Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability…

Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
7.5 HIGH

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.25.0.000. Easily exploita…

Aug 18, 2026 Aug 25, 2026
Aug 18, 2026
Aug 25, 2026
7.8 HIGH

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vul…

Aug 18, 2026 Aug 21, 2026
Aug 18, 2026
Aug 21, 2026
7.5 HIGH

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability al…

Aug 18, 2026 Aug 24, 2026
Aug 18, 2026
Aug 24, 2026
6.5 MEDIUM
CVE-2026-55593 — Froxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery…

Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Fro…

froxlor | Remote | Cross-Site Request Forgery
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
7.8 HIGH
CVE-2026-55426 — linuxfabrik-lib: Local privilege escalation using embedded command

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands.…

| Injection
Aug 18, 2026 Sep 09, 2026
Aug 18, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-54543 — Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields

Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values witho…

froxlor | Remote | Injection
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
7.2 HIGH
CVE-2026-54348 — Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Da…

Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array …

froxlor | Remote | Injection
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-54347 — Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover

Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/…

froxlor | Remote | Cross-Site Scripting
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
2.0 LOW
CVE-2026-53759 — linuxfabrik-lib: Insecure creation of SQLite databases

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 4.2.0, db_sqlite.py created SQLite databases at predictable paths in the …

| Path Traversal
Aug 18, 2026 Sep 09, 2026
Aug 18, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-53458 — Blueprint Studio API exposed internal exception details

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py retur…

Remote | Information Disclosure
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
5.1 MEDIUM
CVE-2026-53457 — Blueprint Studio terminal command working directory not bounded to config directory

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in custom_components/blueprint_studio/backe…

Remote | Path Traversal
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
5.6 MEDIUM
CVE-2026-53456 — Blueprint Studio terminal SSH private key written to disk

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio terminal SSH key authentication in custom_components/blueprint_studio/backend/t…

| Authentication
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
8.6 HIGH
CVE-2026-53455 — Blueprint Studio Git credential helper command injection

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in custom_components/blueprint_st…

Remote | Misconfiguration
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
6.9 MEDIUM
CVE-2026-53454 — Blueprint Studio stored Git credentials in plaintext Git credential store

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing G…

Remote | Misconfiguration
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-53453 — Blueprint Studio API authorization bypass for non-admin Home Assistant users

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home As…

Remote | Authorization
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
7.0 HIGH
CVE-2026-52817 — Linuxfabrik Monitoring Plugins Sudoers: /usr/bin/apt-get arguments allow privilege escala…

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icin…

| Authorization
Aug 18, 2026 Sep 09, 2026
Aug 18, 2026
Sep 09, 2026
8.1 HIGH
CVE-2026-52793 — Froxlor: API Authentication bypasses 2FA Authentication

Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for an …

froxlor | Remote | Authentication
Aug 18, 2026 Sep 08, 2026
Aug 18, 2026
Sep 08, 2026
5.4 MEDIUM
CVE-2026-41921 — Koha Stored XSS via Purchase Suggestion Handler

Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts …

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 31, 2026
Aug 18, 2026
Aug 31, 2026
5.4 MEDIUM
CVE-2026-18504 — fastify vulnerable to schema validation bypass via root primitive coercion mismatch

fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a request body schema targets a root primitive value. W…

fastify | Injection
Aug 18, 2026 Sep 02, 2026
Aug 18, 2026
Sep 02, 2026
Showing 20 of 15304 Results