Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-11407 — Pimcore CMS 12.3.8 Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed

Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attackers to execute arbitrary methods on PHP objects by exploiting empty checkMethodAl…

pimcore | Remote | Misconfiguration
Jun 17, 2026 Jun 23, 2026
Jun 17, 2026
Jun 23, 2026
5.9 MEDIUM
CVE-2026-10741 — Nexus Repository Manager - Incorrect Authorization allows credential disclosure via proxy…

Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstr…

nexus_repository_manager | Remote | Authorization
Jun 17, 2026 Jun 23, 2026
Jun 17, 2026
Jun 23, 2026
7.5 HIGH
CVE-2026-10696 — Devolutions UniGetUI Incorrect Name Resolution Remote Code Execution

Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an installed application t…

unigetui | Remote | Misconfiguration
Jun 17, 2026 Jun 24, 2026
Jun 17, 2026
Jun 24, 2026
7.1 HIGH
CVE-2026-55198 — Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endp…

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_…

hermes_web_ui | Remote | Authorization
Jun 17, 2026 Jun 17, 2026
Jun 17, 2026
Jun 17, 2026
7.1 HIGH
CVE-2026-55197 — Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can b…

hermes_web_ui | Remote | Authorization
Jun 17, 2026 Jun 17, 2026
Jun 17, 2026
Jun 17, 2026
9.1 CRITICAL
CVE-2026-55196 — Hermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication Bypass

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES…

Remote | Authentication
Jun 17, 2026 Jun 23, 2026
Jun 17, 2026
Jun 23, 2026
8.6 HIGH
CVE-2026-53871 — Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile C…

Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenti…

hermes_web_ui | Remote | Authorization
Jun 17, 2026 Jun 18, 2026
Jun 17, 2026
Jun 18, 2026
6.8 MEDIUM
CVE-2026-53870 — Hermes Agent < 0.16.0 - Sensitive File Permission Vulnerability in Store Files

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attack…

Jun 17, 2026 Jun 17, 2026
Jun 17, 2026
Jun 17, 2026
8.7 HIGH
CVE-2026-53869 — Hermes Agent < 0.16.0 - DNS Rebinding Bypass via WebSocket Endpoints

Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute fo…

hermes-agent | Remote | Misconfiguration
Jun 17, 2026 Jun 18, 2026
Jun 17, 2026
Jun 18, 2026
7.5 HIGH
CVE-2026-48818 — Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to …

starlette | Remote | Server-Side Request Forgery
Jun 17, 2026 Jun 30, 2026
Jun 17, 2026
Jun 30, 2026
7.4 HIGH
CVE-2026-9697 — undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 P…

Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to N…

undici | Misconfiguration
Jun 17, 2026 Jul 02, 2026
Jun 17, 2026
Jul 02, 2026
5.9 MEDIUM
CVE-2026-9679 — undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 §…

undici | Injection
Jun 17, 2026 Jun 25, 2026
Jun 17, 2026
Jun 25, 2026
5.9 MEDIUM
CVE-2026-9678 — undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as p…

undici | Misconfiguration
Jun 17, 2026 Jun 25, 2026
Jun 17, 2026
Jun 25, 2026
8.8 HIGH
CVE-2026-7300 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in R…

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Overflow.This issue aff…

connext_professional | Remote | Memory Corruption
Jun 17, 2026 Jun 17, 2026
Jun 17, 2026
Jun 17, 2026
8.8 HIGH
CVE-2026-6734 — undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse

Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched…

undici | Remote | Misconfiguration
Jun 17, 2026 Jul 02, 2026
Jun 17, 2026
Jul 02, 2026
3.7 LOW
CVE-2026-6733 — undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idl…

undici | Misconfiguration
Jun 17, 2026 Jun 27, 2026
Jun 17, 2026
Jun 27, 2026
9.8 CRITICAL
CVE-2026-53805 — NVIDIA SIL GEN3C Unauthenticated RCE via Pickle Deserialization in Inference API

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deseri…

Remote | Injection
Jun 17, 2026 Jun 22, 2026
Jun 17, 2026
Jun 22, 2026
4.8 MEDIUM
CVE-2026-48591 — Stored XSS via unescaped HTML attribute values in earmark

Improper Neutralization of Script in Attributes in a Web Page vulnerability in pragdave earmark allows stored cross-site scripting via unescaped HTML attribute values. 'Elixir.Earmark.Transform':_ma…

earmark | Cross-Site Scripting
Jun 17, 2026 Jun 22, 2026
Jun 17, 2026
Jun 22, 2026
7.5 HIGH
CVE-2026-47774 — Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK ampl…

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request proc…

envoy | Remote | Denial of Service
Jun 17, 2026 Jun 30, 2026
Jun 17, 2026
Jun 30, 2026
9.2 CRITICAL
CVE-2026-3894 — Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Over…

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from…

connext_professional | Remote | Memory Corruption
Jun 17, 2026 Jun 17, 2026
Jun 17, 2026
Jun 17, 2026
Showing 20 of 7970 Results