Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-19629 — Privilege Escalation

A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to othe…

security_center | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-12366 — Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object …

Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its reference count reaches zero, after running a per-obj…

zephyr zephyr | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.8 MEDIUM
CVE-2026-12365 — Use-after-free in Zephyr delayable work-queue cancellation under SMP timing race

A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work item's timeout has been dequeued and its handler w…

zephyr zephyr | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.4 HIGH
CVE-2026-12364 — Missing user-space pointer validation in logging syscall z_log_msg_static_create allows k…

The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, and data arguments di…

zephyr zephyr | Information Disclosure
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.2 MEDIUM
CVE-2026-12363 — Out-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0

The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does not validate the fragment counter in a received DATA_FRAGMENT command before forwarding it to the c…

zephyr zephyr | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-73846 — CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vert…

Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.3 MEDIUM
CVE-2026-73845 — CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to valida…

Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
3.7 LOW
CVE-2026-73844 — CKAN MCP Server: Information disclosure via verbose error reflection

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanit…

Remote | Server-Side Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.1 HIGH
CVE-2026-49989 — CrateDB's Blob HTTP handler bypasses authorization

CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in …

cratedb | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.1 HIGH
CVE-2026-49986 — Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`

The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code …

| Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
0.0 NONE
CVE-2026-49826 — Concourse login flow has an open redirect issue

Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to…

Remote | Information Disclosure
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.1 MEDIUM
CVE-2026-47766 — crun follows rootfs /dev symlink while creating default devices

crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle …

crun | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
2.1 LOW
CVE-2026-47192 — kas's late signature validation may allow unnoticed repository manipulations

kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to validating signat…

Remote | Supply Chain
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
2.1 LOW
CVE-2026-47191 — kas checks out SHA-like git branches as valid commits

kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state val…

Remote | Supply Chain
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-46603 — Excessive memory allocation during VP8L decoding in golang.org/x/image

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to c…

Remote | Denial of Service
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.8 HIGH
CVE-2026-46439 — compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template…

compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author j…

| Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.7 MEDIUM
CVE-2026-46380 — compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get()…

| Server-Side Request Forgery
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19845 — TOTOLINK A800R lan.so cstecgi.cgi setStaticDhcpConfig stack-based overflow

A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulati…

a800r | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.0 HIGH
CVE-2026-19844 — TOTOLINK A800R ipv6.so cstecgi.cgi setRadvdCfg stack-based overflow

A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulati…

a800r | Remote | Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
3.1 LOW
CVE-2026-19841 — TRENDNET TEW-813DRU vsftpd vsftpd.conf default permission

A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect default permissions. The…

tew-813dru tew-813dru | Remote | Misconfiguration
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
Showing 20 of 10608 Results