Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.3 LOW
CVE-2026-46712 — Misskey: Lack of proper permission checks in Direct Messaging feature

Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certa…

misskey | Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
3.1 LOW
CVE-2026-18682 — OpenAkita File Upload API upload cross site scripting

A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload API. The manipulation of the argument File…

openakita | Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.2 HIGH
CVE-2026-10849 — Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response bo…

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). T…

zephyr zephyr | Remote | Memory Corruption
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.2 HIGH
CVE-2026-69246 — Guzzle: Noncanonical host can bypass host-based checks

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the …

guzzle | Remote | Server-Side Request Forgery
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.5 MEDIUM
CVE-2026-69245 — Guzzle: Noncanonical cookie domain keeps subdomain scope

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Do…

guzzle | Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.1 HIGH
CVE-2026-69244 — AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked …

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a …

aiohttp | Remote | Memory Corruption
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.3 MEDIUM
CVE-2026-69243 — AIOHTTP: HTTP request smuggling via WebSocket upgrade

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If usin…

aiohttp | Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.8 CRITICAL
CVE-2026-69240 — Sequelize: SQL Injection (Oracle DB)

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the v…

sequelize | Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-67976 — Fprime Ref::SignalGen Denial of Service Vulnerability

The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe paramete…

| Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-67972 — NASA cFS Path Traversal Information Disclosure

An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure.

| Path Traversal
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.4 HIGH
CVE-2026-66065 — Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys …

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Sever…

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-52521 — Z-BlogPHP SQL Injection

A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-52520 — Emlog CMS Stored Cross-Site Scripting Vulnerability

Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript c…

| Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-52102 — OpenMediaVault OS Command Injection

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-51775 — FastAdmin SQL Injection Vulnerability

SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-51190 — Serverless-Devs OS Command Injection

The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in ".git" bypasses the only input check, all…

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.4 MEDIUM
CVE-2026-49132 — OPNsense < 26.1.9 Stored XSS via Certificate Description Field

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate descrip…

Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.4 MEDIUM
CVE-2026-49131 — OPNsense < 26.1.9 Stored XSS via Firewall Rule Description Field

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embe…

Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.5 HIGH
CVE-2026-48113 — Chisel: ACL Bypass via Post-Handshake SSH Channel ExtraData Injection

Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destin…

Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.3 CRITICAL
CVE-2026-48063 — Baileys has message upsert / hist sync spoofing and app state corruption when using malic…

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage an…

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
Showing 20 of 9416 Results