Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-82261 — SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malfo…

Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-82260 — SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form de…

Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-82259 — SvelteKit 2.49.0 before 2.53.3 Denial of Service via form

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunc…

Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.9 MEDIUM
CVE-2026-82258 — SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch

SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploi…

Remote | Race Condition
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.3 MEDIUM
CVE-2026-82257 — SvelteKit before 2.69.1 Prototype Pollution via File Input

SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate…

Remote | Misconfiguration
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.3 MEDIUM
CVE-2026-82256 — SvelteKit before 2.69.1 Denial of Service via Remote Form

SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of s…

Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.8 MEDIUM
CVE-2026-82255 — gitoxide 0.25.4 HTTP Credential Leak via Redirect

gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vul…

gitoxide | Remote | Misconfiguration
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-82254 — gitoxide before 0.69.0 Denial of Service via gix-pack

gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during cl…

gitoxide | Remote | Memory Corruption
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-82253 — gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass

gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..…

gitoxide | Remote | Path Traversal
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-82252 — gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repo…

gitoxide | Remote | Path Traversal
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-82251 — gitoxide before 0.52.1 Path Traversal via Submodule Name

gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names…

gitoxide | Remote | Path Traversal
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.5 MEDIUM
CVE-2026-82250 — gitoxide gix-packetline before 0.21.5 Denial of Service

gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git serv…

gitoxide | Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
3.1 LOW
CVE-2026-82249 — gitoxide before 0.38.2 Credential Helper Protocol Field Injection

gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper …

gitoxide | Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.3 MEDIUM
CVE-2026-82248 — gitoxide before 0.33.0 Path Traversal via symlink following

gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (inc…

gitoxide | Remote | Path Traversal
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-82247 — gitoxide before 0.37.1 HTTP Basic credential leak via URL parsing

gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-…

gitoxide | Remote | Misconfiguration
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-82246 — Budibase Server before 3.41.3 SSRF via Query Import

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit…

Remote | Server-Side Request Forgery
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.1 HIGH
CVE-2026-82245 — Budibase before 3.41.3 Missing Authorization License Management

Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers with b…

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.1 CRITICAL
CVE-2026-82244 — Budibase before 3.41.3 Remote Code Execution via Plugin eval()

Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarbal…

Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.6 HIGH
CVE-2026-82243 — Budibase Server before 3.41.3 SSRF with Credential Leakage

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. …

Remote | Server-Side Request Forgery
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.7 HIGH
CVE-2026-82242 — Budibase before 3.41.3 Cross-Application Resource Injection via Missing Authorization

Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, …

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
Showing 20 of 12522 Results