Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-13198 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition…

Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the event notification functionality of KUNBUS …

| Race Condition
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.3 HIGH
CVE-2026-13197 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition…

Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-image management …

| Race Condition
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.3 HIGH
CVE-2026-13196 — Out-of-bounds Write in KUNBUS piControl

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attac…

| Memory Corruption
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.4 MEDIUM
CVE-2026-13002 — Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted respo…

Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.7 HIGH
CVE-2026-69101 — Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint

Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by suppl…

Remote | XML External Entity
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-58224 — Samba: ctdb fails to do integrity checking of received packets

A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field l…

Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.3 MEDIUM
CVE-2026-19880 — Incomplete protection against CVE-2025-11226

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitize…

Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.3 MEDIUM
CVE-2026-19879 — Io.undertow/undertow: undertow: http response header integrity issue due to character tru…

A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes w…

Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-73633 — Apache Struts: Unbounded read of a JSON request body

Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into me…

struts | Remote | Denial of Service
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.3 MEDIUM
CVE-2026-53472 — Migration-planner: credentialurl validator accepts javascript: urls

A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim vi…

Remote | Cross-Site Scripting
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.3 MEDIUM
CVE-2026-1621 — Register Bypass in Universal Sotware's E-Municipality

Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers. This issue affects E-Municipality: from 20251127 before …

Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
9.3 CRITICAL
CVE-2026-19871 — Use of hard-coded credentials in Prospero Flow CRM employee onboarding

Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the …

prospero_flow_crm | Remote | Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.5 MEDIUM
CVE-2026-19830 — TRENDnet TEW-816DRM bftpd bftpd.conf allocation of resources

A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the component bftpd. The manipulation of the argument…

Remote | Denial of Service
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
4.3 MEDIUM
CVE-2026-19829 — 648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal

A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability affects unknown code of the file LogController.java of the component Log File Download Endpoint. Th…

Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
6.5 MEDIUM
CVE-2026-19828 — 648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal

A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown part of the file PlayController.java of the component Snapshot Endpoint. The manipulation of the ar…

Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
5.5 MEDIUM
CVE-2026-19827 — alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path tr…

A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. This …

Remote | Path Traversal
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.1 HIGH
CVE-2026-19768 — Devolutions PowerShell Universal Code Injection Vulnerability

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permis…

powershell_universal | Remote | Injection
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-73673 — Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmwar…

Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authe…

| Authentication
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
8.6 HIGH
CVE-2026-19870 — IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation

Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and…

prospero_flow_crm | Remote | Authorization
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
7.5 HIGH
CVE-2026-19826 — alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject de…

A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Liste…

Remote | Information Disclosure
Aug 14, 2026 Aug 14, 2026
Aug 14, 2026
Aug 14, 2026
Showing 20 of 10630 Results