Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-55552 — Yamcs: Unauthenticated Directory Traversal

Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm tha…

Remote | Path Traversal
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.5 MEDIUM
CVE-2026-55549 — Yamcs: Reflected XSS in the URL of the Authorize Endpoint

Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize…

Remote | Cross-Site Scripting
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.3 MEDIUM
CVE-2026-55547 — Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authe…

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/m…

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.5 MEDIUM
CVE-2026-55545 — Yamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enfo…

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePacke…

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-55521 — Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.i…

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-55520 — Protego: Exponential backtracking ReDoS in robots.txt URL wildcard matching

Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URLPattern._prepare_pattern_for_regex translates every asterisk in an Allow or Dis…

Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.1 CRITICAL
CVE-2026-55511 — Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs …

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into g…

Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-55509 — WsgiDAV: Blind SQL injection in the MySQL provider

WsgiDAV is a generic and extendable WebDAV server based on WSGI. Prior to 4.3.5, the sample MySQLBrowserProvider in wsgidav/samples/mysql_dav_provider.py concatenates the record key parsed from a req…

Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-55485 — Piccolo Admin: Privilege escalation - admin to superuser via session-token disclosure in …

Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELET…

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-55484 — ALOS HTTP: Unauthenticated remote DoS: malformed path starting with "?" triggers out-of-b…

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPa…

Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.0 MEDIUM
CVE-2026-55425 — Graylog: System Catalog titles endpoint can be used to retrieve values of protected datab…

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/sy…

Remote | Information Disclosure
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.3 CRITICAL
CVE-2026-55378 — JS Recon: Command injection in PR Branch Checker workflow via untrusted pull request cont…

JS Recon is a JavaScript enumeration and SAST tool. From 1.2.1-beta.1 until 1.3.1-beta.2, the PR Branch Checker workflow in .github/workflows/pr_checker.yml places github.head_ref and github.event.pu…

Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.1 CRITICAL
CVE-2026-55248 — plone.app.portlets: Denial of service via RSS feed portlet

plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large…

Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.1 CRITICAL
CVE-2026-55247 — plone.app.event: Denial of service via iCalendar import

plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar a…

Remote | Server-Side Request Forgery
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.7 HIGH
CVE-2026-55245 — Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-l…

Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock a…

Remote | Server-Side Request Forgery
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.3 CRITICAL
CVE-2026-55220 — Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over objec…

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/D…

Remote | Misconfiguration
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-55215 — MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM despite `ssl…

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or se…

Remote | Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.5 HIGH
CVE-2026-55108 — KubeVela Terraform remote loader DoS via unbounded file read

KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in…

Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.3 CRITICAL
CVE-2026-55068 — free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoni…

free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without e…

Remote | Misconfiguration
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.0 MEDIUM
CVE-2026-55067 — Vikunja: Authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-a…

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket} allows the request body project_view_id value to be mass …

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
Showing 20 of 12608 Results