Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-46595 — Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/s…

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would…

crypto | Remote | Authorization
May 22, 2026 May 28, 2026
May 22, 2026
May 28, 2026
9.1 CRITICAL
CVE-2026-42508 — Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

crypto | Remote | Cryptography
May 22, 2026 May 28, 2026
May 22, 2026
May 28, 2026
5.3 MEDIUM
CVE-2026-39835 — Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an…

crypto | Remote | Authentication
May 22, 2026 May 28, 2026
May 22, 2026
May 28, 2026
9.1 CRITICAL
CVE-2026-39834 — Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh

When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty pack…

crypto | Remote | Denial of Service
May 22, 2026 May 28, 2026
May 22, 2026
May 28, 2026
9.1 CRITICAL
CVE-2026-39833 — Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent

The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indicatio…

crypto | Remote | Authentication
May 22, 2026 May 28, 2026
May 22, 2026
May 28, 2026
9.1 CRITICAL
CVE-2026-39832 — Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forward…

crypto | Remote | Misconfiguration
May 22, 2026 May 28, 2026
May 22, 2026
May 28, 2026
9.1 CRITICAL
CVE-2026-39831 — Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch …

crypto | Remote | Authentication
May 22, 2026 Jun 02, 2026
May 22, 2026
Jun 02, 2026
9.1 CRITICAL
CVE-2026-39830 — Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto…

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), r…

crypto | Remote | Denial of Service
May 22, 2026 Jun 02, 2026
May 22, 2026
Jun 02, 2026
7.5 HIGH
CVE-2026-39829 — Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumptio…

crypto | Remote | Denial of Service
May 22, 2026 Jun 02, 2026
May 22, 2026
Jun 02, 2026
6.3 MEDIUM
CVE-2026-39828 — Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as forc…

crypto | Remote | Authentication
May 22, 2026 Jun 02, 2026
May 22, 2026
Jun 02, 2026
6.5 MEDIUM
CVE-2026-39827 — Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users.…

crypto | Remote | Denial of Service
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
9.3 CRITICAL
CVE-2026-9264 — Cross-Site Scripting in SketchUp Dynamic Components

A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerabil…

sketchup | Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.7 HIGH
CVE-2026-34911 — "UniFi OS Path Traversal Disclosure"

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulat…

Remote | Path Traversal
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
10.0 CRITICAL
CVE-2026-34910 — "UniFi OS Command Injection Vulnerability"

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Remote | Injection
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
10.0 CRITICAL
CVE-2026-34909 — "UniFi OS Path Traversal Vulnerability"

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an und…

Remote | Path Traversal
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
10.0 CRITICAL
CVE-2026-34908 — "UniFi OS Improper Access Control Vulnerability"

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
9.1 CRITICAL
CVE-2026-33000 — "UniFi OS Command Injection Vulnerability"

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Remote | Injection
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.5 MEDIUM
CVE-2026-8435 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concret…

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CMS security team gave this vulnerability a CVSS v.4…

concrete_cms | Remote | Cross-Site Request Forgery
May 21, 2026 May 22, 2026
May 21, 2026
May 22, 2026
8.8 HIGH
CVE-2026-8434 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concret…

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulnerability a CVSS v.4…

concrete_cms | Remote | Cross-Site Request Forgery
May 21, 2026 May 26, 2026
May 21, 2026
May 26, 2026
8.8 HIGH
CVE-2026-8433 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concret…

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score…

concrete_cms | Remote | Cross-Site Request Forgery
May 21, 2026 May 26, 2026
May 21, 2026
May 26, 2026
Showing 20 of 6714 Results