Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-8650 — Authenticated Path Traversal allows MOVEit admins to view arbitrary system files

Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

moveit_transfer | Remote | Path Traversal
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
9.8 CRITICAL
CVE-2026-8649 — Institution scope bypass vulnerability in custom reports

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0…

moveit_transfer | Remote | Injection
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
9.3 CRITICAL
CVE-2026-60104 — Bitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request

Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtai…

server | Remote | Authentication
Jul 08, 2026 Jul 20, 2026
Jul 08, 2026
Jul 20, 2026
7.0 HIGH
CVE-2026-59948 — Composer: Arbitrary file write outside vendor via malicious transitive package name

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause C…

composer | Supply Chain
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
4.7 MEDIUM
CVE-2026-59947 — Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repos…

composer | Information Disclosure
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
6.1 MEDIUM
CVE-2026-59946 — Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files

Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve outside the package install directory and cause…

composer | Path Traversal
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
7.5 HIGH
CVE-2026-59939 — httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handli…

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decom…

httplib2 | Remote | Denial of Service
Jul 08, 2026 Jul 13, 2026
Jul 08, 2026
Jul 13, 2026
8.7 HIGH
CVE-2026-59936 — pypdf: Possible infinite loop for not terminated inline images

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inline image, causing an infinite loop dur…

pypdf | Remote | Denial of Service
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
8.7 HIGH
CVE-2026-59935 — pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filt…

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCI…

pypdf | Remote | Denial of Service
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
8.8 HIGH
CVE-2026-59822 — LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated A…

litellm | Remote | Authentication
Jul 08, 2026 Jul 13, 2026
Jul 08, 2026
Jul 13, 2026
7.2 HIGH
CVE-2026-59821 — LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the sam…

litellm | Remote | Misconfiguration
Jul 08, 2026 Jul 13, 2026
Jul 08, 2026
Jul 13, 2026
6.5 MEDIUM
CVE-2026-59820 — LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded …

litellm | Remote | Path Traversal
Jul 08, 2026 Jul 13, 2026
Jul 08, 2026
Jul 13, 2026
4.9 MEDIUM
CVE-2026-59819 — LiteLLM: Local file read via request-supplied OIDC file references

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OID…

litellm | Remote | Information Disclosure
Jul 08, 2026 Jul 13, 2026
Jul 08, 2026
Jul 13, 2026
8.9 HIGH
CVE-2026-59807 — Composio SDK < 0.2.32-beta.283 - Sensitive File Upload via tool-file-uploads.ts

Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check…

composio | Remote | Path Traversal
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
7.4 HIGH
CVE-2026-59806 — Gradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpoint

Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalid…

gradio gradio | Remote | Server-Side Request Forgery
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
7.1 HIGH
CVE-2026-59805 — Gumroad < 2026.07.06.2 - Insecure Direct Object Reference in PurchasesController

Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by se…

Remote | Authorization
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
7.6 HIGH
CVE-2026-59804 — Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket

Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows unauthenticated remote attackers to hijack active…

Remote | Authentication
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
8.7 HIGH
CVE-2026-59803 — rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol

rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in protocol.Message.Decode (protocol/message.go). When a message has the compression flag set, the payload is g…

Remote | Denial of Service
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
8.2 HIGH
CVE-2026-59802 — PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload

PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URI…

password_pusher | Remote | Cross-Site Scripting
Jul 08, 2026 Jul 14, 2026
Jul 08, 2026
Jul 14, 2026
5.9 MEDIUM
CVE-2026-58501 — Zeep SSRF because Settings.forbid_external is not enforced

Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd:include, wsdl:impor…

zeep zeep | Remote | Server-Side Request Forgery
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
Showing 20 of 9488 Results