Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.2 CRITICAL
CVE-2026-63304 — AVideo through 29.0 OS Command Injection via listFFmpegProcesses

AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside s…

avideo | Remote | Injection
Jul 16, 2026 Jul 20, 2026
Jul 16, 2026
Jul 20, 2026
5.0 MEDIUM
CVE-2026-12391 — ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbit…

An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes pred…

| Path Traversal
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.0 CRITICAL
CVE-2026-11386 — ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injec…

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu…

Remote | Injection
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
7.6 HIGH
CVE-2025-71388 — stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions

stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because …

delta | Remote | Authorization
Jul 16, 2026 Jul 20, 2026
Jul 16, 2026
Jul 20, 2026
8.7 HIGH
CVE-2025-71377 — stoatchat before 20250210-1 Unrestricted Message History Fetch

stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limi…

delta | Remote | Denial of Service
Jul 16, 2026 Jul 20, 2026
Jul 16, 2026
Jul 20, 2026
6.9 MEDIUM
CVE-2024-58360 — stoatchat before 0.7.8 Unrestricted Account Creation

stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts…

Remote | Authentication
Jul 16, 2026 Jul 18, 2026
Jul 16, 2026
Jul 18, 2026
6.3 MEDIUM
CVE-2026-59249 — Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict …

Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on…

mint | Remote | Injection
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
8.2 HIGH
CVE-2026-35149 — HCL DFXServer is affected by an Authentication Bypass vulnerability via server response m…

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering…

dfx_server | Remote | Authentication
Jul 16, 2026 Jul 21, 2026
Jul 16, 2026
Jul 21, 2026
6.3 MEDIUM
CVE-2026-35148 — HCL DFXServer is affected by a Missing Access Control vulnerability

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows…

dfx_server | Remote | Authentication
Jul 16, 2026 Jul 21, 2026
Jul 16, 2026
Jul 21, 2026
8.2 HIGH
CVE-2026-35147 — HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access.

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allow…

dfx_server | Remote | Authentication
Jul 16, 2026 Jul 21, 2026
Jul 16, 2026
Jul 21, 2026
6.3 MEDIUM
CVE-2026-35146 — HCL DFXServer is affected by an Unencrypted Communication vulnerability.

HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a re…

dfx_server | Remote | Cryptography
Jul 16, 2026 Jul 21, 2026
Jul 16, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2023-49900 — Origin Validation Error in X-Rite MA-T6

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

ma-t6 | Remote | Injection
Jul 16, 2026 Jul 16, 2026
Jul 16, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2023-49899 — Origin Validation Error in X-Rite MA-T6

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

ma-t6 | Remote | Authentication
Jul 16, 2026 Jul 18, 2026
Jul 16, 2026
Jul 18, 2026
9.6 CRITICAL
CVE-2026-22752 — Spring Security Authorization Server Dynamic Client Registration endpoints perform insuff…

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1…

Remote | Authentication
Jul 16, 2026 Jul 21, 2026
Jul 16, 2026
Jul 21, 2026
Showing 20 of 11274 Results