Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-54338 — JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed Lo…

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controll…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.6 CRITICAL
CVE-2026-50540 — Kata Containers: Config Path Annotation Arbitrary File Loading

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable …

Remote | Misconfiguration
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.6 HIGH
CVE-2026-47664 — Pathling: $import-pnp operation enables authenticated SSRF, credential leakage, and wareh…

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, the `$import-pnp` operation in Pathling Se…

Remote | Server-Side Request Forgery
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-47663 — Pathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfiltration and …

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR su…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-47662 — Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning…

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR su…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.4 MEDIUM
CVE-2026-46358 — OpenBao's Inline Auth Incorrectly Redacted Headers

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers b…

| Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.5 MEDIUM
CVE-2026-19246 — HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url se…

A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_generation.py of the component Provider-returned Im…

Remote | Server-Side Request Forgery
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
3.3 LOW
CVE-2026-19245 — HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disc…

A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of the file nanobot/agent/tools/shell.py of the component Login-shell Environment Ha…

| Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.8 MEDIUM
CVE-2026-19244 — HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control

A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP enabledTools Scope Hand…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.4 MEDIUM
CVE-2026-11425 — Domoticz Mobile Dashboard versions prior to 2026.3 Stored XSS via Text/Alert Device Rende…

Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript by updating …

Remote | Cross-Site Scripting
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.8 MEDIUM
CVE-2026-71870 — pypdf: Possible large memory usage for large /ToUnicode streams

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-cod…

| Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-66151 — SonicWall Global VPN Client Out-of-Bounds Memory Read

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.

global_vpn_client | Memory Corruption
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-65819 — gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enab…

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffe…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-62296 — HAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow denial of serv…

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-62295 — HAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of service

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enfo…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.0 MEDIUM
CVE-2026-62293 — HAPI FHIR: Stored XSS in scan report via unescaped IG and profile titles

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command concatenates attacker-controlled Implementation Guide…

| Cross-Site Scripting
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.8 CRITICAL
CVE-2026-61808 — LightRAG: Missing Authentication for Critical API Functions in Default Configuration

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an u…

lightrag | Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.1 CRITICAL
CVE-2026-48039 — Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditio…

Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.6 HIGH
CVE-2026-48007 — Element Call reports full URLs of visited pages to analytics server

Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a `posthog` key in config.json or by th…

Remote | Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-47661 — Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a ca…

Remote | Path Traversal
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
Showing 20 of 10014 Results