Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-74785 — Scriban before 7.0.0 Denial of Service via Unbounded Resource Consumption

Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigI…

Remote | Denial of Service
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
8.7 HIGH
CVE-2026-74784 — Scriban before 7.2.0 Denial of Service via array.insert_at

Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attack…

Remote | Denial of Service
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.5 HIGH
CVE-2026-74783 — Scriban 6.6.0 through 7.2.0 Parser Recursion Denial of Service

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with …

Remote | Denial of Service
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.5 HIGH
CVE-2026-73062 — Scriban 3.0.0 through 7.2.0 Denial of Service via Array Multiplication

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic check…

Remote | Denial of Service
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
9.8 CRITICAL
CVE-2026-73061 — Scriban before 7.2.2 Arbitrary Property Write via TypedObjectAccessor

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can m…

Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.5 HIGH
CVE-2026-73060 — Scriban 3.0.0 through 7.2.5 Denial of Service via ScriptRange.Multiply

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers ca…

Remote | Denial of Service
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.5 MEDIUM
CVE-2026-73059 — stoatchat before 0.15.0 Permission Bypass via message_fetch

stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requiring ReadMessageHistory. Attackers with ViewChann…

Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
5.8 MEDIUM
CVE-2026-73058 — stoatchat before 0.15.0 SSRF via IPv6 unspecified address bypass

stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. A…

Remote | Server-Side Request Forgery
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.5 HIGH
CVE-2026-73057 — stoatchat before 0.15.0 Uncapped SVG Rendering Denial of Service

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extr…

Remote | Denial of Service
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
9.8 CRITICAL
CVE-2026-73056 — SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.To…

siyuan | Remote | Authentication
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-72888 — Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of…

Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores results in a process-global hash with no bound an…

| Memory Corruption
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-72887 — Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently d…

Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.…

| Authentication
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
0.0 NA
CVE-2026-19349 — Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from …

Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO sessi…

| Authentication
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.5 HIGH
CVE-2024-58375 — OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As …

Remote | Misconfiguration
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
9.3 CRITICAL
CVE-2026-74251 — Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoc…

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specification) GET array parameters on Phoca Cart's public s…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.1 HIGH
CVE-2026-74578 — crypto: algif_skcipher - force synchronous processing on trees without ctx->state

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processing on trees without ctx->state The AIO/async path in skcipher_recvmsg() passes…

linux_kernel | Cryptography
Aug 16, 2026 Aug 17, 2026
Aug 16, 2026
Aug 17, 2026
9.8 CRITICAL
CVE-2024-13784 — Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP …

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted i…

arforms_form_builder | Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
7.2 HIGH
CVE-2026-2497 — Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via Gallery Image…

The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all versions up to, and including, 4.7.9. This is due to insu…

Remote | Injection
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
6.4 MEDIUM
CVE-2026-2357 — Bold Page Builder <= 5.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions up to, and including, 5.6.8 due to insufficient in…

bold_page_builder | Remote | Cross-Site Scripting
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
4.3 MEDIUM
CVE-2026-18347 — Kirki <= 6.1.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Informati…

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.1.1. This is due to the plugin not p…

Remote | Authorization
Aug 16, 2026 Aug 16, 2026
Aug 16, 2026
Aug 16, 2026
Showing 20 of 11118 Results