Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-78250 — bytebot-ai bytebot Agent Execution Workflow infinite loop

A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component Agent Execution Workflow. Such manipulation leads to infinite loop. The attack…

| Denial of Service
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.7 HIGH
CVE-2026-76848 — TypeORM 0.2.21 through 1.1.0 SQL Injection via SelectQueryBuilder.distinctOn

TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family drivers, createSelectDistinctExpression in src/query-…

Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-76847 — act 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 Backend

act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSigne…

act | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.8 MEDIUM
CVE-2026-76845 — adm-zip 0.5.9 through 0.6.0 Arbitrary File Overwrite via Symlink Following on Extraction

adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive entry name again…

| Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.3 HIGH
CVE-2026-76844 — webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Terminated publicPa…

webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset. The guard, U…

Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.4 HIGH
CVE-2026-76843 — Flair 0.15.0 and 0.15.1 Deserialization of Untrusted Data via ClusteringModel.load

The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes a…

| Supply Chain
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-76842 — Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Paymen…

The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into the outgoing reques…

Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-76841 — Xinference through 2.11.0 Remote Code Execution via Hardcoded trust_remote_code in Model …

Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True …

Remote | Supply Chain
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.6 CRITICAL
CVE-2026-76840 — RustDesk through 1.4.9 Heap Buffer Overflow via Unvalidated CLIPRDR FileContentsResponse …

RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Rea…

Remote | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.2 CRITICAL
CVE-2026-78372 — RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data

RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked as private. An unauthenticated or otherwise unauthorized remote attacker can a…

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
10.0 CRITICAL
CVE-2026-77995 — Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client…

Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.

Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.2 CRITICAL
CVE-2026-78370 — RansomLook Unauthenticated Database Export Exposes Private Data

RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private. The /export/<dat…

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-78248 — SourceCodester Simple Online Food Ordering System ajax.php save_settings sql injection

A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-78369 — Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLook

RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint provides an administrative function for creating new crypto group entries, it wa…

Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.5 MEDIUM
CVE-2026-78323 — Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without …

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.3 MEDIUM
CVE-2026-78291 — WordPress RepairBuddy plugin <= 4.1223 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.5 MEDIUM
CVE-2026-78290 — WordPress Magazine Blocks plugin <= 1.8.6 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.

magazine_blocks | Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
4.3 MEDIUM
CVE-2026-78280 — WordPress Hash Form plugin <= 1.4.0 - Cross Site Request Forgery (CSRF) vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.

hash_form | Remote | Cross-Site Request Forgery
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.4 MEDIUM
CVE-2026-78279 — WordPress Fluent Support Pro plugin <= 2.3.1 - Cross Site Request Forgery (CSRF) vulnerab…

Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.

Remote | Cross-Site Request Forgery
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.3 MEDIUM
CVE-2026-78278 — WordPress Fluent Boards Pro plugin <= 2.0.11 - Insecure Direct Object References (IDOR) v…

Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11307 Results