Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-8169 — ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG

ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which under ce…

Remote | Authentication
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-64612 — Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malform…

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abor…

enterprise_linux enterprise_linux libcupsfilters | Remote | Denial of Service
Jul 20, 2026 Aug 19, 2026
Jul 20, 2026
Aug 19, 2026
5.3 MEDIUM
CVE-2026-55639 — xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_se…

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Creat…

xrdp | Remote | Information Disclosure
Jul 20, 2026 Jul 29, 2026
Jul 20, 2026
Jul 29, 2026
8.0 HIGH
CVE-2026-55626 — xrdp: No authentication required with Xvnc backend on RHEL 9

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with i…

xrdp | Authorization
Jul 20, 2026 Jul 28, 2026
Jul 20, 2026
Jul 28, 2026
7.5 HIGH
CVE-2026-48812 — FreeScout Allows Unauthenticated Access to Legacy Attachment Files

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication for any attachment whose …

freescout | Remote | Authentication
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
5.3 MEDIUM
CVE-2026-46715 — Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity…

Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentication flow can mark a session as fresh after verifying an OAuth account that bel…

flask-security-too | Remote | Authentication
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-45295 — FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation …

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` allows unauthe…

freescout | Remote | Authentication
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
5.4 MEDIUM
CVE-2026-44228 — RT: Stored Cross-Site Scripting via insufficient template escaping

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled dat…

rt request_tracker | Remote | Cross-Site Scripting
Jul 20, 2026 Aug 07, 2026
Jul 20, 2026
Aug 07, 2026
6.1 MEDIUM
CVE-2026-44227 — RT: Reflected Cross-Site Scripting via URL parameters

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can ind…

rt request_tracker | Remote | Cross-Site Scripting
Jul 20, 2026 Aug 07, 2026
Jul 20, 2026
Aug 07, 2026
9.3 CRITICAL
CVE-2026-39878 — Chamilo stored XSS via user registration leads to admin account takeover

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in …

chamilo_lms | Remote | Cross-Site Scripting
Jul 20, 2026 Jul 22, 2026
Jul 20, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-34239 — Chamilo Authenticated Remote Code Execution

Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`…

chamilo_lms | Remote | Authentication
Jul 20, 2026 Jul 22, 2026
Jul 20, 2026
Jul 22, 2026
6.1 MEDIUM
CVE-2026-26483 — Mettle SendPortal Stored Cross-Site Scripting Vulnerability

Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input…

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
Showing 20 of 12452 Results