Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-69246 — Guzzle: Noncanonical host can bypass host-based checks

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the …

| Server-Side Request Forgery
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-48113 — Chisel: ACL Bypass via Post-Handshake SSH Channel ExtraData Injection

Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destin…

| Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-69245 — Guzzle: Noncanonical cookie domain keeps subdomain scope

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Do…

| Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-18648 — Blix Email Blue Mail Calendar App react-native-receive-sharing-intent FileDirectory.getFi…

A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-shar…

| Path Traversal
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.5 HIGH
CVE-2026-41447 — FirmaCheck < 1.3.16 DLL Hijacking via Unvalidated OpenSSL Configuration Path

FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program F…

| Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-48063 — Baileys has message upsert / hist sync spoofing and app state corruption when using malic…

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage an…

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.1 MEDIUM
CVE-2026-18738 — Shlink CSV Formula Injection via Visit Export CLI

Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying mali…

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-69244 — AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked …

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a …

| Memory Corruption
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-48061 — Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forward…

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-…

| Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-69243 — AIOHTTP: HTTP request smuggling via WebSocket upgrade

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If usin…

| Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-18647 — jina-ai reader Crawler/Puppeteer crawler.ts isValidTLD server-side request forgery

A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functions/src/cloud-functi…

| Server-Side Request Forgery
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.1 HIGH
CVE-2026-18737 — Shlink Blind SQL Injection via tags/stats orderBy Parameter

Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query par…

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.4 MEDIUM
CVE-2026-49132 — OPNsense < 26.1.9 Stored XSS via Certificate Description Field

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate descrip…

Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.8 HIGH
CVE-2026-18733 — Prompt injection bypasses shell tool consent gate in Strands Agents Tools

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a craft…

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-18646 — danpros HTMLy Author Name htmly.php path traversal

A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system/htmly.php of the component Author Name Handler. Executing a manipulation of th…

| Path Traversal
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.4 MEDIUM
CVE-2026-49131 — OPNsense < 26.1.9 Stored XSS via Firewall Rule Description Field

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embe…

Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-69240 — Sequelize: SQL Injection (Oracle DB)

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the v…

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
0.0 NA
CVE-2026-66065 — Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys …

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Sever…

| Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-69198 — ip-address: a CIDR suffix on the parsed address suppresses special-use classification and…

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circu…

ip-address | Remote | Server-Side Request Forgery
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.7 HIGH
CVE-2026-69192 — ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them a…

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the…

ip-address | Remote | Server-Side Request Forgery
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
Showing 20 of 9352 Results