Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-78417 — Devolutions Remote Desktop Manager IronVNC Improper Authentication Verification

Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept an…

remote_desktop_manager | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.5 HIGH
CVE-2026-78541 — Command Injection in Parent Control of TP-Link Archer BE3600 v1

A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile …

| Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.7 HIGH
CVE-2026-9254 — Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices

An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special c…

| Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.1 MEDIUM
CVE-2026-78475 — Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checki…

enterprise_linux enterprise_linux | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.5 HIGH
CVE-2026-76838 — Hi.Events before 1.11.1-beta Server-Side Request Forgery via Unvalidated Webhook Redirects

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethost…

Remote | Server-Side Request Forgery
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.4 MEDIUM
CVE-2026-76837 — Baserow before 2.3.0 Stored Cross-Site Scripting via Rich Text Mention Display Name

Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer in web-fron…

Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-76836 — AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Gr…

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is a…

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.3 CRITICAL
CVE-2026-76835 — OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri Under the De…

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy…

Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-76073 — Label Studio through 1.23.0 Cross-Organization Annotation Access via Unscoped AnnotationA…

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides …

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.3 HIGH
CVE-2026-76072 — Continue CLI through 1.5.47 Incomplete Destructive Command Denylist in Headless and Auto …

The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattended. In headless mode and auto mode the default policy in extensions/cli/src/perm…

continue | Remote | Misconfiguration
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71943 — DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields befo…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71942 — DrayTek VigorSwitch Multiple Models Buffer Overflow via mail_mailalert

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a f…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71941 — DrayTek VigorSwitch Multiple Models Buffer Overflow via diag_logmail

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fix…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71940 — DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Edit ACE

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer …

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71939 — DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Add ACE

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer w…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71938 — DrayTek VigorSwitch Multiple Models Buffer Overflow via switch_lan_gvrp

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buf…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71937 — DrayTek VigorSwitch Multiple Models Buffer Overflow via poe_schedule_profile

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, …

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71936 — DrayTek VigorSwitch Multiple Models Buffer Overflow via sysreboot

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into a fixed-size buffe…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71935 — DrayTek VigorSwitch Multiple Models Buffer Overflow via webBackupAction

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, an…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71934 — DrayTek VigorSwitch Multiple Models Buffer Overflow via pingtrace

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields a…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11402 Results