Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-68750 — Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhau…

Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat run of siblin…

Remote | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.2 HIGH
CVE-2026-68749 — Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion d…

Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS declaration in sa…

Remote | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
2.3 LOW
CVE-2026-68747 — CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attack…

Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
2.3 LOW
CVE-2026-66843 — html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing unt…

Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted pa…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
2.3 LOW
CVE-2026-66829 — html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cro…

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the at…

Remote | Misconfiguration
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.8 MEDIUM
CVE-2026-66370 — html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allo…

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to retarget a form already on the renderin…

Remote | Misconfiguration
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.2 HIGH
CVE-2026-5423 — Subscription Authentication Bypass via Unverified connectionParams.jwt

@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unau…

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.7 HIGH
CVE-2026-53985 — Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forci…

Remote | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.7 HIGH
CVE-2026-53977 — OpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdown

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown e…

Remote | Authentication
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.5 HIGH
CVE-2026-43622 — llama.cpp b1886–b7445 Double Free via llama-android.cpp

llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using t…

| Memory Corruption
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.6 HIGH
CVE-2026-3430 — Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart e…

Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.3 MEDIUM
CVE-2026-19047 — NocteDefensor LudusMCP ludus_cli_execute cliWrapper.ts executeCommand command injection

A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli…

| Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.8 MEDIUM
CVE-2026-19046 — NocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuidesSearch.ts pa…

A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component l…

| Path Traversal
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.5 HIGH
CVE-2026-18427 — @fastify/static vulnerable to route guard bypass via non-canonical path segments

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot se…

| Path Traversal
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.5 HIGH
CVE-2026-18359 — Server-Side Request Forgery (SSRF) in eScriptorium

Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to int…

Remote | Server-Side Request Forgery
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.1 HIGH
CVE-2026-18277 — Missing Authorization in eScriptorium

Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR …

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.3 MEDIUM
CVE-2026-18276 — Missing Authorization in eScriptorium

Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segme…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-18275 — Authorization Bypass Through User-Controlled Key in eScriptorium

Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other …

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
8.8 HIGH
CVE-2026-18258 — Authorization Bypass Through User-Controlled Key in eScriptorium

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and de…

Remote | Authorization
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.5 HIGH
CVE-2026-70646 — aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in …

aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This a…

Remote | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
Showing 20 of 9989 Results