Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-51274 — schreibfaul1 ESP32-audioI2S Heap-Based Buffer Overflow

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers to cause a denial of service (application crash), i…

Remote | Memory Corruption
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.8 HIGH
CVE-2026-51273 — ESP32-audioI2S Heap-Based Buffer Overflow

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the ID3 tag parsing function showID3Tag() of the embedded audio streaming library. The program reads untrust…

| Memory Corruption
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
5.9 MEDIUM
CVE-2026-18085 — Improper Input Validation Leads to Arbitrary File Download and Potential Denial of Servic…

An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.

Remote | Path Traversal
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.6 HIGH
CVE-2026-18084 — Cross-Site Scripting (XSS) in time zone parameter of BlackBerry UEM

Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF…

Remote | Cross-Site Scripting
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.6 HIGH
CVE-2026-16313 — Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq -…

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newlin…

Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
4.5 MEDIUM
CVE-2026-8058 — This Power System update is being released to address a sensitive information disclosure

IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into the BMC audit log where an admin use…

openbmc | Remote | Information Disclosure
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
6.5 MEDIUM
CVE-2026-7868 — This Power System update is being released to address incorrect authorization

IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.

openbmc | Remote | Authentication
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
5.5 MEDIUM
CVE-2026-7775 — Cross-site Scripting Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterli…

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2…

sterling_b2b_integrator sterling_file_gateway | Remote | Cross-Site Scripting
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.2 HIGH
CVE-2026-67181 — Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the prox…

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.5 HIGH
CVE-2026-66754 — Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding

Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted p…

Remote | Denial of Service
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
6.3 MEDIUM
CVE-2026-66753 — tiny-http 0.12.0 HTTP Response Splitting via Header Injection

tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header values on both request and …

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.2 HIGH
CVE-2026-66752 — tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling

tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a Transfer-Encoding header with any value, including…

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
5.4 MEDIUM
CVE-2026-66751 — Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room

Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler w…

Remote | Authorization
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
4.3 MEDIUM
CVE-2026-66750 — Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files route

Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they are not a…

Remote | Authorization
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
6.5 MEDIUM
CVE-2026-66749 — Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup

Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid 24-character hex string room parameter that match…

Remote | Denial of Service
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.8 HIGH
CVE-2026-66748 — Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supply…

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
5.4 MEDIUM
CVE-2026-66746 — Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection

Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrary response headers by embedding carriage return (0x0D) or line feed (0x0A)…

Remote | Injection
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
5.4 MEDIUM
CVE-2026-62828 — Microsoft Edge for Android (Chromium-based) Tampering Vulnerability

Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.

Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
7.5 HIGH
CVE-2026-61609 — Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenti…

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single glo…

panel | Remote | Authentication
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
8.1 HIGH
CVE-2026-54593 — Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly gra…

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that conta…

panel | Remote | Authentication
Jul 28, 2026 Jul 28, 2026
Jul 28, 2026
Jul 28, 2026
Showing 20 of 9546 Results