Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2026-18481 — Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative cont…

aws_ops_wheel | Remote | Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.7 MEDIUM
CVE-2026-18321 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec

Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd

ntpsec | Memory Corruption
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.7 HIGH
CVE-2026-55100 — hashi-vault-js has a path traversal and query parameter injection

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and versi…

Remote | Path Traversal
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.3 HIGH
CVE-2026-54737 — @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merg…

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filterin…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.7 HIGH
CVE-2026-54729 — dssrf: any users using 1.1.1.1 DNS is impacted by SSRF

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN…

Remote | Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.6 CRITICAL
CVE-2026-54725 — vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during adm…

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.b…

Remote | Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.8 MEDIUM
CVE-2026-34497 — FMS Employee Vulnerable to HTML Injection

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems E…

fm_systems_employee | Remote | Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.8 MEDIUM
CVE-2026-34495 — FMS Employee vulnerable to XSS

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: …

fm_systems_employee | Remote | Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.8 MEDIUM
CVE-2026-34490 — XAAP Android Data Stored in Unencrypted Database

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.…

xaap_application | Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.8 MEDIUM
CVE-2026-21662 — FMS Employee Allows Upload of Unrestricted Files

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.

fm_systems_employee | Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.8 CRITICAL
CVE-2026-67822 — Tenda W6-S Stack-based Buffer Overflow

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' par…

Remote | Memory Corruption
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.4 CRITICAL
CVE-2026-58048 — cPanel SQL Mode Improper Preservation Vulnerability

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

Remote | Injection
Jul 31, 2026 Aug 01, 2026
Jul 31, 2026
Aug 01, 2026
5.6 MEDIUM
CVE-2026-58047 — cPanel HTTP Request Smuggling Vulnerability

HTTP Smuggling in cPanel allows potential leak of credentials.

Remote | Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.4 MEDIUM
CVE-2026-54707 — OnionShare Receive mode writes uploaded files even when file uploads are disabled

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enfor…

onionshare | Remote | Misconfiguration
Jul 31, 2026 Aug 01, 2026
Jul 31, 2026
Aug 01, 2026
4.8 MEDIUM
CVE-2026-54706 — OnionShare follows symlinks in shared directories, allowing unintended disclosure of loca…

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbol…

onionshare | Remote | Path Traversal
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-52856 — Wings: Maliciously crafted packet during SFTP connection handshake causes denial of servi…

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go pani…

wings | Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.9 CRITICAL
CVE-2026-52855 — Wings exposes node configuration secrets through egg configuration-file templating

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileg…

wings | Remote | Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.9 MEDIUM
CVE-2026-67607 — LightFTP 2.3.1 Race Condition DoS via worker_thread_cleanup

LightFTP 2.3.1 contains a race condition vulnerability that allows remote attackers to crash the server by racing a fresh connection that reuses the FTP context against an in-progress ABRT cleanup. A…

lightftp | Remote | Race Condition
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-59232 — Stored Cross-site Scripting in Prospero Flow CRM lead name field

Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the app…

prospero_flow_crm | Remote | Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-59231 — Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs

Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen …

pentestify | Remote | Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
Showing 20 of 9406 Results