Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-37271 — Fire-Boltt Smartwatch Improper Authentication Vulnerability

Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session v…

Remote | Authentication
Jul 07, 2026 Jul 10, 2026
Jul 07, 2026
Jul 10, 2026
9.8 CRITICAL
CVE-2026-37270 — Trueview Security Camera Authentication Bypass

Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.

Remote | Authentication
Jul 07, 2026 Jul 10, 2026
Jul 07, 2026
Jul 10, 2026
5.4 MEDIUM
CVE-2026-36163 — LiquidFiles Stored Cross-Site Scripting Vulnerability

An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading…

Remote | Cross-Site Scripting
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
5.4 MEDIUM
CVE-2026-36162 — LiquidFiles Upload File Shares API Stored Cross-Site Scripting

An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted p…

Remote | Cross-Site Scripting
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
7.5 HIGH
CVE-2026-14895 — String::Util versions before 1.36 for Perl are susceptible to a regular expression denial…

String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches gr…

Remote | Denial of Service
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
9.1 CRITICAL
CVE-2026-14740 — DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting …

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a c…

dbi | Remote | Memory Corruption
Jul 07, 2026 Jul 10, 2026
Jul 07, 2026
Jul 10, 2026
9.8 CRITICAL
CVE-2026-14739 — DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements wi…

DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle app…

dbi | Remote | Memory Corruption
Jul 07, 2026 Jul 10, 2026
Jul 07, 2026
Jul 10, 2026
8.8 HIGH
CVE-2026-14380 — DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced…

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and…

dbi | Remote | Injection
Jul 07, 2026 Jul 10, 2026
Jul 07, 2026
Jul 10, 2026
9.3 CRITICAL
CVE-2026-59706 — mem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url

mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attac…

mem0 | Remote | Authentication
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
2.1 LOW
CVE-2026-59153 — Anki's local HTTP server does not sufficiently validate requests

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other ori…

anki | Remote | Server-Side Request Forgery
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
6.5 MEDIUM
CVE-2026-58266 — Anki: User scripts in iframes have access to the internal Anki API

Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with the Rust backend using an internal localhost API, and user scripts included via …

anki | Remote | Information Disclosure
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
6.5 MEDIUM
CVE-2026-55490 — OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Service

OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the loca…

openwrt | Denial of Service
Jul 07, 2026 Jul 10, 2026
Jul 07, 2026
Jul 10, 2026
8.6 HIGH
CVE-2026-55418 — FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-…

FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unrelated resource and then sign or read an S3 object using a key taken directly f…

fastgpt | Remote | Authorization
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
8.4 HIGH
CVE-2026-55408 — Koodo Reader: Remote code execution via malicious epub file

Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files because the open-book IPC handler enables nodeIntegrati…

| Injection
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
7.4 HIGH
CVE-2026-55075 — Coder vulnerable to OIDC account takeover via email-based user matching and email_verifie…

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaws in Coder's OIDC login chained into account takeo…

coder | Remote | Authentication
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
6.0 MEDIUM
CVE-2026-54698 — Hasura: Row-level authorization bypass on table computed fields

Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table computed field (returning SETOF some_table) to infer ro…

graphql_engine | Remote | Authorization
Jul 07, 2026 Jul 10, 2026
Jul 07, 2026
Jul 10, 2026
7.7 HIGH
CVE-2026-54607 — FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the i…

FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer validates only the top-level URL before passing it to SwaggerParser.bundle, whose re…

fastgpt | Remote | Server-Side Request Forgery
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
7.1 HIGH
CVE-2026-54602 — FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRec…

FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates the caller but loads LLM request and response traces only by requestId without t…

fastgpt | Remote | Information Disclosure
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
6.3 MEDIUM
CVE-2026-54601 — FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant…

FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticated tenant user to call POST /api/core/dataset/collection/create/reTrainingColle…

fastgpt | Remote | Authorization
Jul 07, 2026 Jul 08, 2026
Jul 07, 2026
Jul 08, 2026
4.2 MEDIUM
CVE-2026-50179 — Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Note…

actual | Remote | Cross-Site Scripting
Jul 07, 2026 Jul 09, 2026
Jul 07, 2026
Jul 09, 2026
Showing 20 of 9365 Results