Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-45045 — Fiber: X-Real-IP Spoofing via Header.Add() in BalancerForward

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when inje…

fiber | Remote | Injection
Jul 08, 2026 Jul 15, 2026
Jul 08, 2026
Jul 15, 2026
5.5 MEDIUM
CVE-2026-44512 — ONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Ups…

onnx | Denial of Service
Jul 08, 2026 Jul 13, 2026
Jul 08, 2026
Jul 13, 2026
5.3 MEDIUM
CVE-2026-44332 — Fiber: Username Enumeration via Timing Oracle in BasicAuth Default Authorizer

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation t…

fiber | Remote | Authentication
Jul 08, 2026 Jul 15, 2026
Jul 08, 2026
Jul 15, 2026
6.8 MEDIUM
CVE-2026-36028 — Code 27 Companion Hub Kiosk Mode Bypass

A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset

| Authentication
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
6.8 MEDIUM
CVE-2026-36027 — Code27 Companion Hub Arbitrary Code Execution

An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via the USB debugging (ADB) and Android Debug Bridge components

| Authentication
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
6.5 MEDIUM
CVE-2026-15154 — Guardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of …

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide special…

openshift_ai | Denial of Service
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
8.7 HIGH
CVE-2026-14891 — Nomad vulnerable to sandbox escape in Docker task driver

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mount…

nomad | Path Traversal
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
7.7 HIGH
CVE-2026-14373 — Nomad Docker driver Linux host namespace bypass

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a …

nomad | Misconfiguration
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
4.7 MEDIUM
CVE-2026-14361 — Consul-template is vulnerable to path redirection in writeToFile through symlink attack

The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended direct…

terraform_provider | Path Traversal
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
6.9 MEDIUM
CVE-2026-59938 — pypdf: Possible large memory usage for wrong image dimensions

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing larg…

pypdf | Remote | Denial of Service
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
7.5 HIGH
CVE-2026-59937 — pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recoverin…

pypdf | Remote | Denial of Service
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
6.1 MEDIUM
CVE-2026-50813 — SQLite Session Extension Information Disclosure

An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path

| Information Disclosure
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
5.5 MEDIUM
CVE-2026-50812 — SQLite Session Extension NULL Pointer Dereference

A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to ca…

| Denial of Service
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
4.9 MEDIUM
CVE-2026-14362 — Denial of service via crafted push/pull gossip message in memberlist

HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memor…

go-getter | Denial of Service
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
8.8 HIGH
CVE-2026-60102 — Horde VFS < 3.0.1 OS Command Injection via Horde_Vfs_Smb Driver

Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fails to sanitize command substituti…

Remote | Injection
Jul 08, 2026 Jul 14, 2026
Jul 08, 2026
Jul 14, 2026
4.3 MEDIUM
CVE-2026-59930 — Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering wi…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the he…

mistune | Remote | Information Disclosure
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
6.1 MEDIUM
CVE-2026-59929 — Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only javascript:, vbscript:, file:, and data: schemes, allo…

mistune | Remote | Cross-Site Scripting
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
7.5 HIGH
CVE-2026-59928 — Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link def…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistun…

mistune | Remote | Denial of Service
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
5.3 MEDIUM
CVE-2026-59927 — Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `Re…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, a…

mistune | Remote | Denial of Service
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
6.1 MEDIUM
CVE-2026-59926 — Mistune: XSS via unescaped class option in Admonition directive

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into t…

mistune | Remote | Cross-Site Scripting
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
Showing 20 of 9420 Results