Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.4 HIGH
CVE-2026-57990 — Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
7.4 HIGH
CVE-2026-57989 — Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
5.4 MEDIUM
CVE-2026-57978 — Microsoft Edge (Chromium-based) Spoofing Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
8.3 HIGH
CVE-2026-17497 — NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in th…

Remote | Misconfiguration
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
8.1 HIGH
CVE-2026-17496 — NoteGen chat preview XSS via unsanitized AI/skill HTML rendering

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization a…

Remote | Cross-Site Scripting
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
4.3 MEDIUM
CVE-2026-17459 — perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.ja…

Remote | Path Traversal
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
6.5 MEDIUM
CVE-2026-17458 — mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side …

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Perfo…

Remote | Server-Side Request Forgery
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
4.3 MEDIUM
CVE-2026-17457 — mf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information…

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component S…

Remote | Information Disclosure
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
0.0 NA
CVE-2026-64530 — net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held b…

linux_kernel | Memory Corruption
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
0.0 NA
CVE-2024-14040 — net: nexthop: Increase weight to u16

In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various points in the network, ECMP weights of t…

linux_kernel | Misconfiguration
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
7.5 HIGH
CVE-2026-63720 — datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious cust…

Remote | Injection
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
6.5 MEDIUM
CVE-2026-17434 — nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulat…

nanoclaw | Remote | Authorization
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
5.3 MEDIUM
CVE-2026-17433 — nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improp…

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. P…

nanoclaw | Authorization
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
8.8 HIGH
CVE-2026-15962 — Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection …

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible …

Remote | Injection
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
5.0 MEDIUM
CVE-2026-17432 — NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control

A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the com…

hermes-agent | Remote | Authorization
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
6.5 MEDIUM
CVE-2026-10681 — SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers s…

In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding li…

zephyr zephyr | Race Condition
Jul 25, 2026 Jul 25, 2026
Jul 25, 2026
Jul 25, 2026
9.3 CRITICAL
CVE-2026-66013 — OpenRemote before 1.26.2 Authentication Bypass via Console Registration

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known a…

openremote | Remote | Authentication
Jul 25, 2026 Jul 25, 2026
Jul 25, 2026
Jul 25, 2026
10.0 CRITICAL
CVE-2026-66012 — SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enf…

siyuan | Remote | Authorization
Jul 25, 2026 Jul 25, 2026
Jul 25, 2026
Jul 25, 2026
3.3 LOW
CVE-2026-66011 — ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplyin…

imagemagick | Memory Corruption
Jul 25, 2026 Jul 25, 2026
Jul 25, 2026
Jul 25, 2026
0.0 NA
CVE-2026-64529 — crypto: qat - remove unused character device and IOCTLs

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - remove unused character device and IOCTLs The QAT driver exposes a character device (qat_adf_ctl) with IOCTLs for d…

linux_kernel | Misconfiguration
Jul 25, 2026 Jul 25, 2026
Jul 25, 2026
Jul 25, 2026
Showing 20 of 8954 Results