Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-76841 — Xinference through 2.11.0 Remote Code Execution via Hardcoded trust_remote_code in Model …

Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True …

Remote | Supply Chain
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.6 CRITICAL
CVE-2026-76840 — RustDesk through 1.4.9 Heap Buffer Overflow via Unvalidated CLIPRDR FileContentsResponse …

RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Rea…

Remote | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.3 CRITICAL
CVE-2026-67602 — phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache

phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechan…

Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.1 CRITICAL
CVE-2026-59568 — Remote Code Execution

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC co…

client_connector | Remote | Misconfiguration
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-59567 — Local privilege escalation

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.

client_connector | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.4 HIGH
CVE-2026-59566 — Local denial-of-service

A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.

client_connector | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-59565 — Local and kernel denial-of-service

A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.

client_connector | Remote | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.1 CRITICAL
CVE-2026-59564 — Authentication bypass between ZCC and client connector portal

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.

client_connector | Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-30512 — Entevo HMI Kiosk Mode Privilege Escalation

A local privilege escalation vulnerability in Entevo HMI V2 R5 P0 M4 allows attackers to escape Kiosk Mode by opening the application manual in an external PDF viewer and abusing the Print functional…

| Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.4 HIGH
CVE-2026-21751 — HCL Hive is affected by use of a cryptographic primitive with a risky implementation

HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal compo…

Remote | Cryptography
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.8 MEDIUM
CVE-2026-17033 — CVE-2026-17033 CVE Record

An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the…

Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.3 MEDIUM
CVE-2025-68833 — HCL Hive is affected by use of a cryptographic primitive with a risky implementation

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.1 HIGH
CVE-2026-39914 — TIM Flow < 26.0.6 Unauthorized SQL Query Execution via Dashboard Export Endpoint

TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for…

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.1 HIGH
CVE-2026-76054 — Black Duck C/C++ Sensitive Information Disclosure via Process Environment

Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Blac…

| Information Disclosure
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.3 MEDIUM
CVE-2026-21755 — HCL Hive is affected by a missing rate limit

HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service.

Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.5 HIGH
CVE-2026-39915 — TIM Flow < 26.0.6 CRLF Injection via rt Parameter and access_token Cookie

TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized carriage return and lin…

Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-78391 — Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook

RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view. Cryptocurrency addresses and blockchain names originating from external sources, includ…

Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.4 CRITICAL
CVE-2026-78387 — RansomLook Missing Authorization in Web Configuration Editor Allows Application Configura…

RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint. The endpoint requires an authenticated session but does not perform an …

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.3 CRITICAL
CVE-2026-78365 — IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read…

Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record…

prospero_flow_crm | Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-78247 — SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql injection

A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation o…

simple_online_food_ordering_system | Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11313 Results