Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-67613 — CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport

CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the …

Remote | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.2 MEDIUM
CVE-2026-19730 — Podman: podman: quadlet install --replace non-truncating write retains removed host-acces…

A flaw was found in Podman 5.8.x. The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fa…

Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-18428 — SQL Query Validation Bypass in OpenSearch Direct Query

A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark w…

opensearch opensearch | Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-12236 — Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero …

The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT server during BT_GATT_DISCOVER_STD_C…

zephyr zephyr | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.7 HIGH
CVE-2024-58374 — Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a pa…

Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.7 HIGH
CVE-2019-25765 — ASP-CMS SQL Injection via commentList.asp id Parameter

ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to…

Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-73652 — vantage6: Algorithm developer can edit another developer's algorithm that is pending / un…

vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer…

| Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-73651 — TypeORM: migration:generate template-literal code injection

TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Prior to versions 0.3.31 and 1.1.0, typeorm migration…

| Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-73650 — SVGO: removeScripts plugin leaves some executable scripts intact

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named r…

| Cross-Site Scripting
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-73266 — Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels…

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the te…

multicluster_engine_for_kubernetes | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-59765 — SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud …

SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

| Server-Side Request Forgery
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-59763 — Unbounded Arch package file metadata can cause resource amplification in Gitea package up…

Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

| Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-59109 — Zalktis: SQL injection via partner-controlled fields in imported e-invoices

SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce expor…

Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-58511 — Webhook Authorization Header Returned in Plaintext via API

Webhook Authorization Header Returned in Plaintext via API

| Information Disclosure
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-58510 — GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code p…

GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

| Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-58508 — Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

| Server-Side Request Forgery
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-58507 — Private Repository Existence Disclosure via go-get Meta Endpoint

Private Repository Existence Disclosure via go-get Meta Endpoint

| Information Disclosure
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-58445 — Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

| Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-58444 — Personal access token scope enforcement bypass on the repository home page (`GET /{owner}…

Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

| Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-58443 — Public-only repository tokens can update private PR head branches

Public-only repository tokens can update private PR head branches

| Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
Showing 20 of 10700 Results