Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-48169 — PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues an…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.2 CRITICAL
CVE-2026-47243 — Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-f…

kata_containers | Path Traversal
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-46405 — OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is sup…

openbao | Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.1 HIGH
CVE-2026-45808 — OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers ca…

openbao | Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.6 MEDIUM
CVE-2026-11743 — Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-…

The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length on its read and write paths with the test (offset + size) > data->size. Because …

zephyr zephyr | Memory Corruption
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
3.6 LOW
CVE-2026-11742 — Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock

The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, reading the node's flag byte and, for items enqueued via k_queue_alloc_append/alloc…

zephyr zephyr | Race Condition
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.8 MEDIUM
CVE-2026-9031 — Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic. Succ…

| Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.8 MEDIUM
CVE-2026-9030 — Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6

A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent sy…

| Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.0 MEDIUM
CVE-2026-71381 — Adobe Genuine Software Integrity Service | CWE-863 Incorrect Authorization

Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could have leveraged this vulnerability t…

| Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-69207 — Hono: ReDoS in CORS middleware via Access-Control-Request-Headers

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of servic…

hono | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.1 HIGH
CVE-2026-66061 — Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enablin…

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routi…

home_assistant_companion | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.1 HIGH
CVE-2026-66060 — Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrust…

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or QR) delivered through an OS-level routing …

home_assistant_companion | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.3 MEDIUM
CVE-2026-59717 — Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL fra…

home_assistant_companion | Remote | Misconfiguration
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-54338 — JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging on Failed Lo…

JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controll…

jupyterhub | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.6 CRITICAL
CVE-2026-50540 — Kata Containers: Config Path Annotation Arbitrary File Loading

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable …

kata_containers | Remote | Misconfiguration
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.6 HIGH
CVE-2026-47664 — Pathling: $import-pnp operation enables authenticated SSRF, credential leakage, and wareh…

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, the `$import-pnp` operation in Pathling Se…

Remote | Server-Side Request Forgery
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-47663 — Pathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfiltration and …

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR su…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-47662 — Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning…

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR su…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.4 MEDIUM
CVE-2026-46358 — OpenBao's Inline Auth Incorrectly Redacted Headers

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers b…

openbao | Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.5 MEDIUM
CVE-2026-19246 — HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url se…

A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_generation.py of the component Provider-returned Im…

nanobot | Remote | Server-Side Request Forgery
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
Showing 20 of 9959 Results