Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.3 LOW
CVE-2026-41515 — OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.9.0 and prior t…

op-tee | Cryptography
Jul 06, 2026 Jul 07, 2026
Jul 06, 2026
Jul 07, 2026
3.3 LOW
CVE-2026-41514 — OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior t…

op-tee | Cryptography
Jul 06, 2026 Jul 07, 2026
Jul 06, 2026
Jul 07, 2026
6.5 MEDIUM
CVE-2026-14898 — OpenAI Codex Information Disclosure via Remote Image Rendering

The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content processed by Codex, such as a conne…

Remote | Server-Side Request Forgery
Jul 06, 2026 Jul 07, 2026
Jul 06, 2026
Jul 07, 2026
8.8 HIGH
CVE-2026-14536 — Devolutions Server Multi-Factor Authentication Bypass

Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authentica…

devolutions_server | Remote | Authentication
Jul 06, 2026 Jul 09, 2026
Jul 06, 2026
Jul 09, 2026
9.8 CRITICAL
CVE-2026-11405 — Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows ad…

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based …

Remote | Authentication
Jul 06, 2026 Jul 08, 2026
Jul 06, 2026
Jul 08, 2026
9.8 CRITICAL
CVE-2026-9182 — Unvalidated File Upload vulnerability in ArcGIS Server.

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitati…

linux_kernel arcgis_server windows | Remote | Misconfiguration
Jul 06, 2026 Jul 08, 2026
Jul 06, 2026
Jul 08, 2026
9.8 CRITICAL
CVE-2026-9181 — Directory Traversal in ArcGIS Server

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path paramete…

linux_kernel arcgis_server windows | Remote | Path Traversal
Jul 06, 2026 Jul 08, 2026
Jul 06, 2026
Jul 08, 2026
4.5 MEDIUM
CVE-2026-55798 — Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the…

pillow | Injection
Jul 06, 2026 Jul 07, 2026
Jul 06, 2026
Jul 07, 2026
7.5 HIGH
CVE-2026-55380 — Pillow GdImageFile decompression bomb protection bypass

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompres…

pillow | Remote | Memory Corruption
Jul 06, 2026 Jul 07, 2026
Jul 06, 2026
Jul 07, 2026
7.5 HIGH
CVE-2026-55379 — Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb pr…

Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() wi…

pillow | Remote | Memory Corruption
Jul 06, 2026 Jul 07, 2026
Jul 06, 2026
Jul 07, 2026
8.2 HIGH
CVE-2026-54291 — Silent channel-binding authentication downgrade via unsupported certificate algorithms

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plai…

postgresql_jdbc_driver | Remote | Authentication
Jul 06, 2026 Jul 09, 2026
Jul 06, 2026
Jul 09, 2026
7.5 HIGH
CVE-2026-54060 — Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._de…

pillow | Remote | Denial of Service
Jul 06, 2026 Jul 07, 2026
Jul 06, 2026
Jul 07, 2026
7.5 HIGH
CVE-2026-54059 — Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_…

Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without callin…

pillow | Remote | Denial of Service
Jul 06, 2026 Jul 07, 2026
Jul 06, 2026
Jul 07, 2026
7.5 HIGH
CVE-2026-13753 — CVE-2026-13753

A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmware version <=TBP1CN2612AR. An unauthenticated attacker with network access can …

Remote | Authorization
Jul 06, 2026 Jul 06, 2026
Jul 06, 2026
Jul 06, 2026
9.9 CRITICAL
CVE-2026-48614 — Plesk XML API Improper Authorization Privilege Escalation

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege es…

Remote | Authorization
Jul 06, 2026 Jul 06, 2026
Jul 06, 2026
Jul 06, 2026
3.3 LOW
CVE-2026-41434 — OP-TEE has unbounded recursion in sanitize_client_object()

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.10.0 and prior …

op-tee | Denial of Service
Jul 06, 2026 Jul 07, 2026
Jul 06, 2026
Jul 07, 2026
6.4 MEDIUM
CVE-2026-12154 — Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 - Authenticated (Contributor+) St…

The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to a…

Remote | Cross-Site Scripting
Jul 06, 2026 Jul 07, 2026
Jul 06, 2026
Jul 07, 2026
10.0 CRITICAL
CVE-2026-48316 — ColdFusion | Improper Input Validation (CWE-20)

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitati…

coldfusion | Remote | Injection
Jul 06, 2026 Jul 09, 2026
Jul 06, 2026
Jul 09, 2026
7.3 HIGH
CVE-2026-43825 — Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel

Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introduced in   OPENNLP-1808 and only present on the 3.x …

opennlp | Remote | Misconfiguration
Jul 06, 2026 Jul 08, 2026
Jul 06, 2026
Jul 08, 2026
5.5 MEDIUM
CVE-2026-40257 — OP-TEE has SHA-3 accelerated finalize heap overflow

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior …

op-tee | Memory Corruption
Jul 06, 2026 Jul 07, 2026
Jul 06, 2026
Jul 07, 2026
Showing 20 of 9325 Results