Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-82470 — Rodauth before 2.47.0 TOTP Code Reuse via Drift Window

Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can …

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
5.4 MEDIUM
CVE-2026-82469 — Rodauth before 2.47.0 Authentication Bypass via jwt_refresh

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access tok…

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
4.7 MEDIUM
CVE-2026-82468 — Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types…

Remote | Cross-Site Request Forgery
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
4.7 MEDIUM
CVE-2026-82467 — Rodauth before 2.47.0 Open Redirect via Return-to Path

Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers…

Remote | Misconfiguration
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
8.7 HIGH
CVE-2026-82466 — Rodauth before 2.46.0 Authentication Bypass via webauthn_login

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper acco…

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
5.3 MEDIUM
CVE-2026-82465 — pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest

pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destr…

pac4j | Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
6.1 MEDIUM
CVE-2026-82464 — pac4j-core before 6.5.6 Open Redirect via Backslash Logout

pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft …

pac4j | Remote | Misconfiguration
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
8.1 HIGH
CVE-2026-82463 — pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check

pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker clie…

pac4j | Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
6.5 MEDIUM
CVE-2026-82462 — pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution

pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to crea…

pac4j | Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
8.1 HIGH
CVE-2026-82461 — pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative r…

pac4j | Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
9.8 CRITICAL
CVE-2026-82460 — Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path tr…

Remote | Path Traversal
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
8.7 HIGH
CVE-2026-82481 — cohttp Directory Traversal Vulnerability

The cohttp package before 6.3.0 for OCaml allows directory traversal.

Remote | Path Traversal
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
5.8 MEDIUM
CVE-2026-82477 — MITRE SAF Heimdall Server-Side Request Forgery

In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/t…

Remote | Server-Side Request Forgery
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
7.8 HIGH
CVE-2026-82457 — su-exec through 0.3 Privilege Escalation via Numeric User ID

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supp…

| Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
10.0 CRITICAL
CVE-2026-82456 — argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the lis…

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
7.1 HIGH
CVE-2026-82455 — RubyGems before 4.0.13 Path Traversal via Symlink Resolution

RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction ro…

rubygems | Path Traversal
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
9.1 CRITICAL
CVE-2026-82454 — Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from th…

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
7.5 HIGH
CVE-2026-82453 — rust-iot-platform Cleartext Password Storage via User Model

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plain…

Remote | Cryptography
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
9.8 CRITICAL
CVE-2026-82452 — rust-iot-platform Authentication Bypass via Missing Request Guards

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers …

Remote | Authentication
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
6.1 MEDIUM
CVE-2026-82451 — Formwork through 2.3.14 Stored XSS via Referer Header

Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer he…

formwork | Remote | Cross-Site Scripting
Aug 29, 2026 Aug 29, 2026
Aug 29, 2026
Aug 29, 2026
Showing 20 of 11939 Results