Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.1 LOW
CVE-2026-44915 — Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulnerable to phishing and credential theft. This issue…

apisix | Remote | Misconfiguration
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
5.3 MEDIUM
CVE-2026-44087 — Apache APISIX: Openid-connect plugin Identity Header Spoofing

Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack surface that allows the attacker to spoof identity …

apisix | Remote | Authentication
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
0.0 NA
CVE-2026-49357 — Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication

Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop application on Windows or Mac via MCP. `line-desktop-mc…

Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
5.3 MEDIUM
CVE-2026-47339 — Apache APISIX: authz-casdoor incorrect session sharing

Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different so…

apisix | Remote | Authorization
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
2.3 LOW
CVE-2026-44046 — Apache APISIX: wolf-rbac plugin Identity Spoofing

Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed identity information a…

apisix | Remote | Misconfiguration
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.0 HIGH
CVE-2026-39999 — Apache APISIX: JWT Algorithm Confusion allows authentication bypass

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apac…

apisix | Remote | Authentication
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
9.1 CRITICAL
CVE-2026-48137 — Untrusted pointer dereference in NI grpc-device sideband streaming API

There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remo…

Remote | Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
5.8 MEDIUM
CVE-2026-39998 — Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup

Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX:…

apisix | Remote | Authentication
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.7 HIGH
CVE-2026-4026 — FlexNet Manager Suite Privilege Escalation Vulnerability

A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to account settings to escalate their privileges to Administ…

Remote | Authorization
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
9.4 CRITICAL
CVE-2026-44939 — Command injection through unsanitized YAML parameter in Rancher

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to…

rancher | Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
10.0 CRITICAL
CVE-2026-50242 — JetBrains Hub Authentication Bypass

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was p…

hub | Remote | Authentication
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
9.9 CRITICAL
CVE-2026-56142 — JetBrains Hub Authentication Privilege Escalation

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible

hub | Remote | Authentication
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
9.8 CRITICAL
CVE-2026-56141 — JetBrains Hub Account Takeover

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible

hub | Remote | Authentication
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.1 HIGH
CVE-2026-53915 — JetBrains GoLand: Remote Code Execution via Untrusted Project Configuration

In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

goland | Remote | Misconfiguration
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
6.5 MEDIUM
CVE-2026-12706 — Ffmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()

A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed buffer, but a subsequent reallocation of that same b…

openshift_ai enterprise_linux_ai | Remote | Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
5.6 MEDIUM
CVE-2026-11941 — Use-after-free in connection ID iterator and FFI functions

Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions w…

quiche | Remote | Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
0.0 NA
CVE-2026-41156 — GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding …

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources creating a write use after free scenario. A shared resource (memory pa…

| Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
0.0 NA
CVE-2026-34192 — GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading to UAF of GPU page tables. The vulnerability allows physical memory allocat…

| Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
5.6 MEDIUM
CVE-2026-8296 — Octopus Server Artifact Cross-Site Scripting

In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.

Remote | Cross-Site Scripting
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.5 HIGH
CVE-2026-11576 — eclipse-threadx NetX Duo HTTP Server fx_file_close Uninitialized Handle Vulnerability

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally cal…

threadx_netx_duo | Remote | Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
Showing 20 of 7563 Results