Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2025-63235 — Sol Broker Resource Exhaustion Denial of Service

In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeate…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-66058 — Frappe: Unrestricted access to a Document Follow API

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixe…

frappe | Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.9 HIGH
CVE-2026-64638 — WordPress Reflected Cross-Site Scripting Vulnerability

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be es…

wordpress | Remote | Cross-Site Scripting
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.9 CRITICAL
CVE-2026-64637 — Plesk XML-RPC API Privilege Escalation

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.

Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.7 HIGH
CVE-2026-64636 — Plesk SQL Injection Vulnerability

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.

Remote | Injection
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.5 MEDIUM
CVE-2026-56818 — Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the ma…

netty | Remote | Denial of Service
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
6.5 MEDIUM
CVE-2026-47364 — Datadog Android Information Disclosure via Firebase Crashlytics

In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash…

Remote | Information Disclosure
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
6.3 MEDIUM
CVE-2026-47363 — Datadog Android Application Improper Intent Handling and Session Injection Vulnerability

In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no…

Remote | Authentication
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
4.6 MEDIUM
CVE-2026-47362 — Datadog Android Application Sensitive Data Exposure via Unencrypted SQLite Databases

In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, reci…

| Misconfiguration
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
6.4 MEDIUM
CVE-2026-47361 — Datadog Android Application Notification Denial of Service Vulnerability

In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the …

Remote | Denial of Service
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
5.5 MEDIUM
CVE-2026-44965 — Datadog Android App Widget Unauthorized Activity Exposure

In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCall…

| Authentication
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
6.5 MEDIUM
CVE-2026-44964 — Datadog Android Application Improper Activity Export Vulnerability

In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-co…

Remote | Authorization
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
5.5 MEDIUM
CVE-2026-19229 — SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information d…

A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executin…

online_clothing_store | Remote | Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.3 MEDIUM
CVE-2026-19213 — WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow

A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCore/TraderAdapter.h of the component Pending Order Handler. The manipulation of …

wondertrader | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-19082 — Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via str…

Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII …

imager imager | Remote | Memory Corruption
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.3 MEDIUM
CVE-2026-71557 — go-git: Malicious reference names may modify files outside the reference storage

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the refe…

go-git | Remote | Path Traversal
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.1 HIGH
CVE-2026-71556 — go-git: Worktree operations may follow symlinks

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the w…

go-git | Remote | Path Traversal
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.5 HIGH
CVE-2026-68772 — ZenML 0.94.6 Remote Code Execution via CloudpickleMaterializer

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by pl…

zenml | Remote | Supply Chain
Aug 07, 2026 Aug 08, 2026
Aug 07, 2026
Aug 08, 2026
8.7 HIGH
CVE-2026-67585 — Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation

Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted _entities representat…

absinthe_federation | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-66062 — SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept hea…

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for head…

kit | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
Showing 20 of 9994 Results