Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-16728 — undici vulnerable to downstream response desynchronization via retry interceptor

undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. In undici before…

| Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-67439 — OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints r…

| Authorization
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-67438 — OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go checkShellArgumentSafety function does not treat reg…

| Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-67437 — OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login…

| Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
0.0 NA
CVE-2026-54249 — VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` —…

Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic A…

| Server-Side Request Forgery
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.3 MEDIUM
CVE-2026-6336 — Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthori…

Remote | Authorization
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.5 HIGH
CVE-2026-6267 — Insertion of Sensitive Information Into Sent Data in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authent…

Remote | Authorization
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.8 HIGH
CVE-2026-6102 — MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability

MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An a…

center | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.3 HIGH
CVE-2026-67436 — Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id …

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating a…

Remote | Server-Side Request Forgery
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.0 MEDIUM
CVE-2026-67435 — linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() followed cross-origin redirects while forwarding c…

Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.8 MEDIUM
CVE-2026-67433 — Linuxfabrik monitoring-plugins: Symlink following in logfile legacy database migration

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable…

| Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.5 HIGH
CVE-2026-67432 — MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in St…

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-…

Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.3 HIGH
CVE-2026-67431 — MCP Ruby SDK: Ruby SSE Session Poisoning

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not bind a session ID to a …

Remote | Authentication
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.3 MEDIUM
CVE-2026-67430 — MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaus…

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not expire sessions by defa…

Remote | Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.2 MEDIUM
CVE-2026-63119 — MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in the mcp gem use IO#gets withou…

| Denial of Service
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.9 MEDIUM
CVE-2026-63118 — MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not validate the HTTP Host …

Remote | Misconfiguration
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
6.5 MEDIUM
CVE-2026-5492 — DriveLock Directory Traversal Information Disclosure Vulnerability

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication…

Remote | Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
7.5 HIGH
CVE-2026-5491 — DriveLock Directory Traversal Information Disclosure Vulnerability

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication…

Remote | Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
8.8 HIGH
CVE-2026-5490 — DriveLock SQL Injection Privilege Escalation Vulnerability

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exp…

Remote | Injection
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
5.3 MEDIUM
CVE-2026-5489 — DriveLock Directory Traversal Information Disclosure Vulnerability

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication…

Remote | Path Traversal
Jul 29, 2026 Jul 29, 2026
Jul 29, 2026
Jul 29, 2026
Showing 20 of 9581 Results