Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.8 MEDIUM
CVE-2026-72788 — SiYuan before v3.7.4 Information Disclosure via UILayout Filter

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to properly restrict administrator workspace state from publish readers. Unauthenticate…

Remote | Information Disclosure
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.4 MEDIUM
CVE-2026-72787 — Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name

Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privil…

Remote | Cross-Site Scripting
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-72786 — Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset

Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with ed…

Remote | Authentication
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-72508 — Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke servi…

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy att…

Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.3 MEDIUM
CVE-2026-6821 — Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticate…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.5 HIGH
CVE-2026-67579 — Filter expression injection via forged keyset pagination cursor in Ash

Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injecti…

ash | Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-63300 — Cross-project instance move bypasses all project restrictions allowing host command execu…

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted projec…

lxd | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-63299 — Storage volume cross-project move and snapshot restore bypass project disk limits

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operation…

lxd | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-63298 — LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplyin…

lxd | Remote | Injection
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-63297 — Cross-project instance copy bypasses target project restrictions via TOCTOU in config mer…

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance cop…

lxd | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-63296 — Project restriction bypass via instance migration config override

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD acce…

lxd | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.3 MEDIUM
CVE-2026-63295 — Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `se…

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container pri…

lxd | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-63294 — Root RCE via image backup.yaml symlink

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properl…

lxd | Remote | Path Traversal
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-63293 — Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access a…

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate wh…

lxd | Remote | Path Traversal
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-62420 — Cross-project cluster migration bypasses project restrictions via cluster notification fl…

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-pr…

lxd | Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.8 HIGH
CVE-2026-59917 — Dell Display and Peripheral Manager Improper Access Control Vulnerability

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit th…

Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.8 HIGH
CVE-2026-59916 — Dell Display and Peripheral Manager Improper Access Control Vulnerability

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit th…

Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
7.8 HIGH
CVE-2026-59914 — Dell Display and Peripheral Manager Authentication Bypass Vulnerability

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potential…

Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
4.3 MEDIUM
CVE-2026-4879 — Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticate…

Remote | Authorization
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-49466 — Draft List - Contributor Stored Cross-Site Scripting via Draft Title in Custom Drafts Tem…

Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (XSS) in the `[drafts]` shortcode and Draft List wid…

Remote | Cross-Site Scripting
Aug 12, 2026 Aug 12, 2026
Aug 12, 2026
Aug 12, 2026
Showing 20 of 11049 Results