Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-78154 — the-momentum open-wearables Public Invitation-Code Redemption Endpoint user_invitation_co…

A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/api/routes/v1/user_invitation_code.py of the compon…

open-wearables | Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.9 MEDIUM
CVE-2026-78148 — ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp graph_compute null pointer dereference

A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Execut…

llama.cpp | Remote | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-78147 — ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp deserialize_tensor deserialization

A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Perform…

llama.cpp | Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.0 MEDIUM
CVE-2026-78145 — CTFd __init__.py _is_safe_url redirect

A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation of the argument Next leads to op…

ctfd | Remote | Misconfiguration
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.5 MEDIUM
CVE-2026-78144 — code-projects Barangay Resident Profiling Management System Boarder Management boarders.p…

A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the componen…

Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.5 HIGH
CVE-2026-78143 — code-projects Barangay Resident Profiling Management System Resident Search Functionality…

A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functiona…

Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.5 MEDIUM
CVE-2026-78142 — code-projects Barangay Resident Profiling Management System Restore/Delete archived_recor…

A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. The m…

Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.4 HIGH
CVE-2026-78141 — Tenda CH22 exeCommand formexeCommand command injection

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. Th…

ch22_firmware ch22 | Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-78183 — DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for …

| Memory Corruption
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
5.8 MEDIUM
CVE-2026-78140 — Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special el…

A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the compo…

ujcms | Remote | Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-19565 — Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session auth…

Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. CreateSessionAuthKey runs five rounds …

| Authentication
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
0.0 NA
CVE-2026-75922 — Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-d…

Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands PATH_INFO to an application perce…

| Injection
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
7.5 HIGH
CVE-2026-9769 — justhtml before 1.10.0 Denial of Service via deeply nested HTML

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_sel…

Remote | Denial of Service
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-8630 — justhtml before 1.12.0 Mutation XSS via Raw Text Elements

justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When a DOM tree is pr…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.8 CRITICAL
CVE-2026-8445 — justhtml before 1.12.0 Sanitizer Bypass via Markdown

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). Wh…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
9.8 CRITICAL
CVE-2026-7808 — justhtml before 1.16.0 Multiple Security Issues via Sanitization

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scr…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-77088 — justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span

justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blank lines as block boundaries. Attackers can inject …

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-74793 — justhtml before 3.11.0 XSS via selectedcontent projection

justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent projections. Attackers can inject SVG or MathML elem…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-6827 — justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities

justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous conten…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
6.1 MEDIUM
CVE-2026-5751 — justhtml before 1.14.0 Mutation XSS via custom sanitization policies

justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces (e.g.,…

Remote | Cross-Site Scripting
Aug 23, 2026 Aug 23, 2026
Aug 23, 2026
Aug 23, 2026
Showing 20 of 11491 Results