Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-69198 — ip-address: a CIDR suffix on the parsed address suppresses special-use classification and…

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circu…

ip-address | Remote | Server-Side Request Forgery
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.7 HIGH
CVE-2026-69192 — ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them a…

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the…

ip-address | Remote | Server-Side Request Forgery
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-69185 — Socket.IO: Zero-attachment Memory Exhaustion

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of…

engine.io | Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.8 HIGH
CVE-2026-68981 — Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the comp…

nifi | Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
2.3 LOW
CVE-2026-68980 — Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Par…

nifi | Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.9 MEDIUM
CVE-2026-68979 — Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Cont…

nifi | Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.2 HIGH
CVE-2026-67599 — ClearOS 7.9 OS Command Injection via Log Viewer filter parameter

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the fi…

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.4 HIGH
CVE-2026-67598 — Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configur…

emlog | Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.1 MEDIUM
CVE-2026-66296 — Reflected XSS in oaskit's default HTML error handler

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler. Oaskit.ErrorHandler.Default.fo…

oaskit | Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.7 HIGH
CVE-2026-62354 — Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override…

nifi | Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.5 MEDIUM
CVE-2026-58139 — DuckDB AWS Extension Security Policy Bypass via load_aws_credentials Procedure

The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the lo…

Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.1 CRITICAL
CVE-2026-48031 — Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", lett…

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.4 HIGH
CVE-2026-47211 — Ouroboros: Remote Code Execution via Untrusted Project-Directory .env

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious r…

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.5 MEDIUM
CVE-2026-18655 — Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt …

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (v…

amazon-mq-mcp-server | Remote | Server-Side Request Forgery
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.8 MEDIUM
CVE-2026-18654 — Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsession…

aws-cli | Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.5 MEDIUM
CVE-2026-18644 — danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal

A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /system/htmly.php of the component Delete Username Endpoint. Such manipulation o…

htmly | Remote | Path Traversal
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-18641 — Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login …

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of…

Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.5 MEDIUM
CVE-2026-18632 — langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a t…

A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the comp…

dify | Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.5 MEDIUM
CVE-2026-18631 — jeequan jeepay PreAuthorize SysLogController.java WebSecurityConfig authorization

A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/src/main/java/com/jeequan/jeepay/mgr/ctrl/sysuser/Sy…

jeepay | Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.8 HIGH
CVE-2026-59913 — Dell Display and Peripheral Manager Privilege Escalation Vulnerability

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could p…

Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
Showing 20 of 9419 Results