Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-53585 — libgit2: Unbounded Memory Allocation via Delta Object Result-Size Header

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, gi…

Remote | Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
4.3 MEDIUM
CVE-2026-53584 — libgit2: Submodule path traversal

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, li…

Remote | Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-53583 — libgit2: Inverted IP SubjectAltName Comparison in OpenSSL Backend

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, ve…

Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.3 MEDIUM
CVE-2026-53569 — Frappe: Missing authorization in toggle_like and mark_as_seen

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-50190 — Shaarli vulnerable to stored XSS via raw bookmark title in document <title> element on pu…

Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/controller/visitor/BookmarkListController.php`. The `permalink` handler concaten…

Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
3.7 LOW
CVE-2026-49996 — securedrop-proxy origin limitation can be bypassed with redirects

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server cou…

Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
0.0 NA
CVE-2026-43678 — SwiftNIO WebSocket Denial of Service Vulnerability

An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active co…

| Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.3 MEDIUM
CVE-2026-19683 — Unencrypted Credential Transmission in Omada Gateway Dynamic DNS Authentication in Omada …

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unen…

er7206 er8411 er7412-m2 er707-m2 er605 er706w +10 more | Remote | Cryptography
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.3 CRITICAL
CVE-2026-19586 — Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gate…

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during …

er7206 er8411 er7412-m2 er707-m2 er605 er706w +10 more | Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
0.0 NA
CVE-2026-15743 — Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicl…

Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of over…

| Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-77036 — elunez eladmin GenConfigController improper authorization

A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayController/GeneratorController/GenConfigController. The manipulation results in impro…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.4 HIGH
CVE-2026-77031 — Tenda CH22 formcreateFileName command injection

A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument fileNameMit lead…

ch22 | Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.7 HIGH
CVE-2026-76641 — Expat Out-of-Bounds Read via dtdCopy

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParser…

Remote | Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.4 MEDIUM
CVE-2026-73259 — Mongoose: Reflected XSS via decoded URI in directory listing render

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to…

mongoose | Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-73258 — Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipart

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/…

mongoose | Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.1 CRITICAL
CVE-2026-73257 — Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked…

mongoose | Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.1 CRITICAL
CVE-2026-73256 — Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: …

mongoose | Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-73255 — Mongoose: Path traversal in SSI #include directives enables arbitrary file read

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual …

mongoose | Remote | Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.4 MEDIUM
CVE-2026-73254 — Mongoose: Stored XSS via unescaped filenames in directory listing

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a…

mongoose | Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.1 CRITICAL
CVE-2026-73253 — Mongoose: TLS Hostname Verification Bypass via Overly Permissive Wildcard Matching

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a clien…

mongoose | Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
Showing 20 of 12762 Results