Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2026-57028 — Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attack…

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion…

junos_os_evolved | Remote | Misconfiguration
Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
7.1 HIGH
CVE-2026-57027 — Junos OS: EX4100 Series, EX4400: With sFlow configured in a VC scenario multicast traffic…

A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent …

Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
8.7 HIGH
CVE-2026-57026 — Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP inv…

An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based at…

junos srx5600 srx5800 srx1500 srx300 srx320 +18 more | Remote | Denial of Service
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
6.8 MEDIUM
CVE-2026-57025 — Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-lear…

A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-S…

junos junos_os_evolved ex2300 ex2300-c ex3400 ex4300 +36 more | Denial of Service
Jul 09, 2026 Jul 16, 2026
Jul 09, 2026
Jul 16, 2026
6.9 MEDIUM
CVE-2026-57024 — Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cau…

A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attac…

junos srx5600 srx5800 srx1500 srx300 srx320 +18 more | Remote | Denial of Service
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-57023 — Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd cr…

An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-base…

junos srx5600 srx5800 srx1500 srx300 srx320 +18 more | Remote | Denial of Service
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
8.2 HIGH
CVE-2026-57022 — Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a TCP connectio…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, netw…

junos srx5600 srx5800 srx4100 srx4200 srx4600 +12 more | Remote | Denial of Service
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
6.9 MEDIUM
CVE-2026-57021 — Junos OS: SRX Series: If VPN compliance-check is configured an attacker can cause http-gk…

An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). …

junos srx5600 srx5800 srx1500 srx300 srx320 +14 more | Remote | Memory Corruption
Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
7.1 HIGH
CVE-2026-57020 — Junos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfaces causes a…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacke…

junos qfx10008 qfx10016 | Denial of Service
Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
7.1 HIGH
CVE-2026-57019 — Junos OS: MX Series: Specific traffic causes an FPC to reset

An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cau…

junos mx2010 mx2020 mx240 mx480 mx960 +6 more | Denial of Service
Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
8.1 HIGH
CVE-2026-55689 — OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer …

openfga helm_charts | Remote | Authentication
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
5.3 MEDIUM
CVE-2026-55605 — @arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP Endpoint

DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@arikusi/deepseek-mcp-server` exposes `POST /mcp` withou…

Remote | Authentication
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
8.6 HIGH
CVE-2026-55604 — @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` accepts caller-supplied `session_id` values without bindi…

Remote | Authentication
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
7.4 HIGH
CVE-2026-55424 — Discourse: Topic featured link susceptible to stored XSS

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently normalized and escaped before being rendered in the …

discourse | Remote | Cross-Site Scripting
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
5.4 MEDIUM
CVE-2026-55170 — OpenFGA MySQL backend: case-insensitive collation on identifier columns causes incorrect …

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tup…

openfga helm_charts | Remote | Authorization
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
9.0 CRITICAL
CVE-2026-53963 — Discourse: Stored-XSS in 2FA delete confirmation modal

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete co…

discourse | Remote | Cross-Site Scripting
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
5.4 MEDIUM
CVE-2026-53962 — Discourse: Insufficient SVG sanitization logic

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to cross-site scripti…

discourse | Remote | Cross-Site Scripting
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
6.5 MEDIUM
CVE-2026-53961 — Discourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missi…

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages were signed by Amazon…

discourse | Remote | Authentication
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
7.5 HIGH
CVE-2026-49256 — Discourse: Hidden tag names leaked via category serializers

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as allowed_tags, allo…

discourse | Remote | Information Disclosure
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
6.5 MEDIUM
CVE-2026-46413 — Discourse: Regular users can route multipart uploads into the admin backup store

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadManager into the admi…

discourse | Remote | Misconfiguration
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
Showing 20 of 9550 Results