Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-76032 — Pydio Cells 5.0.0 to 5.0.2 - Missing Authorization on the Share Link REST Handler

Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from the path…

cells | Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.9 CRITICAL
CVE-2026-75936 — Memory-amplification denial of service via GZIP decompression bomb in Amazon ion-java

Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion…

Remote | Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.7 HIGH
CVE-2026-75935 — Memory-amplification denial of service via declared-length preallocation in Amazon ion-ja…

Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a d…

Remote | Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.9 CRITICAL
CVE-2026-75877 — TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow

A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailChanged/SystemFTPChanged/websCheckRealm/FUN_00432574/…

Remote | Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.5 MEDIUM
CVE-2026-75876 — xianrendzw EasyReport Move Operations ModuleController.java sql injection

A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of the file ModuleController.java of the component Mov…

easyreport | Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.9 MEDIUM
CVE-2026-73529 — Plainpad Missing Rate Limiting via POST /v1/sessions

Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoin…

Remote | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-71676 — Open5GS NAS 5GS Decoder Buffer Overflow

Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the NAS 5GS decoder chain, triggered when the message type byte of a NAS PDU is mutated

| Memory Corruption
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-71675 — Open5GS Denial of Service Vulnerability

An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in src/amf/ngap-path.c

| Denial of Service
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.3 HIGH
CVE-2026-71417 — Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate reco…

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using another certificate body, authority_id, serial, or…

lemur | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.3 MEDIUM
CVE-2026-71322 — Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with req…

Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_key branch for POST /api/1/certificates//export. …

lemur | Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.5 MEDIUM
CVE-2026-71317 — Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent authority when ADMIN_ONLY_AUTHORITY_CREATION was fals…

lemur | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
8.1 HIGH
CVE-2026-71308 — Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotatio…

Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved…

lemur | Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.7 HIGH
CVE-2026-71307 — Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP…

Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. Dest…

lemur | Remote | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.7 HIGH
CVE-2026-71303 — Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint allows non-adm…

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when an authority was created, but PUT /api/1/authorities/ passed options to lemur/au…

lemur | Remote | Server-Side Request Forgery
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.4 HIGH
CVE-2026-70666 — Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/authorities/ without revalidation and direct setup_acme_client_no_retry to an…

lemur | Remote | Misconfiguration
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.2 CRITICAL
CVE-2026-67443 — FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote …

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for…

fuxa | Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.9 MEDIUM
CVE-2026-67440 — FUXA: Unauthenticated Socket.IO read events

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERFACES, and DEVICE_TAGS_REQUEST handlers in server/r…

fuxa | Remote | Information Disclosure
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
6.0 MEDIUM
CVE-2026-65985 — FUXA: SSRF hardening for `device-webapi-request`

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-adm…

fuxa | Remote | Server-Side Request Forgery
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.5 HIGH
CVE-2026-65984 — FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessions

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, incl…

fuxa | Remote | Authentication
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.3 HIGH
CVE-2026-59915 — Dell Alienware Command Center Elevation of Privilege Vulnerability

Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulner…

alienware_command_center | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
Showing 20 of 11330 Results