Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-18929 — Resource Exhaustion in Carbone

Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip decompression without validating entry sizes, allowin…

Remote | Denial of Service
Aug 18, 2026 Aug 28, 2026
Aug 18, 2026
Aug 28, 2026
6.3 MEDIUM
CVE-2026-43971 — Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1

Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib int…

cowlib | Remote | Injection
Aug 18, 2026 Sep 16, 2026
Aug 18, 2026
Sep 16, 2026
6.5 MEDIUM
CVE-2024-14045 — OpenBoxes Product Supplier Edit Controller RoleInterceptor.groovy improper authorization

A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product S…

openboxes | Remote | Authorization
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
9.8 CRITICAL
CVE-2026-34884 — Apache SkyWalking MCP: SSRF via set_skywalking_url Tool and GraphQL Expression Injection …

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to ve…

skywalking_mcp | Remote | Server-Side Request Forgery
Aug 18, 2026 Sep 02, 2026
Aug 18, 2026
Sep 02, 2026
Showing 20 of 14844 Results