Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-68087 — HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush()

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush() wacom_wac_queue_flush() is called via the .raw_event callback (wacom_raw_ev…

linux_kernel | Misconfiguration
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
0.0 NA
CVE-2026-68086 — mm/khugepaged: write all dirty file folios when collapsing

In the Linux kernel, the following vulnerability has been resolved: mm/khugepaged: write all dirty file folios when collapsing [There is no upstream commit, as this code was removed by upstream co…

linux_kernel | Memory Corruption
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.0 HIGH
CVE-2026-68085 — Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled HCI_UART_SENDING bit in tx_state means write_work is pend…

linux_kernel | Race Condition
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
0.0 NA
CVE-2026-68084 — staging: vme_user: fix location monitor leak in tsi148 bridge

In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: fix location monitor leak in tsi148 bridge tsi148_probe() allocates a location monitor resource and links it i…

Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
9.1 CRITICAL
CVE-2026-68083 — ksmbd: fix path resolution in ksmbd_vfs_kern_path_create

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create The SMB2 open lookup is rooted at the share with LOOKUP_BENEATH, but the…

linux_kernel | Remote | Path Traversal
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
2.1 LOW
CVE-2026-64941 — Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attacker to send a victim's browser to an origin of the attacker's choosing via a :to…

phoenix_live_view | Remote | Misconfiguration
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
5.5 MEDIUM
CVE-2026-59088 — Gimp: gimp: denial of service via signed integer overflow in fli file processing

A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation…

enterprise_linux gimp enterprise_linux | Denial of Service
Aug 10, 2026 Aug 21, 2026
Aug 10, 2026
Aug 21, 2026
7.6 HIGH
CVE-2026-72594 — lobehub lobe-chat - Stored Cross-Site Scripting via Unrestricted SVG Avatar Upload

A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary JavaScript into the application by uploading a cr…

lobe_chat | Cross-Site Scripting
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72593 — dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access

A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, an…

phpfilemanager | Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72592 — dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload

An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships with an empty up…

phpfilemanager | Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
7.7 HIGH
CVE-2026-72591 — Koito - Authenticated Server-Side Request Forgery via Album Image URL Parameter

A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP requests to arbitrary internal or external hosts by supp…

| Server-Side Request Forgery
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72590 — alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter

An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /cron…

| Injection
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72589 — alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database ho…

An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system commands by importing a crafted crontab database f…

| Injection
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.3 MEDIUM
CVE-2026-72588 — bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password Rec…

A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/rec…

checkmate | Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
6.1 MEDIUM
CVE-2026-72587 — Instatic - Cache Poisoning via Unauthenticated Server Island Endpoint

A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of …

| Misconfiguration
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-72586 — frangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event Handler

A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEna…

fuxa | Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
7.4 HIGH
CVE-2026-72584 — fastschema - TOCTOU Race Condition Bypasses OTP Attempt Limit in Account Recovery

A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attacker to bypass the OTP attempt limit on the account recovery flow, enabling brut…

| Race Condition
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-72583 — fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Upload

A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated user to upload an SVG file containing malicious JavaScript by bypassing the MIME …

| Cross-Site Scripting
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-72582 — fastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery Endpoint

A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a single HTTP request. The sendOTPEmail function in p…

| Denial of Service
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
8.6 HIGH
CVE-2026-72581 — duhow xiaoai-patch - Server-Side Request Forgery in /auth Endpoint

A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal o…

| Server-Side Request Forgery
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
Showing 20 of 13768 Results