Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-73212 — coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path…

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without c…

| Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.0 MEDIUM
CVE-2026-20901 — Intel Xeon Processor Firmware Improper Input Validation Privilege Escalation

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complex…

| Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-48790 — turso-cli persists Turso platform JWT with world-readable (0o644) file permissions

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermiss…

| Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-73211 — PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore()

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowi…

| Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-48771 — ishankportfolio: Stored Contact Form Submission Exposure via Public Client-Side Database …

ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured client-side database configuration and insufficient acc…

| Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-73090 — PeerTube: Cross-origin remote video takeover via Update activity

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying th…

| Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.5 HIGH
CVE-2026-73089 — Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, lea…

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache an…

Remote | Denial of Service
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.5 HIGH
CVE-2026-73088 — Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json cust…

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() …

Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
2.3 LOW
CVE-2026-73087 — Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook no…

Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, used by safeDialContext for webhook notifi…

Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.4 HIGH
CVE-2026-73086 — nanoid: Integer Overflow or Wraparound

nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size …

Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.3 MEDIUM
CVE-2026-73085 — Audiobookshelf: Refresh Token Accepted on Resource Endpoints

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens…

Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.1 MEDIUM
CVE-2026-73084 — Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script…

Remote | Cross-Site Scripting
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.6 HIGH
CVE-2026-73083 — Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading

Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine loads the compiled user module with importFresh(), a wrapper around Node.js requ…

Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.3 MEDIUM
CVE-2026-73082 — Activepieces: Server-side request forgery in MCP tool validation endpoint

Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request…

Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.7 HIGH
CVE-2026-73081 — Activepieces: Remote Code Execution via Command Injection in Code Step Name

Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk path for a Code step from the step's name and passes that pa…

Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.5 MEDIUM
CVE-2026-72971 — Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.0 MEDIUM
CVE-2026-71390 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security meas…

| Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.2 MEDIUM
CVE-2026-71389 — CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to c…

| Denial of Service
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.8 HIGH
CVE-2026-71387 — ColdFusion | Incorrect Authorization (CWE-863)

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to ex…

| Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.8 HIGH
CVE-2026-71386 — ColdFusion | Cross-site Scripting (XSS) (CWE-79)

is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb…

| Cross-Site Scripting
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
Showing 20 of 10817 Results