Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-71905 — DrayTek VigorAP Multiple Models OS Command Injection via ExportSettings

Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realt…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71904 — DrayTek VigorAP Multiple Models OS Command Injection via tr069TestInform

Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the eve…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.7 HIGH
CVE-2026-78416 — Authenticated RCE via `condition.config` JSON cleanse bypass

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSO…

Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.8 CRITICAL
CVE-2026-76071 — Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized dest…

Remote | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.8 CRITICAL
CVE-2026-76070 — Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Bas…

Remote | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.7 HIGH
CVE-2026-71366 — Awx: notification backends allow ssrf and credential leakage

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template U…

ansible_automation_platform | Remote | Server-Side Request Forgery
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71364 — Awx: project archive extraction allows path traversal file writes

A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project directory path with the mem…

ansible_automation_platform | Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.4 MEDIUM
CVE-2026-67204 — BookStack < 26.05.4 Broken Access Control via Image Gallery API

BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploit…

bookstack | Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-21752 — HCL Hive is affected by a use of vulnerable third-party components

HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws.

Remote | Supply Chain
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.3 MEDIUM
CVE-2026-13343 — Uninitialised stack memory disclosure in the MIDI 2.0 UMP Stream responder

The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (uint32_t data[4]). The builders make_endpoint_info() and make_function_block_in…

zephyr zephyr | Information Disclosure
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-13212 — Zephyr virtio driver calls an arbitrary function pointer from an out-of-range used-ring d…

The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In virtio_isr() (drivers/virtio/virtio_common.c), the device-written vq->used…

zephyr zephyr | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.7 HIGH
CVE-2026-12556 — HP Easy Start for macOS - Security Update

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasi…

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.7 HIGH
CVE-2026-12555 — HP Easy Start for macOS - Security Update

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasi…

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.5 HIGH
CVE-2026-12554 — HP Easy Start for macOS - Security Update

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasi…

| Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2025-68825 — HCL Hive is affected by incorrect default permissions

HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.

Remote | Misconfiguration
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.4 MEDIUM
CVE-2026-9728 — TOCTOU race in mbox_send syscall verifier allows userspace to leak kernel memory

The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwa…

zephyr zephyr | Race Condition
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.0 HIGH
CVE-2026-78414 — Cross-site scripting in Nx Witness VMS Web Administration allows session token exfiltrati…

Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary Java…

| Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-78391 — Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook

RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view. Cryptocurrency addresses and blockchain names originating from external sources, includ…

Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.4 CRITICAL
CVE-2026-78387 — RansomLook Missing Authorization in Web Configuration Editor Allows Application Configura…

RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint. The endpoint requires an authenticated session but does not perform an …

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-76055 — Black Duck Black Duck C/C++ OS Command Injection Vulnerability

Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7 allows an actor able to create a file within the scanned …

| Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11392 Results