Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-71364 — Awx: project archive extraction allows path traversal file writes

A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project directory path with the mem…

ansible_automation_platform | Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-21752 — HCL Hive is affected by a use of vulnerable third-party components

HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws.

Remote | Supply Chain
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.4 MEDIUM
CVE-2026-9728 — TOCTOU race in mbox_send syscall verifier allows userspace to leak kernel memory

The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwa…

zephyr zephyr | Race Condition
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.0 HIGH
CVE-2026-78414 — Cross-site scripting in Nx Witness VMS Web Administration allows session token exfiltrati…

Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary Java…

| Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-78391 — Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook

RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view. Cryptocurrency addresses and blockchain names originating from external sources, includ…

Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.4 CRITICAL
CVE-2026-78387 — RansomLook Missing Authorization in Web Configuration Editor Allows Application Configura…

RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint. The endpoint requires an authenticated session but does not perform an …

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-76055 — Black Duck Black Duck C/C++ OS Command Injection Vulnerability

Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7 allows an actor able to create a file within the scanned …

| Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.1 HIGH
CVE-2026-76054 — Black Duck C/C++ Sensitive Information Disclosure via Process Environment

Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Blac…

| Information Disclosure
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.1 MEDIUM
CVE-2026-65053 — Horde IMP before 7.2.0 Stored Cross-Site Scripting via AppleDouble Viewer Part Name

Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it. In lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of t…

imp | Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.5 HIGH
CVE-2026-39915 — TIM Flow < 26.0.6 CRLF Injection via rt Parameter

TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized carriage return and lin…

Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.1 HIGH
CVE-2026-39914 — TIM Flow < 26.0.6 Unauthorized SQL Query Execution via Dashboard Export Endpoint

TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for…

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.3 MEDIUM
CVE-2026-21755 — HCL Hive is affected by a missing rate limit

HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service.

Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-19874 — Konami's Metal Gear Online 3 contains a heap-based buffer overflow

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes…

| Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.7 HIGH
CVE-2026-78386 — Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLoo…

RansomLook exposed sensitive operator-side scraping configuration through multiple unauthenticated API responses. Location records associated with ransomware groups and markets were returned largely …

Remote | Information Disclosure
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.2 HIGH
CVE-2026-78385 — RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local…

RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents are converted from Markdown to HTML and passed to WeasyPrint for PDF rendering. P…

Remote | Server-Side Request Forgery
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.2 HIGH
CVE-2026-78381 — RansomLook Arbitrary File Read via Path Traversal in Post screen Field

RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The GroupPost.get API handler concatenates the database-controlled screen value dir…

Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.7 HIGH
CVE-2026-78380 — Private Group and Market Posts Disclosed Through Public Notification Channels in RansomLo…

RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic checks whet…

Remote | Information Disclosure
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.9 MEDIUM
CVE-2026-78378 — Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook Data

Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlled input before it is incorporated into Redis SCAN MATCH patterns. The /api/he…

Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-78376 — Webkitgtk: use-after-free of jscvalue function parameters

A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.

enterprise_linux enterprise_linux | Remote | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.2 CRITICAL
CVE-2026-78372 — RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data

RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked as private. An unauthenticated or otherwise unauthorized remote attacker can a…

Remote | Authorization
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11319 Results