Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-67340 — ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authe…

Remote | Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
5.3 MEDIUM
CVE-2026-67339 — guzzlehttp/guzzle before 7.14.2 Proxy-Authorization Header Disclosure

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server acces…

guzzle | Remote | Misconfiguration
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.1 MEDIUM
CVE-2026-67338 — JupyterLab before 4.5.9 Stored XSS via Extension Manager

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious Py…

jupyterlab | Remote | Cross-Site Scripting
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.5 MEDIUM
CVE-2026-67337 — better-auth before 1.4.9 Two-Factor Authentication Bypass via session.cookieCache

better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated route…

better-auth\/oauth-provider | Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
8.7 HIGH
CVE-2026-67336 — better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploi…

better-auth\/oauth-provider | Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
5.3 MEDIUM
CVE-2026-67335 — better-auth before 1.6.2 OAuth State Validation Bypass

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and …

better-auth\/oauth-provider | Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
3.8 LOW
CVE-2026-67334 — better-auth Stale Sessions Persist After User Deletion

better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. …

better-auth\/oauth-provider | Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.2 HIGH
CVE-2026-67333 — better-auth before 1.6.13 Stored XSS via javascript redirect_uri

better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin…

better-auth\/oauth-provider | Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.4 MEDIUM
CVE-2026-67332 — @better-auth/oauth-provider before 1.7.0-beta.4 Authorization Bypass

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an O…

better-auth\/oauth-provider | Remote | Authorization
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
8.3 HIGH
CVE-2026-67331 — better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attac…

Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
9.9 CRITICAL
CVE-2026-67330 — better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject pr…

Remote | Authorization
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.1 HIGH
CVE-2026-67329 — @better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subscription

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organi…

Remote | Authorization
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
8.1 HIGH
CVE-2026-67328 — @better-auth/sso before 1.6.21 Account Takeover via SSO

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domai…

Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
8.3 HIGH
CVE-2026-67327 — better-auth before 1.6.22 Account Takeover via Magic-Link Email-OTP

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign…

better-auth\/oauth-provider | Remote | Authentication
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.0 HIGH
CVE-2026-67326 — GitPython before 3.1.50 Newline Injection via config_writer section

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject…

gitpython | Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
8.8 HIGH
CVE-2026-67325 — GitPython before 3.1.51 Command Injection via option prefix abbreviation

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by us…

gitpython | Remote | Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
9.8 CRITICAL
CVE-2026-67324 — GitPython 3.1.50 Authentication Bypass via Joined Short Options

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes att…

gitpython | Remote | Misconfiguration
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
8.4 HIGH
CVE-2026-67323 — GitPython before 3.1.51 Command Injection via unguarded Git options

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-…

gitpython | Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67322 — GitPython before 3.1.52 Environment Variable Exfiltration via clone_from

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls…

gitpython | Remote | Information Disclosure
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.9 MEDIUM
CVE-2026-67321 — axios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via maxDepth bypass

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who contr…

axios | Remote | Denial of Service
Aug 01, 2026 Aug 02, 2026
Aug 01, 2026
Aug 02, 2026
Showing 20 of 9258 Results