Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-47662 — Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning…

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR su…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.4 MEDIUM
CVE-2026-46358 — OpenBao's Inline Auth Incorrectly Redacted Headers

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers b…

openbao | Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.5 MEDIUM
CVE-2026-19246 — HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url se…

A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_generation.py of the component Provider-returned Im…

nanobot | Remote | Server-Side Request Forgery
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
3.3 LOW
CVE-2026-19245 — HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disc…

A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of the file nanobot/agent/tools/shell.py of the component Login-shell Environment Ha…

nanobot | Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.8 MEDIUM
CVE-2026-19244 — HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control

A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP enabledTools Scope Hand…

nanobot | Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.4 MEDIUM
CVE-2026-11425 — Domoticz Mobile Dashboard versions prior to 2026.3 Stored XSS via Text/Alert Device Rende…

Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript by updating …

domoticz | Remote | Cross-Site Scripting
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.8 MEDIUM
CVE-2026-71870 — pypdf: Possible large memory usage for large /ToUnicode streams

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-cod…

pypdf | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-66151 — SonicWall Global VPN Client Out-of-Bounds Memory Read

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.

global_vpn_client | Memory Corruption
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-65819 — gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/underflow) enab…

gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffe…

gopacket | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-62296 — HAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow denial of serv…

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested…

hl7_fhir_core | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-62295 — HAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of service

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enfo…

hl7_fhir_core | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.0 MEDIUM
CVE-2026-62293 — HAPI FHIR: Stored XSS in scan report via unescaped IG and profile titles

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command concatenates attacker-controlled Implementation Guide…

hl7_fhir_core | Cross-Site Scripting
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.8 CRITICAL
CVE-2026-61808 — LightRAG: Missing Authentication for Critical API Functions in Default Configuration

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an u…

lightrag | Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.1 CRITICAL
CVE-2026-48039 — Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditio…

Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.6 HIGH
CVE-2026-48007 — Element Call reports full URLs of visited pages to analytics server

Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a `posthog` key in config.json or by th…

Remote | Information Disclosure
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-47661 — Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a ca…

Remote | Path Traversal
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-47660 — Pathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltr…

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's bulk-submit operation allows an…

Remote | Misconfiguration
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-47659 — Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /j…

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's `/$result` endpoint allows a ca…

Remote | Path Traversal
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.5 MEDIUM
CVE-2026-19243 — HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection

A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component She…

nanobot | Remote | Injection
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-19113 — Unauthenticated denial of service via unbounded request body processing

Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to…

consul | Remote | Denial of Service
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
Showing 20 of 9952 Results