Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-66798 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 28, 2026 Aug 29, 2026
Aug 28, 2026
Aug 29, 2026
6.5 MEDIUM
CVE-2026-66324 — Microsoft Edge (Chromium-based) Spoofing Vulnerability

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-66323 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 28, 2026 Aug 29, 2026
Aug 28, 2026
Aug 29, 2026
5.4 MEDIUM
CVE-2026-62904 — Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.4 MEDIUM
CVE-2026-58616 — Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.

Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.1 HIGH
CVE-2026-56100 — SpringBlade 2.7.3 < 5.0.0 Privilege Escalation via Exposed Feign Endpoint

SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to a…

Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.3 MEDIUM
CVE-2026-55834 — Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with pr…

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter …

pocket_id | Remote | Authentication
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-55673 — PowSyBl: Command Injection in LocalCommandExecutor-s

PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and enviro…

Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.9 CRITICAL
CVE-2026-55634 — Pimcore: Remote Code Execution via DataObject Class-Definition Field Name

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/…

pimcore | Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-55584 — phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP hea…

phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client…

phpsysinfo | Remote | Information Disclosure
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.6 MEDIUM
CVE-2026-55569 — aqua: Archive extraction in aqua follows attacker-planted symlinks, allowing writes outsi…

aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the handler.HandleFile method calls os.Symlink with archives.FileInfo.LinkTarget withou…

| Path Traversal
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.3 MEDIUM
CVE-2026-55566 — Yamcs: DOM XSS in Extension Routing

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/ext…

yamcs | Remote | Cross-Site Scripting
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.9 CRITICAL
CVE-2026-55565 — Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compile…

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an une…

yamcs | Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-55559 — Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstanc…

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamc…

yamcs | Remote | Injection
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-55552 — Yamcs: Unauthenticated Directory Traversal

Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm tha…

yamcs | Remote | Path Traversal
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.5 MEDIUM
CVE-2026-55549 — Yamcs: Reflected XSS in the URL of the Authorize Endpoint

Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize…

yamcs | Remote | Cross-Site Scripting
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
4.3 MEDIUM
CVE-2026-55547 — Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authe…

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/m…

yamcs | Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
6.5 MEDIUM
CVE-2026-55545 — Yamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enfo…

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePacke…

yamcs | Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-55521 — Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.i…

yamcs | Remote | Authorization
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-55520 — Protego: Exponential backtracking ReDoS in robots.txt URL wildcard matching

Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URLPattern._prepare_pattern_for_regex translates every asterisk in an Allow or Dis…

Remote | Denial of Service
Aug 28, 2026 Aug 28, 2026
Aug 28, 2026
Aug 28, 2026
Showing 20 of 12181 Results