Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-57586 — CodeRAG: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Exec…

CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for a…

| Supply Chain
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
4.4 MEDIUM
CVE-2026-55650 — Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitiz…

| Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.9 MEDIUM
CVE-2026-55617 — Hydro: Insufficient session expiration when recreating sessions

Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session t…

Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-55178 — GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, s…

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the …

Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.1 CRITICAL
CVE-2026-55158 — Conflibot: Command injection via crafted pull request branch names under pull_request_tar…

Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by …

Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.5 MEDIUM
CVE-2026-54637 — Dragonfly scheduler v1 gRPC unauthenticated SSRF via attacker-controlled PeerHost in Down…

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduler's default unauthenticated v1 gRPC flow accepts attacker-controlled PeerHost.I…

dragonfly | Remote | Server-Side Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.9 MEDIUM
CVE-2026-54254 — Cyberdrop-DL: Pixeldrain API key shared with unverified thirdparty sites

Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler uses substring host matching instead of requiring the input host to be an exact…

Remote | Server-Side Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.5 MEDIUM
CVE-2026-54168 — Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to p…

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during we…

Remote | Information Disclosure
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.2 HIGH
CVE-2026-54167 — Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Hos…

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterpri…

Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.1 HIGH
CVE-2026-53966 — XWiki Platform: Privilege escalation from edit to script right through Live Data editing

XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who can edit a page to change that page's rights…

xwiki | Remote | Authorization
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.7 HIGH
CVE-2026-53957 — Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy`…

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in pa…

Remote | Server-Side Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.8 MEDIUM
CVE-2026-52724 — kuma-dp connects to control plane without verifying TLS certificate when no CA is configu…

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an H…

| Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.5 MEDIUM
CVE-2026-50166 — Kuma: kumactl connects to control plane without verifying TLS certificate when no CA is c…

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for …

| Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.1 MEDIUM
CVE-2026-49446 — Cosmos: Authentication bypass via forward-auth header smuggling on Constellation tunnel i…

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go c…

| Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
2.9 LOW
CVE-2026-49254 — Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1…

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/router.go registers GET /api/v1/oauth and GET /api/v1/oauth/:id without jwt.Middl…

dragonfly | Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.5 MEDIUM
CVE-2026-48987 — pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for…

pyload | Remote | Denial of Service
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
4.9 MEDIUM
CVE-2026-48737 — pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/pyload/core/utils/web/check.py relies on Python's global-address classification …

pyload | Remote | Server-Side Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.5 MEDIUM
CVE-2026-48722 — Nextflow: Incorrect default permissions in the nextflow auth login command

Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqer…

| Information Disclosure
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.9 MEDIUM
CVE-2026-47780 — free5GC: UDR Improper ueId validation in free5GC EE subscription handlers allows arbitrar…

free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go val…

free5gc | Remote | Path Traversal
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.2 CRITICAL
CVE-2026-46495 — OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-contr…

Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
Showing 20 of 13220 Results