Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-67189 — pfSense Plus/CE Stored XSS via Traffic Graphs PTR Record

pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups…

pfsense_plus pfsense_ce | Remote | Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
9.8 CRITICAL
CVE-2026-63722 — ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php

ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validati…

Remote | Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
8.7 HIGH
CVE-2026-63188 — logto-tunnel serves files outside --experience-path via path traversal

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy from packages/tunnel/src/commands/tunnel/index.ts…

Remote | Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.3 MEDIUM
CVE-2026-63187 — Logto: OS command injection vulnerability exists in the Commitlint workflow

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title int…

Remote | Injection
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
7.5 HIGH
CVE-2026-62317 — Logto: ReDoS via unescaped user input in email subaddressing regex (blockSubaddressing)

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in packages/core/src/libraries/sign-in-experience/email-blocklist-pol…

Remote | Denial of Service
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
2.3 LOW
CVE-2026-61712 — BuildKit: Possible runtime DoS via unbounded group parsing

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group fi…

Remote | Denial of Service
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.3 MEDIUM
CVE-2026-61711 — BuildKit: Custom frontend could bypass Seccomp/AppArmor

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in …

Remote | Misconfiguration
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.3 MEDIUM
CVE-2026-55090 — Etherpad: Stored XSS in HTML export via unescaped attribute-pool values

Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data…

Remote | Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
9.9 CRITICAL
CVE-2026-55089 — Etherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every E…

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredC…

Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.8 MEDIUM
CVE-2026-55088 — Etherpad: Device-to-device author-token transfer endpoint is replayable, never expires, a…

Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browser…

Remote | Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
6.1 MEDIUM
CVE-2026-55087 — Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and …

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into…

Remote | Information Disclosure
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
4.2 MEDIUM
CVE-2026-55086 — Etherpad: Import/export use Math.random() for temp file paths; predictable paths on share…

Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in o…

| Path Traversal
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
9.6 CRITICAL
CVE-2026-55085 — Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Script…

Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attr…

Remote | Cross-Site Scripting
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
5.1 MEDIUM
CVE-2026-54742 — Lemmy: `CollectionAdd::Featured` does not check the post is in the community

Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature posts in other communities through federated Coll…

Remote | Authorization
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
10.0 CRITICAL
CVE-2026-22306 — Critical flaw impacting OZOLS ERP's automatic update channel

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows…

Remote | Supply Chain
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-19509 — RDK WebUI DOS vulnerability

Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows an authenticated attacker to cause denial of service via a crafted `ss…

| Denial of Service
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-19508 — RDK WebUI heap-based buffer overflow vulnerability

Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause memory corruption and de…

| Memory Corruption
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-19507 — RDK WebUI uncontrolled resource consumption

Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password val…

| Denial of Service
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-19506 — RDK-B WebUI race condition vulnerability

Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to gain unauthorized access via concurrent authentication requests that exploit shared authentic…

| Race Condition
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
0.0 NA
CVE-2026-19505 — RDK-B WebUI improper cryptographic signature verification vulnerability

Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access v…

| Authentication
Aug 19, 2026 Aug 19, 2026
Aug 19, 2026
Aug 19, 2026
Showing 20 of 12575 Results