Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-49255 — electerm: Command Injection in File System Operations (rmrf, mv, cp)

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm constructs operating system commands in src/app/lib/fs.js by interpolating untrust…

electerm | Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.1 HIGH
CVE-2026-49253 — electerm: Path Traversal in Zmodem and Trzsz Download Filename Handling

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames directly with path.join() while receiving Zmodem an…

electerm | Remote | Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.0 HIGH
CVE-2026-48711 — SSHFS: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oProxyCommand=CMD]:/path and find_base_path() remove…

| Misconfiguration
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
9.3 CRITICAL
CVE-2026-47187 — SSHFS Symlink Escape: Rogue SFTP Server → Local File Read/Write

SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory com…

Remote | Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-45742 — Gotenberg: Concurrent Execution using Shared Resource with Improper Synchronization ('Rac…

Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext function in pkg/modules/api/context.go starts one errgroup.Go goroutine for each multipart download…

gotenberg | Remote | Denial of Service
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-45741 — Gotenberg: SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and …

gotenberg | Remote | Server-Side Request Forgery
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.9 MEDIUM
CVE-2026-45274 — MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enfor…

MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserver/handlers/user.py does not enforce the ALLOW_REG…

Remote | Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.7 HIGH
CVE-2026-45273 — MyBooks: Privilege Escalation via Missing Authorization on Admin Settings Endpoint

MyBooks is an ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler for POST /api/admin/settings in webserver/handlers/admin.py applies the auth de…

Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
9.4 CRITICAL
CVE-2026-45272 — MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File

MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler in webserver/handlers/admin.py accepts SOCIAL…

Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.8 HIGH
CVE-2026-44829 — Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filena…

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat backslashes as path…

gotenberg | Remote | Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.3 MEDIUM
CVE-2026-40509 — OpenEMR < 8.3.0 CSRF via DICOM Viewer web_path Parameter

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized as a URL without validation a…

Remote | Cross-Site Request Forgery
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.4 MEDIUM
CVE-2026-40508 — OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to up…

Remote | Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.1 MEDIUM
CVE-2026-40507 — OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. The templateHtml GET parameter is reflected into the page response without …

Remote | Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.3 MEDIUM
CVE-2026-32802 — Dell PowerPath Improper Privilege Management Vulnerability

Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, lead…

powerpath | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.2 HIGH
CVE-2026-23501 — Dell RecoverPoint for VMs OS Command Injection Vulnerability

Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker…

recoverpoint_for_virtual_machines | Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.2 HIGH
CVE-2026-18756 — HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button re…

HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the…

Remote | Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.4 HIGH
CVE-2026-18526 — HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation

HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.

Remote | Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-16818 — Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.

aix | Remote | Denial of Service
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-16817 — Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.

aix | Remote | Denial of Service
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
9.9 CRITICAL
CVE-2026-16816 — Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

aix | Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Showing 20 of 12435 Results