Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-48374 — Bridge | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (…

Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vul…

bridge | Path Traversal
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
4.6 MEDIUM
CVE-2026-48058 — nebula-mesh: Session and OIDC state cookies lack the Secure attribute

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on eve…

Remote | Cryptography
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
5.5 MEDIUM
CVE-2026-47768 — nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, pro…

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs).…

| Information Disclosure
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.1 HIGH
CVE-2026-47726 — nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGetAuditLog does no admin check. The route is bearer…

Remote | Authorization
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
6.9 MEDIUM
CVE-2026-47725 — nebula-mesh: Web UI lacks CSRF tokens on /ui/* mutating endpoints

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DELETE route processes the request as soon as the se…

Remote | Cross-Site Request Forgery
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.8 HIGH
CVE-2026-18107 — Criu: criu: container escape via rseq critical section hijack during checkpoint/restore

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasit…

Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
0.0 NA
CVE-2026-16771 — CVE-2026-16771

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaS…

| Authentication
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
10.0 CRITICAL
CVE-2026-16498 — terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP state…

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be us…

| Authentication
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.9 HIGH
CVE-2026-16496 — terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID…

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID t…

| Authorization
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.8 HIGH
CVE-2026-15992 — WP Password Policy <= 3.7.1 - Authenticated (Subscriber+) Privilege Escalation

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the …

Remote | Authorization
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
6.5 MEDIUM
CVE-2026-15304 — Plugin Organizer <= 10.2.4 - Authenticated (Subscriber+) SQL Injection

The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4. This is due to insufficient escaping on the user-…

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.6 HIGH
CVE-2026-14869 — terraform-mcp-server vulnerable to server side request forgery leading to token exposure

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the ser…

| Server-Side Request Forgery
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
6.3 MEDIUM
CVE-2026-57511 — SuperPlane < 0.30.0 SMTP Header Injection via Webhook Event Title

SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by including CRLF sequences in the event payload title …

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.8 HIGH
CVE-2026-57510 — SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC

SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to …

Remote | Authorization
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
0.0 NA
CVE-2026-48060 — Litestar: HTML Injection Through CSRF Token

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HT…

| Cross-Site Scripting
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
0.0 NA
CVE-2026-11391 — Tanium addressed a SQL injection vulnerability in Patch.

Tanium addressed a SQL injection vulnerability in Patch.

| Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.5 HIGH
CVE-2026-59933 — PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up t…

phpspreadsheet | Remote | Denial of Service
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.7 HIGH
CVE-2026-59931 — PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up t…

phpspreadsheet | Remote | Server-Side Request Forgery
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.5 HIGH
CVE-2026-54635 — pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the Authorization heade…

Remote | Authentication
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.6 HIGH
CVE-2026-48388 — Photoshop Installer | CWE-427: Uncontrolled Search Path Element

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could …

photoshop_installer | Path Traversal
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
Showing 20 of 9500 Results