Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-15928 — XMLRPC-C Library Reflected Cross-Site Scripting Vulnerability

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.9 MEDIUM
CVE-2026-17501 — ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform al…

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. T…

Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.9 MEDIUM
CVE-2026-17500 — ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereference

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer de…

Remote | Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.4 HIGH
CVE-2026-57990 — Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
7.4 HIGH
CVE-2026-57989 — Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
5.4 MEDIUM
CVE-2026-57978 — Microsoft Edge (Chromium-based) Spoofing Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
8.3 HIGH
CVE-2026-17497 — NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in th…

Remote | Misconfiguration
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
8.1 HIGH
CVE-2026-17496 — NoteGen chat preview XSS via unsanitized AI/skill HTML rendering

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization a…

Remote | Cross-Site Scripting
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
4.3 MEDIUM
CVE-2026-17459 — perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.ja…

spark | Remote | Path Traversal
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
6.5 MEDIUM
CVE-2026-17458 — mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side …

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Perfo…

openclaw-cn | Remote | Server-Side Request Forgery
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
4.3 MEDIUM
CVE-2026-17457 — mf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information…

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component S…

openclaw-cn | Remote | Information Disclosure
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
0.0 NA
CVE-2026-64530 — net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held b…

linux_kernel | Memory Corruption
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
0.0 NA
CVE-2024-14040 — net: nexthop: Increase weight to u16

In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various points in the network, ECMP weights of t…

linux_kernel | Misconfiguration
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
7.5 HIGH
CVE-2026-63720 — datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious cust…

Remote | Injection
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
6.5 MEDIUM
CVE-2026-17434 — nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulat…

nanoclaw | Remote | Authorization
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
5.3 MEDIUM
CVE-2026-17433 — nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improp…

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. P…

nanoclaw | Authorization
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
8.8 HIGH
CVE-2026-15962 — Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection …

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible …

Remote | Injection
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
5.0 MEDIUM
CVE-2026-17432 — NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control

A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the com…

hermes-agent | Remote | Authorization
Jul 26, 2026 Jul 26, 2026
Jul 26, 2026
Jul 26, 2026
6.5 MEDIUM
CVE-2026-10681 — SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers s…

In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding li…

zephyr zephyr | Race Condition
Jul 25, 2026 Jul 25, 2026
Jul 25, 2026
Jul 25, 2026
9.3 CRITICAL
CVE-2026-66013 — OpenRemote before 1.26.2 Authentication Bypass via Console Registration

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known a…

openremote | Remote | Authentication
Jul 25, 2026 Jul 25, 2026
Jul 25, 2026
Jul 25, 2026
Showing 20 of 8914 Results