Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.2 CRITICAL
CVE-2026-65886 — Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2

Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files.

Remote | Information Disclosure
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.6 HIGH
CVE-2026-59247 — Insufficient verification of Hex package metadata in Gleam

Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged Hex package contents during dependency resolution. During dependency reso…

gleam | Remote | Supply Chain
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.3 HIGH
CVE-2026-54666 — swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in…

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to …

Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.3 HIGH
CVE-2026-54664 — swagger-typescript-api vulnerable to code injection via unescaped enum string values

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] valu…

Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.1 MEDIUM
CVE-2026-54663 — swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and …

Remote | Server-Side Request Forgery
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.3 HIGH
CVE-2026-54662 — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fet…

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, an…

Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.3 HIGH
CVE-2026-54661 — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axi…

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src…

Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.4 HIGH
CVE-2026-54660 — swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards --authorizationToken to …

Remote | Information Disclosure
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.0 HIGH
CVE-2026-12703 — Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS

TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Una…

remote | Remote | Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.4 CRITICAL
CVE-2026-9177 — Server-Side Template Injection in SecureTransport's Apache Velocity mail templates

A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker w…

securetransport | Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.3 MEDIUM
CVE-2026-67217 — cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation

cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose desti…

cjson | Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.9 MEDIUM
CVE-2026-67216 — cJSON cJSON_Compare Exponential Complexity Denial of Service

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with…

cjson | Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.5 HIGH
CVE-2026-67215 — cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseS…

cjson | Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.9 MEDIUM
CVE-2026-67214 — nanoid before 5.1.16 Infinite Loop via Negative Size in non-secure module

nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the l…

Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.9 MEDIUM
CVE-2026-67213 — nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customRandom

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never sati…

Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.1 MEDIUM
CVE-2026-66490 — Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Grid…

Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

Remote | Cross-Site Scripting
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-66489 — Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbo…

Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

| Information Disclosure
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-66488 — Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

| Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
4.8 MEDIUM
CVE-2026-66400 — Grav Login Plugin before 3.8.13 Insufficient Session Expiration

Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token times…

grav | Remote | Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.2 CRITICAL
CVE-2026-65890 — Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
Showing 20 of 9590 Results