Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-55491 — BigBlueButton: Stored XSS in Screenshare Recording Playback via Unescaped Meeting Name

BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screensha…

Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
4.9 MEDIUM
CVE-2026-55489 — BigBlueButton: IDOR on BBB through /api/graphql via POST parameter "presentationId" leads…

BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another mee…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.5 MEDIUM
CVE-2026-55015 — Microsoft Remote Help Denial of Service Vulnerability

Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.1 HIGH
CVE-2026-55013 — Windows Remote Help Defense Spoofing Vulnerability

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-54509 — TREK IDOR: any authenticated user can read another user's journey share token (full journ…

TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns the result of getJourneyShareLink() from server/src/…

trek | Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.3 MEDIUM
CVE-2026-54508 — TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps …

TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() and importNaverList() in server/src/services/placeSe…

trek | Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
2.0 LOW
CVE-2026-54505 — TREK: Stored cross-user HTML injection via trip title in the Journey suggestion banner

TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped activeSuggestion.title value into journey.frontpage.suggestionText through …

trek | Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.7 MEDIUM
CVE-2026-54389 — Ghidra < 12.1.3 PDB Parser Uncontrolled Heap Growth DoS via AbstractPdb

Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted PDB file with an oversi…

| Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.9 MEDIUM
CVE-2026-50192 — Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target…

Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKe…

Remote | Information Disclosure
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.3 HIGH
CVE-2026-49436 — LinkAce vulnerable to stored XSS via 'javascript:' URI in Bulk Link API

LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authe…

Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
3.7 LOW
CVE-2026-49245 — SFTPGo: Stored XSS via inline parameter on public shares and user file download

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Co…

sftpgo | Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.9 MEDIUM
CVE-2026-49244 — SFTPGo: Path confinement bypass in public browsable share partial ZIP download

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entrie…

sftpgo | Remote | Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-49217 — Mailu missing authentication on PATCH /api/v1/token/<id>, which allows unauthenticated re…

Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.5 HIGH
CVE-2026-46682 — BigBlueButton: Blind SQL Injection AUTH (Moderator)

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVi…

Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.1 HIGH
CVE-2026-46355 — BigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinEx…

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/…

Remote | Authentication
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.7 MEDIUM
CVE-2026-19783 — Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds ke…

aix aix powervm_vios | Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.8 HIGH
CVE-2026-19449 — Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.

aix aix powervm_vios | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-19448 — Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cau…

aix aix powervm_vios | Remote | Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-19446 — Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requir…

aix aix powervm_vios | Remote | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.2 HIGH
CVE-2026-19442 — Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege…

aix aix powervm_vios | Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
Showing 20 of 11681 Results