Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.6 MEDIUM
CVE-2026-66486 — Improper Output Encoding in GNU cpio

GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output w…

cpio | Information Disclosure
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
4.6 MEDIUM
CVE-2026-66485 — Uncontrolled Memory Allocation in GNU cpio

GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is der…

cpio | Memory Corruption
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
4.6 MEDIUM
CVE-2026-66484 — Path Traversal in GNU cpio

GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file…

cpio | Path Traversal
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
7.3 HIGH
CVE-2026-65948 — Apache Ranger: UnixAuth lacks brute-force protection

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option for production deployments.  Users are recommended to upgrade to version 2.9.0, …

ranger | Remote | Authentication
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-65945 — Apache Ranger: Logs contain replayable JWT bearer tokens

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

ranger | Remote | Information Disclosure
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
7.5 HIGH
CVE-2026-65942 — Apache Ranger: Clients accept TLS certificates issued for other hostnames

TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

ranger | Remote | Misconfiguration
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
7.5 HIGH
CVE-2026-61899 — Apache Tapestry: Possible classpath file download through URL manipulation

Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Users are recommended to upgrade to version 5.9.1, w…

tapestry | Remote | Path Traversal
Aug 10, 2026 Aug 18, 2026
Aug 10, 2026
Aug 18, 2026
7.8 HIGH
CVE-2026-59087 — Gimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes attacker-con…

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a sp…

enterprise_linux gimp enterprise_linux | Memory Corruption
Aug 10, 2026 Aug 24, 2026
Aug 10, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-55814 — Apache Ranger: Download APIs expose plugin data without authentication

Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

ranger | Remote | Authentication
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
9.8 CRITICAL
CVE-2026-55799 — Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator

Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

ranger | Remote | Misconfiguration
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
9.8 CRITICAL
CVE-2026-44416 — Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation

Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

ranger | Remote | Misconfiguration
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
9.8 CRITICAL
CVE-2026-42537 — Apache Ranger: Remote Code Execution via JDBC URL Injection

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

ranger | Remote | Injection
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
9.8 CRITICAL
CVE-2026-40920 — Apache Ranger: Privilege Escalation via URL Parameter

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

ranger | Remote | Authorization
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
9.8 CRITICAL
CVE-2026-32227 — Apache Ranger: SQL Injection vulnerability in lookup functionality

SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue.

ranger | Remote | Injection
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
9.8 CRITICAL
CVE-2026-28672 — Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.

ranger | Remote | Injection
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
10.0 CRITICAL
CVE-2026-66915 — Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.7.2

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

Remote | Injection
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
7.5 HIGH
CVE-2026-44630 — Apache IoTDB: RPC service denial of service via unchecked Thrift string length

Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sending a crafted malformed Thrift frame, an attacker…

iotdb | Remote | Denial of Service
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
6.5 MEDIUM
CVE-2026-19404 — 389-ds-base: 389-ds-base: missing authorization allows anonymous clients to start or abor…

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker…

Aug 10, 2026 Aug 14, 2026
Aug 10, 2026
Aug 14, 2026
6.9 MEDIUM
CVE-2026-66411 — Ecovacs DEEBOT PRO Authentication Bypass Vulnerability

DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may connect and operate the affected robot.

| Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
4.8 MEDIUM
CVE-2026-66410 — ECOVACS PRO App Improper Certificate Validation Vulnerability

Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered.

| Cryptography
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
Showing 20 of 13964 Results