Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.8 MEDIUM
CVE-2026-73212 — coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path…

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without c…

coturn | Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.8 CRITICAL
CVE-2026-73211 — PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore()

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowi…

peertube | Remote | Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.3 CRITICAL
CVE-2026-73090 — PeerTube: Cross-origin remote video takeover via Update activity

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying th…

peertube | Remote | Authorization
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
8.7 HIGH
CVE-2026-72713 — XAgent Path Traversal Arbitrary File Read via /workspace/file

XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory…

xagent | Remote | Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.9 MEDIUM
CVE-2026-72712 — Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option…

nmap | Remote | Denial of Service
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
10.0 CRITICAL
CVE-2026-71398 — Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this v…

campaign campaign_classic | Remote | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
9.1 CRITICAL
CVE-2026-71362 — Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive re…

magento_open_source commerce commerce_b2b | Remote | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-69113 — Cap v0.3.1 Broken Access Control via video comment endpoint

Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on any private video without permission by supplying…

Remote | Authorization
Aug 11, 2026 Aug 14, 2026
Aug 11, 2026
Aug 14, 2026
9.8 CRITICAL
CVE-2026-69102 — MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authen…

maxkey | Remote | Authentication
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
6.7 MEDIUM
CVE-2026-65680 — Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.

Aug 11, 2026 Aug 17, 2026
Aug 11, 2026
Aug 17, 2026
5.5 MEDIUM
CVE-2026-48790 — turso-cli persists Turso platform JWT with world-readable (0o644) file permissions

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermiss…

| Misconfiguration
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
8.2 HIGH
CVE-2026-48771 — ishankportfolio: Stored Contact Form Submission Exposure via Public Client-Side Database …

ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured client-side database configuration and insufficient acc…

Remote | Misconfiguration
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
7.6 HIGH
CVE-2026-48767 — Google Sheets OAuth access token disclosure to guest members via getAccessToken

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth access token for that workspace by calling the Googl…

typebot | Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.1 HIGH
CVE-2026-48494 — TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-previe…

TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook session that belongs to a different typebot by mix…

typebot | Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.7 HIGH
CVE-2026-48447 — Lightroom Classic | Incorrect Authorization (CWE-863)

Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerabilit…

lightroom windows | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
8.6 HIGH
CVE-2026-48441 — Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Tr…

Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could explo…

lightroom windows | Path Traversal
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-48416 — Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and ga…

magento_open_source commerce commerce_b2b | Remote | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.6 HIGH
CVE-2026-48415 — Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security m…

magento_open_source commerce commerce_b2b | Remote | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.7 HIGH
CVE-2026-48414 — Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious Ja…

magento_open_source commerce commerce_b2b | Remote | Cross-Site Scripting
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
8.7 HIGH
CVE-2026-48413 — Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious Ja…

magento_open_source commerce commerce_b2b | Remote | Cross-Site Scripting
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
Showing 20 of 14311 Results