Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-53785 — rsync < 3.5.0 Path Traversal Write Escape via --relative Mode

rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink compon…

| Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-53784 — rsync < 3.5.0 Path Traversal via Symlink Module Root

rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a compon…

| Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.1 HIGH
CVE-2026-53783 — rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory …

Remote | Race Condition
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.4 HIGH
CVE-2026-49857 — auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback

auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/security.ts`) to block requests…

Remote | Server-Side Request Forgery
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.3 MEDIUM
CVE-2026-49856 — @jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization

@jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF authorization policy that blocks pr…

Remote | Server-Side Request Forgery
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.7 MEDIUM
CVE-2026-49820 — Probo has an open redirect bypass via path normalization

Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication fl…

Remote | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-28154 — WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) vulnera…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion Woo…

Remote | Cross-Site Scripting
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.6 HIGH
CVE-2026-19734 — IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking

Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to re…

prospero_flow_crm | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-19293 — SMP security request

SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the key easier. See V6 in BLERP p…

| Cryptography
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-19292 — Bluetooth re-pairing with legitimate device can use lower security level

Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.

| Cryptography
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-19291 — Bluetooth re-pairing can use a lower security level than previous

Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.

| Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-16101 — forced re-pairing with already bonded device

Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below

| Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.0 HIGH
CVE-2026-15994 — Lenovo Vantage Improper Link Following Privilege Escalation

During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute …

vantage commercial_vantage | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-14456 — Unbounded Memory Growth in QUIC Server Incoming Channel Queue

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without e…

| Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.7 MEDIUM
CVE-2026-14256 — ELAN TrackPoint Driver Out-of-Bounds Write Vulnerability

ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash.

| Memory Corruption
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-12036 — Lenovo Vantage VantageCoreAddin Arbitrary File Deletion Vulnerability

An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file…

vantage | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.3 MEDIUM
CVE-2026-73403 — WordPress User Registration plugin <= 5.2.6 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.

user_registration | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.3 MEDIUM
CVE-2026-73401 — WordPress InstaWP Connect plugin <= 0.1.3.7 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.

Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-73357 — WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability

Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.

Remote | Cross-Site Scripting
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.3 MEDIUM
CVE-2026-73353 — WordPress Revolut Gateway for WooCommerce plugin < 4.22.10 - Broken Access Control vulner…

Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.

Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
Showing 20 of 11087 Results