Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-18785 — o6 open62541 client_types_custom.c UA_Client_getRemoteDataTypes use after free

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom…

| Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.3 MEDIUM
CVE-2026-18784 — o6 open62541 ua_client_highlevel.c UA_Client_readNodeClassAttribute heap-based overflow

A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results…

| Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-18775 — NousResearch hermes-agent Browser Tooling browser_tool.py browser_snapshot server-side re…

A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. …

hermes-agent | Remote | Server-Side Request Forgery
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-18774 — NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py save_url_im…

A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This …

hermes-agent | Remote | Server-Side Request Forgery
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.1 MEDIUM
CVE-2026-15920 — Potential cross-site scripting via URLField values in the admin

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating…

django | Remote | Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.9 MEDIUM
CVE-2026-15830 — Potential denial-of-service vulnerability via nested geometry collections

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GE…

django | Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.9 MEDIUM
CVE-2026-15337 — Potential denial-of-service vulnerability in check_for_language()

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, …

django | Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-15314 — Authenticated Denial-of-Service Vulnerability in TP-Link Tapo P110

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy opera…

| Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.8 HIGH
CVE-2026-15307 — Server-side file-write and request forgery via spatial lookups

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis…

django | Remote | Server-Side Request Forgery
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2025-29296 — H3C Magic Series Command Injection Vulnerability

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, and H3C NE36 Pro V100R002 contain multiple c…

| Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.4 CRITICAL
CVE-2026-69254 — Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the defaul…

flowise | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.0 CRITICAL
CVE-2026-69253 — Flowise Sandbox Escape to RCE

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow…

flowise | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.2 HIGH
CVE-2026-69252 — Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list …

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce …

flowise | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.3 CRITICAL
CVE-2026-69110 — OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by direc…

Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.8 HIGH
CVE-2026-69100 — LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template f…

lamp-cloud | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.8 CRITICAL
CVE-2026-69098 — kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying …

kotaemon | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.6 HIGH
CVE-2026-25292 — Improper Validation of Syntactic Correctness of Input in Automotive Linux OS

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

| Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.6 CRITICAL
CVE-2026-25289 — Stack-based Buffer Overflow in WLAN Firmware

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

| Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.4 HIGH
CVE-2026-25288 — Buffer Over-read in WLAN Firmware

Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

| Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.5 HIGH
CVE-2026-24084 — Insecure Security Identifier Mechanism in Multi-Mode Call Processor

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

Remote | Misconfiguration
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
Showing 20 of 9516 Results