Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-81698 — openssl_encrypt before 1.4.9 Shell Injection via info command

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can …

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.7 HIGH
CVE-2026-81697 — openssl_encrypt before 1.4.9 KDF Downgrade via CWD-relative Configuration

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user pat…

Remote | Misconfiguration
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.3 CRITICAL
CVE-2026-81696 — openssl_encrypt before 1.4.9 Terminal Injection via info Command

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to rep…

Remote | Information Disclosure
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.3 CRITICAL
CVE-2026-81695 — openssl_encrypt before 1.4.9 Terminal Injection via key_id

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id conta…

Remote | Information Disclosure
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.3 CRITICAL
CVE-2026-81694 — verify-usb before 1.4.9 Output Injection via Unsanitized Filenames

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command…

Remote | Information Disclosure
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.7 HIGH
CVE-2026-81693 — openssl_encrypt before 1.4.9 Denial of Service via QR total field

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger u…

Remote | Denial of Service
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.7 HIGH
CVE-2026-81692 — openssl_encrypt before 1.4.9 Denial of Service via STREAMINFO

openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files before using it to size an allocation (np.random.randint(siz…

Remote | Denial of Service
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.7 HIGH
CVE-2026-81691 — openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs

openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path…

Remote | Misconfiguration
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.7 HIGH
CVE-2026-81690 — verify-usb before 1.4.9 Symlink Directory Traversal Code Execution

openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not desc…

Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.7 HIGH
CVE-2026-81689 — openssl_encrypt before 1.4.9 Weak Pepper Key Derivation

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with …

Remote | Cryptography
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.7 HIGH
CVE-2026-81688 — openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256

openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plaint…

Remote | Cryptography
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.7 HIGH
CVE-2026-81687 — openssl_encrypt before 1.4.9 Denial of Service via KDF

openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with extremely high KDF iteratio…

Remote | Denial of Service
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.9 MEDIUM
CVE-2026-81686 — openssl_encrypt before 1.4.9 D-Bus Properties Authorization Bypass

openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any l…

| Misconfiguration
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.3 CRITICAL
CVE-2026-81685 — openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata

openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal con…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.9 MEDIUM
CVE-2026-81684 — openssl_encrypt before 1.4.9 Information Disclosure via Command Line

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the --stego-password argument (o…

| Information Disclosure
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.6 HIGH
CVE-2026-81683 — openssl_encrypt before 1.4.9 Plaintext Private Key Storage

openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Sett…

| Information Disclosure
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.6 HIGH
CVE-2026-81682 — openssl_encrypt before 1.4.9 Insecure File Permissions

openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read…

| Misconfiguration
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.3 CRITICAL
CVE-2026-81681 — openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspa…

Remote | Cryptography
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.3 CRITICAL
CVE-2026-81680 — openssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot Removal

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. At…

Remote | Cryptography
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.3 HIGH
CVE-2026-81679 — OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification API

OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notific…

Remote | Information Disclosure
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Showing 20 of 12307 Results