Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-51977 — Trueview Robot Pan-Tilt Security Camera Privilege Escalation Vulnerability

An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component

Remote | Authentication
Aug 17, 2026 Aug 31, 2026
Aug 17, 2026
Aug 31, 2026
5.9 MEDIUM
CVE-2026-45791 — Dokploy: Password Change Does Not Revoke Active Sessions

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/dokploy/server/api/routers/user.ts updates account.password without deleting ot…

dokploy | Remote | Authentication
Aug 17, 2026 Sep 08, 2026
Aug 17, 2026
Sep 08, 2026
8.0 HIGH
CVE-2026-45790 — Dokploy: Invitation Role Escalation Allows Organization Takeover

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user wit…

dokploy | Remote | Authorization
Aug 17, 2026 Sep 08, 2026
Aug 17, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-43795 — Apple Safari Memory Handling Vulnerability

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing …

macos iphone_os safari ipados safari macos +1 more | Remote | Memory Corruption
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
8.8 HIGH
CVE-2026-43794 — Apple WebKit Memory Corruption

A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27,…

macos iphone_os tvos watchos safari ipados +4 more | Remote | Memory Corruption
Aug 17, 2026 Sep 14, 2026
Aug 17, 2026
Sep 14, 2026
6.5 MEDIUM
CVE-2026-43667 — Apple iOS and iPadOS Denial of Service Vulnerability

A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An …

macos iphone_os watchos ipados macos watchos +1 more | Remote | Denial of Service
Aug 17, 2026 Aug 25, 2026
Aug 17, 2026
Aug 25, 2026
9.8 CRITICAL
CVE-2026-42163 — Mahara Learning Tools Interoperability Unauthorized Account Access Vulnerability

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 …

Remote | Authentication
Aug 17, 2026 Aug 31, 2026
Aug 17, 2026
Aug 31, 2026
4.3 MEDIUM
CVE-2026-28984 — Apple Safari Memory Corruption Vulnerability

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchO…

macos iphone_os tvos watchos safari ipados +4 more | Remote | Memory Corruption
Aug 17, 2026 Aug 25, 2026
Aug 17, 2026
Aug 25, 2026
5.3 MEDIUM
CVE-2026-11817 — CVE-2026-11817 CVE Record

This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a…

grafana | Remote | Information Disclosure
Aug 17, 2026 Aug 31, 2026
Aug 17, 2026
Aug 31, 2026
6.5 MEDIUM
CVE-2026-10080 — Boards plugin panics on WebSocket command with non-string field types

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash the plugin process and deny ser…

mattermost_server mattermost_desktop legal_hold | Remote | Denial of Service
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
7.0 HIGH
CVE-2026-75531 — Stored Cross-Site Scripting in URL Observables via Lookyloo Submission Handler in Pandora

Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted from or associated with an analyzed file was inserted directly into the inline …

Remote | Cross-Site Scripting
Aug 17, 2026 Aug 26, 2026
Aug 17, 2026
Aug 26, 2026
6.9 MEDIUM
CVE-2026-75529 — Stored Cross-Site Scripting via MIME-Type Confusion in PDF Downloads of Pandora

Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download/<task_id>/.../pdf endpoint verifies that the submitted file is a PDF using Pan…

Remote | Cross-Site Scripting
Aug 17, 2026 Aug 26, 2026
Aug 17, 2026
Aug 26, 2026
4.8 MEDIUM
CVE-2026-75483 — powerlevel10k Control Character Injection via package.json Version

powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the version string to emit a…

| Injection
Aug 17, 2026 Aug 20, 2026
Aug 17, 2026
Aug 20, 2026
8.7 HIGH
CVE-2026-75482 — SWE-agent Trajectory Inspector Path Traversal File Disclosure

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent…

Remote | Path Traversal
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
8.8 HIGH
CVE-2026-75481 — SkyPilot Authentication Bypass via Service Account Role Escalation

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to adminis…

skypilot | Remote | Authorization
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
7.1 HIGH
CVE-2026-75480 — OpenViking Debug Vector Endpoints Multi-tenant Data Exposure

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query…

openviking | Remote | Authorization
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
8.7 HIGH
CVE-2026-75479 — JimuReport Unauthenticated Report Listing and Share Token Disclosure

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Att…

jimureport | Remote | Authentication
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
8.7 HIGH
CVE-2026-75111 — Evidently UI Path Traversal via Dataset Materialization Filename

Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Att…

Remote | Path Traversal
Aug 17, 2026 Aug 20, 2026
Aug 17, 2026
Aug 20, 2026
9.8 CRITICAL
CVE-2026-75110 — MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET

MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment var…

Remote | Authentication
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
7.1 HIGH
CVE-2026-75109 — Determined Missing Authorization Check on Generic Task Endpoints

Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by terminating, pausing, …

Remote | Authorization
Aug 17, 2026 Aug 18, 2026
Aug 17, 2026
Aug 18, 2026
Showing 20 of 14636 Results