Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-13734 — Zephyr WireGuard mutates peer state before anti-replay check, enabling capture-replay end…

Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c validated the anti-replay counter too late. After AEAD decryption of a MESSAGE_TRAN…

zephyr zephyr | Race Condition
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
0.0 NA
CVE-2026-55678 — Arc: Unauthenticated cluster node admission when `cluster.shared_secret` is unset

Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is true …

| Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.7 HIGH
CVE-2026-75118 — http_gdpr_decrypt Pre-Authentication Stack-Based Buffer Overflow

A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login e…

| Memory Corruption
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-81533 — MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT Values

An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The iss…

Remote | Memory Corruption
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
0.0 NA
CVE-2026-55763 — Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop a…

| Misconfiguration
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-81532 — BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to Memory Corrup…

A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length…

Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
0.0 NA
CVE-2026-55891 — PrivateBin: Reflected JSON injection in backend responses via unescaped REQUEST_URI

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE…

| Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.7 HIGH
CVE-2026-81520 — MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhau…

A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to c…

Remote | Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
0.0 NA
CVE-2026-55696 — PrivateBin: Stored Cross-Side-Scripting (XSS) vulnerability in attachment download link v…

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAttachment in js/privatebin.js uses getAttachmentMimeType to accept attacker-c…

| Cross-Site Scripting
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.1 MEDIUM
CVE-2026-82343 — Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-c…

A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads…

enterprise_linux enterprise_linux | Memory Corruption
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-82329 — Potential authentication bypass leading to administrative access in Artifactory

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

artifactory | Remote | Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.5 MEDIUM
CVE-2026-82306 — StarRocks Query Detail Endpoint Returns Every User's Query History

StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges…

Remote | Information Disclosure
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.1 HIGH
CVE-2026-82291 — HeyForm Reflects Any Origin in CORS Responses While Allowing Credentials

HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated Grap…

Remote | Cross-Site Request Forgery
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.0 MEDIUM
CVE-2026-82290 — Chainlit Feedback Endpoints Missing Ownership Validation

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback…

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.3 HIGH
CVE-2026-82289 — Gitingest Prefix-Based Git Host Check Enables Request Forgery and Token Disclosure

Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab., or github. prefix regardless of known-hosts list membership. Attackers can sub…

Remote | Server-Side Request Forgery
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.7 HIGH
CVE-2026-82288 — Stable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flags

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth …

stable-diffusion-webui | Remote | Information Disclosure
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.6 HIGH
CVE-2026-82287 — Rybbit Reflects Any Origin in CORS Responses While Allowing Credentials

Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while …

Remote | Misconfiguration
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-82286 — gpt-crawler Arbitrary File Write via outputFileName Parameter

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can…

Remote | Path Traversal
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-82285 — BISHENG Unauthenticated Server-Side Request Forgery via Workflow Report Callback

bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions …

Remote | Server-Side Request Forgery
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.6 HIGH
CVE-2026-82284 — Quivr Chat Endpoints Missing Ownership Validation

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers …

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
Showing 20 of 12622 Results