Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-59901 — Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable …

Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.9 MEDIUM
CVE-2026-59900 — Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads…

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCode…

Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.9 MEDIUM
CVE-2026-59899 — Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining L…

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentComp…

Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.3 MEDIUM
CVE-2026-54705 — mathlive's Lack of Escaping of HTML allows for XSS

MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode content in \text{} and \mbox{} commands in Box.toMarkup at src/core/box.ts, in xmlEsc…

Remote | Cross-Site Scripting
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.8 CRITICAL
CVE-2026-41939 — Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administra…

Remote | Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.0 HIGH
CVE-2026-40272 — Vulnerability in the QNX libtraceparser Impacts QNX Software Development Platform

Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash i…

qnx_software_development_platform | Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.3 CRITICAL
CVE-2026-18236 — Google-ADK Continuation Forgery

A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute u…

Remote | Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.0 HIGH
CVE-2026-14266 — 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User in…

| Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.5 MEDIUM
CVE-2026-13723 — Develar's electron-builder allows arbitrary file overwrite

A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization Collision combined …

Remote | Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.7 HIGH
CVE-2026-8339 — SQL Injection in Coverity Connect SOAP API

A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted pay…

Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.2 CRITICAL
CVE-2026-8338 — Authentication and Authorization Bypass in Coverity Connect

A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafte…

Remote | Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.1 HIGH
CVE-2026-67194 — Courier IMAP < 6.0.1 Mail Server < 2.0.2 Stack Overflow DoS via Nested SEARCH Queries

Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The SEARCH command parser (all…

Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-64560 — posix-cpu-timers: Prevent UAF caused by non-leader exec() race

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a non-leader exec() related…

| Race Condition
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-64559 — s390/pkey: Check length in PKEY_VERIFYPROTK ioctl

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer length request structure provided by user-space and…

| Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-64558 — s390/pkey: Check length in pkey_pckmo handler implementation

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler implementation Explicitly check the length of the target buffer in the pkey_pckmo i…

| Memory Corruption
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.2 HIGH
CVE-2026-54727 — proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verif…

| Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.2 HIGH
CVE-2026-54693 — ZITADEL Users Can Self-Verify Email/Phone via API

ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API paths in internal/co…

Remote | Authorization
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
9.9 CRITICAL
CVE-2026-54680 — Logging operator has Fluentd configuration injection that allows remote code execution

Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go …

logging-operator | Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.2 HIGH
CVE-2026-54574 — `proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar…

proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/in…

| Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
2.0 LOW
CVE-2026-52791 — fuse-overlayfs release-1.x preserves SUID/SGID bits after truncate/open(O_TRUNC)

fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate…

| Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
Showing 20 of 9585 Results