Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-19266 — Kirachon context-engine review-git-diff Endpoint gitUtils.ts execGitCommand command injec…

A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Execut…

| Injection
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
6.4 MEDIUM
CVE-2026-18988 — Easy Accordion <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'a…

The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, and including, 3.1.8. This is due to insufficient i…

Remote | Cross-Site Scripting
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
8.7 HIGH
CVE-2026-13505 — Zeroisation of sensitive key material on garbage collection relies on finalization

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A…

Remote | Cryptography
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
8.7 HIGH
CVE-2026-8798 — Native entropy source retries the CPU entropy instructions without limit

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound. RDSEED and RDRAND report failur…

Remote | Denial of Service
Aug 08, 2026 Aug 08, 2026
Aug 08, 2026
Aug 08, 2026
7.5 HIGH
CVE-2026-52880 — Klever-Go: REST API slow-header connection exhaustion via Gin Engine.Run

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with t…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-52879 — Klever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-driven DoS

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message be…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-52878 — Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can halt the cha…

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData s…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.9 MEDIUM
CVE-2026-49343 — Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / sta…

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a resource-exhaustion flaw that leaks bounded thrott…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.4 MEDIUM
CVE-2026-48122 — Workspace settings can override executable and Gemfile paths used by the Ruby LSP VS Code…

Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to version 0.10.4 could override the path to the Ruby …

| Supply Chain
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.6 HIGH
CVE-2026-48120 — Kakoune has a Critical RCE via Autorestore Backup Filename Injection

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell comm…

| Misconfiguration
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.9 MEDIUM
CVE-2026-48047 — XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (…

XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, a potential path traversal vulnerabilit…

xwiki | Remote | Path Traversal
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-48026 — lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI rende…

lakefs | Remote | Cross-Site Scripting
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-47249 — Klever-Go KVM: Hash-array amplification in P2P resolver request handling

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-array amplification. A connected peer can send a c…

Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.5 MEDIUM
CVE-2026-47127 — Ghostfolio has a Stripe subscription bypass

Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/subscription/stripe/callback?checkoutSessionId=<id>` …

ghostfolio | Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.6 CRITICAL
CVE-2026-46409 — OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<rand…

Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.7 MEDIUM
CVE-2026-64676 — Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with c…

Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vulnerable to an authorization bypas…

kata_containers | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.1 HIGH
CVE-2026-58262 — Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits of the PubKeysBitmap toward the two-thirds validato…

Remote | Misconfiguration
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.1 CRITICAL
CVE-2026-48170 — scimPatch vulnerable to prototype pollution via unfiltered keys in patch

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`…

Remote | Misconfiguration
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.8 HIGH
CVE-2026-48169 — PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues an…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.2 CRITICAL
CVE-2026-47243 — Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-f…

kata_containers | Path Traversal
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
Showing 20 of 9984 Results