Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-16770 — PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via m…

PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every <meta name…

| Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.8 MEDIUM
CVE-2026-71194 — OpenStack Designate mDNS Handler Denial of Service Vulnerability

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, t…

designate | Remote | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.6 CRITICAL
CVE-2026-71193 — OpenStack Designate Cross-Tenant Zone Overlap Vulnerability

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass thes…

designate | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.6 CRITICAL
CVE-2026-49481 — UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/sh…

UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command templat…

Remote | Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.5 MEDIUM
CVE-2026-47718 — FUXA provides guest and invalid-token access to protected read APIs in secure mode

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and sched…

fuxa | Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.5 HIGH
CVE-2026-47717 — FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Con…

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context req…

fuxa | Remote | Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-15141 — Referer Validation Bypass in TL-WR820N Web Management Interface

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be ac…

tl-wr820n | Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.2 MEDIUM
CVE-2026-7366 — IBM DataPower Gateway affected by HTTP request header leakage in XML-Firewall

IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improp…

datapower_gateway | Remote | Race Condition
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.8 CRITICAL
CVE-2026-73519 — WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypa…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.1 CRITICAL
CVE-2026-73501 — kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticat…

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenti…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.7 HIGH
CVE-2026-73500 — etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connec…

Remote | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.1 HIGH
CVE-2026-73499 — etcd: Watch API authorization bypass via open-ended range requests

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC AP…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.7 HIGH
CVE-2026-73498 — MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path val…

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to ope…

Remote | Path Traversal
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.4 HIGH
CVE-2026-73495 — blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-e…

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.head…

Remote | Misconfiguration
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.5 HIGH
CVE-2026-73493 — http4s-blaze-server: Unbounded WebSocket message aggregation

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with …

Remote | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
2.3 LOW
CVE-2026-73492 — Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character refer…

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject j…

Remote | Misconfiguration
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-71846 — Insights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch …

A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a …

Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
8.5 HIGH
CVE-2026-71473 — Acm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enable…

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configura…

Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.0 CRITICAL
CVE-2026-71471 — Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated…

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerabilit…

advanced_cluster_management_for_kubernetes | Remote | Misconfiguration
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.5 HIGH
CVE-2026-71469 — Acm-search-v2-api-rhel9: search-v2-api: unbounded tokenreviews cache allows unauthenticat…

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded toke…

advanced_cluster_management_for_kubernetes | Remote | Denial of Service
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
Showing 20 of 11043 Results