Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-48440 — ColdFusion | Heap-based Buffer Overflow (CWE-122)

ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacke…

coldfusion | Remote | Memory Corruption
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-48439 — CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust sys…

c2pa c2pa-web c2patool | Remote | Denial of Service
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-48438 — CAI Content Credentials | NULL Pointer Dereference (CWE-476)

CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the applic…

c2pa c2pa-web c2patool | Remote | Denial of Service
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
5.5 MEDIUM
CVE-2026-48437 — CAI Content Credentials | Improper Certificate Validation (CWE-295)

CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass securit…

c2pa c2pa-web c2patool | Misconfiguration
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
6.5 MEDIUM
CVE-2026-48436 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security meas…

c2pa c2pa-web c2patool | Remote | Authentication
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
6.2 MEDIUM
CVE-2026-48435 — CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to c…

c2pa c2pa-web c2patool | Denial of Service
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
6.2 MEDIUM
CVE-2026-48434 — CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust sys…

c2pa c2pa-web c2patool | Denial of Service
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
6.2 MEDIUM
CVE-2026-48387 — CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…

c2pa c2pa-web c2patool | Denial of Service
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-48386 — ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)

ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose…

coldfusion | Remote | Cryptography
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.7 HIGH
CVE-2026-48385 — ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Comma…

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in a Security feature bypass. A low-privileged …

coldfusion | Remote | Injection
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
4.9 MEDIUM
CVE-2026-48384 — ColdFusion | Improper Input Validation (CWE-20)

ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability to crash …

coldfusion | Remote | Denial of Service
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-48376 — ColdFusion | Improper Encoding or Escaping of Output (CWE-116)

is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security …

coldfusion | Remote | Information Disclosure
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
6.5 MEDIUM
CVE-2026-48375 — ColdFusion | Incorrect Authorization (CWE-863)

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the appli…

coldfusion | Remote | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
10.0 CRITICAL
CVE-2026-48362 — ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Comma…

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of t…

coldfusion | Remote | Injection
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
4.7 MEDIUM
CVE-2026-47922 — CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue requires user interaction in that a vic…

c2pa c2pa-web c2patool | Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-47704 — TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` lineage allow…

TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook session that belongs to a different typebot by mixing…

typebot | Remote | Authorization
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
7.2 HIGH
CVE-2026-47299 — Azure Monitor Agent Elevation of Privilege Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.

Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-47285 — Visual Studio Code Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Aug 11, 2026 Sep 02, 2026
Aug 11, 2026
Sep 02, 2026
8.5 HIGH
CVE-2026-43606 — AMD Vitis Libraries ECDSA Timing Side-Channel Vulnerability

Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks,…

| Cryptography
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
7.8 HIGH
CVE-2026-42976 — Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.

Aug 11, 2026 Aug 16, 2026
Aug 11, 2026
Aug 16, 2026
Showing 20 of 14196 Results