Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-73199 — Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`…

A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol …

enterprise_linux enterprise_linux | Remote | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.6 CRITICAL
CVE-2026-11861 — Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relation…

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal,…

enterprise_linux enterprise_linux | Remote | Authentication
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-73198 — Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the servi…

enterprise_linux enterprise_linux | Remote | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.1 CRITICAL
CVE-2026-13097 — Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniquene…

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent repr…

enterprise_linux enterprise_linux | Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.9 MEDIUM
CVE-2026-77026 — Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms exten…

Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
4.3 MEDIUM
CVE-2026-73196 — Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encod…

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-…

enterprise_linux enterprise_linux | Remote | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-73197 — Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request …

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force th…

enterprise_linux enterprise_linux | Remote | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.8 HIGH
CVE-2026-18917 — Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, le…

enterprise_linux enterprise_linux | Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.3 MEDIUM
CVE-2026-77014 — Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission o…

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign fo…

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.9 MEDIUM
CVE-2026-76610 — Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65

Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated use…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.3 MEDIUM
CVE-2026-14953 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is Missing Authorization due to imprope…

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

Remote | Information Disclosure
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.7 HIGH
CVE-2026-14952 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is offering files with sensitive inform…

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP withou…

Remote | Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-14951 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Cross-Site Request For…

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

Remote | Cross-Site Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.8 CRITICAL
CVE-2026-14950 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session E…

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leak…

Remote | Authentication
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.5 HIGH
CVE-2026-14949 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Incorrect Authorizatio…

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, incl…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.8 HIGH
CVE-2026-14948 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insertion of Sensitive…

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated user…

Remote | Information Disclosure
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-14947 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution …

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locat…

Remote | Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-14946 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution …

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could…

Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.3 MEDIUM
CVE-2026-76569 — Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Downloa…

Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4

Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.3 MEDIUM
CVE-2026-76565 — Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters i…

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
Showing 20 of 12695 Results