Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.7 LOW
CVE-2026-42955 — Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-ti…

In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost …

unbound | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
3.7 LOW
CVE-2026-41637 — Degradation of resolution service from improperly accounted client-terminated DNS-over-QU…

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of r…

unbound | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-40691 — Packet of death for DNSCrypt over TCP

In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer si…

unbound | Memory Corruption
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-32665 — Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the pe…

unbound | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.3 MEDIUM
CVE-2026-16560 — 389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the sam…

Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-16232 — Authentication Bypass in the SmartConsole Login Process Using an Application Token

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with ful…

quantum_security_management | Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-14932 — Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart

In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files withi…

telerik_ui_for_asp.net_ajax | Remote | Path Traversal
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.3 MEDIUM
CVE-2026-14865 — XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via …

telerik_ui_for_asp.net_ajax | Remote | XML External Entity
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.9 MEDIUM
CVE-2026-14586 — Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger an…

unbound | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-13192 — RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side req…

telerik_ui_for_asp.net_ajax | Remote | Server-Side Request Forgery
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-13190 — PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which c…

telerik_ui_for_asp.net_ajax | Remote | Injection
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-13189 — SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJ…

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolutio…

telerik_ui_for_asp.net_ajax | Remote | Server-Side Request Forgery
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.9 MEDIUM
CVE-2026-13188 — DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.

telerik_ui_for_asp.net_ajax | Remote | Injection
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-13187 — DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.

telerik_ui_for_asp.net_ajax | Remote | Injection
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-13186 — AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP…

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-contro…

telerik_ui_for_asp.net_ajax | Remote | Path Traversal
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-13185 — PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unau…

telerik_ui_for_asp.net_ajax | Remote | Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-13184 — RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall b…

telerik_ui_for_asp.net_ajax | Remote | Misconfiguration
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-13183 — RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to r…

telerik_ui_for_asp.net_ajax | Remote | Cryptography
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-13182 — RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.N…

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals prote…

telerik_ui_for_asp.net_ajax | Remote | Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-13181 — RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NE…

In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote cod…

telerik_ui_for_asp.net_ajax | Remote | Misconfiguration
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
Showing 20 of 9652 Results