Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-73140 — cti-transmute Evaluation Report Exports Expose Private Comments and Author Information

Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal comment retrieval filters comments according to conversi…

Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.3 MEDIUM
CVE-2026-19519 — Claircore: claircore: denial of service via unchecked type assertion in rpm header parser

A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the C…

quay advanced_cluster_security | Remote | Denial of Service
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.3 HIGH
CVE-2026-19418 — TYPO3 CMS - Broken Access Control in Backend and Install Tool

The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the …

Remote | Cross-Site Scripting
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-19518 — Samsung rlottie Improper Validation of Specified Quantity in Input

Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.

Remote | Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-19517 — Samsung rlottie Resource Exhaustion Vulnerability

Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

Remote | Denial of Service
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-19391 — Insights-core: insights-core: incomplete credential redaction exposes sssd bind passwords…

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_a…

enterprise_linux satellite enterprise_linux satellite | Remote | Information Disclosure
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.5 HIGH
CVE-2026-16053 — Path Traversal

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.

Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.3 MEDIUM
CVE-2026-8158 — Axis Signed Video Framework Buffer Overflow Vulnerability

The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signe…

Remote | Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.1 MEDIUM
CVE-2026-6505 — Axis ACAP Privilege Escalation via TOCTOU Race Condition

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device i…

| Race Condition
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.9 MEDIUM
CVE-2026-6181 — Device Configuration Framework Authentication Bypass

The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account.

Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.7 MEDIUM
CVE-2026-5304 — Axis Communications ACAP Configuration File Improper Input Validation Privilege Escalation

An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the install…

Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.7 MEDIUM
CVE-2026-5303 — Axis ACAP Time-of-Check to Time-of-Use Privilege Escalation

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device i…

Remote | Race Condition
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.2 HIGH
CVE-2026-4757 — Axis Communications VAPIX API Improper Input Validation Leading to Remote Code Execution

A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an admin…

Remote | Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.1 CRITICAL
CVE-2026-19516 — CVE-2026-19516 CVE Record

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and bod…

Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.1 MEDIUM
CVE-2026-18348 — Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from t…

velociraptor | Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-14549 — Ray Enterprise Translation <= 1.7.3 - Subscriber+ Language Addition and Deletion

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to ad…

| Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-14548 — Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token Update

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to ov…

| Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.1 CRITICAL
CVE-2026-13716 — Path Traversal: '.../...//' in Crafty Controller

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application a…

Remote | Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.2 MEDIUM
CVE-2026-12052 — Out-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the …

The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c builds a fixed-size response for the GET_NTB_PARAMETERS (28-byte struct ntb_p…

zephyr zephyr | Memory Corruption
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.6 MEDIUM
CVE-2026-12051 — NULL pointer dereference in USB DFU device_next download handler (handle_download)

The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The ha…

zephyr zephyr | Denial of Service
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
Showing 20 of 10242 Results