Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-53599 — Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to…

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with m…

| Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-62999 — Copier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (In…

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configur…

copier | Path Traversal
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-53510 — Savon::Model evaluates WSDL operation names as Ruby source

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code exe…

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.4 HIGH
CVE-2026-18394 — Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration

Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LL…

Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.1 LOW
CVE-2026-57232 — Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Mo…

Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderController::getResponse() to…

Remote | Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
2.6 LOW
CVE-2026-55824 — Contao crawler leaks auth credentials to external hosts

Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP…

Remote | Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-53505 — Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform …

Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-53504 — Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing…

Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-53503 — Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> valu…

Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.7 HIGH
CVE-2026-53502 — Thumbor has path traversal via post-validation URL decoding bypass in file_loader

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_L…

Remote | Path Traversal
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.2 HIGH
CVE-2026-53501 — Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signat…

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the UR…

Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.2 HIGH
CVE-2026-53500 — Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypa…

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at …

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.3 MEDIUM
CVE-2026-25552 — Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header

Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a miscon…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.3 HIGH
CVE-2026-18481 — Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative cont…

Remote | Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.7 MEDIUM
CVE-2026-18321 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec

Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd

| Memory Corruption
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-65841 — Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html …

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing …

| Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-62324 — Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check t…

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values bef…

| Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-55825 — Contao: Possible path traversal in job download URIs

Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segments and make the job attac…

| Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.7 HIGH
CVE-2026-55100 — hashi-vault-js has a path traversal and query parameter injection

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and versi…

Remote | Path Traversal
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.3 HIGH
CVE-2026-54737 — @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merg…

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filterin…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
Showing 20 of 9469 Results