Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-16732 — fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count

fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to derive the request host, protocol, hostname, ip, an…

fastify | Server-Side Request Forgery
Aug 18, 2026 Sep 02, 2026
Aug 18, 2026
Sep 02, 2026
7.3 HIGH
CVE-2026-15571 — Keycloak-services: keycloak-services: predictable account-linking hash enables account ta…

A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-link…

single_sign-on data_grid build_of_keycloak | Remote | Authentication
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-12632 — Out-of-bounds read in Zephyr PTP message parsing from unvalidated message type

Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type straight off the wire via ptp_msg_type() (msg->header.type_major_sdo_id &…

zephyr zephyr | Memory Corruption
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
6.5 MEDIUM
CVE-2026-12631 — Broken access-control denial in k_thread_join/k_thread_abort syscall validation in Zephyr…

The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_validate() in kernel/thread.c. Its default switch …

zephyr zephyr | Authorization
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
Showing 20 of 15304 Results