Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-67324 — GitPython 3.1.50 Authentication Bypass via Joined Short Options

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes att…

gitpython | Remote | Misconfiguration
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
8.4 HIGH
CVE-2026-67323 — GitPython before 3.1.51 Command Injection via unguarded Git options

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-…

gitpython | Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-67322 — GitPython before 3.1.52 Environment Variable Exfiltration via clone_from

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls…

gitpython | Remote | Information Disclosure
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.9 MEDIUM
CVE-2026-67321 — axios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via maxDepth bypass

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who contr…

axios | Remote | Denial of Service
Aug 01, 2026 Aug 02, 2026
Aug 01, 2026
Aug 02, 2026
8.3 HIGH
CVE-2026-67320 — axios before 0.33.0 Prototype Pollution via Node HTTP adapter

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but reque…

axios | Remote | Misconfiguration
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.3 MEDIUM
CVE-2026-67319 — axios before 0.33.0 Prototype Pollution via nested option objects

axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another com…

axios | Remote | Misconfiguration
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.3 MEDIUM
CVE-2026-67318 — axios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2

axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request …

axios | Remote | Misconfiguration
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.3 MEDIUM
CVE-2026-67317 — axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-l…

axios | Remote | Denial of Service
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.3 MEDIUM
CVE-2026-67316 — axios before 1.18.0 Prototype Pollution via bodyless methods

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the body…

axios | Remote | Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.9 MEDIUM
CVE-2026-67315 — axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers …

axios | Remote | Misconfiguration
Aug 01, 2026 Aug 02, 2026
Aug 01, 2026
Aug 02, 2026
6.3 MEDIUM
CVE-2026-67314 — axios before 1.18.0 Prototype Pollution via auth subfields

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is alrea…

axios | Remote | Injection
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.3 MEDIUM
CVE-2026-67313 — axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field nam…

axios | Remote | Denial of Service
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.3 MEDIUM
CVE-2026-67312 — axios 0.28.0 before 0.33.0 Denial of Service via formToJSON

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData wit…

axios | Remote | Denial of Service
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
6.8 MEDIUM
CVE-2026-67311 — Budibase before 3.38.1 SSRF Blacklist Bypass via HTTP Redirect

Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder r…

budibase | Remote | Server-Side Request Forgery
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
5.4 MEDIUM
CVE-2026-67310 — openremote before 1.27.0 Cross-Tenant IDOR via setAssetLinks

OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validate…

openremote | Remote | Authorization
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
7.8 HIGH
CVE-2026-67309 — Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass

Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rew…

traefik | Remote | Path Traversal
Aug 01, 2026 Aug 02, 2026
Aug 01, 2026
Aug 02, 2026
10.0 CRITICAL
CVE-2026-67308 — Wazuh GitHub Actions Shell Injection via Fork Pull Request

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json file…

wazuh | Remote | Injection
Aug 01, 2026 Aug 02, 2026
Aug 01, 2026
Aug 02, 2026
6.3 MEDIUM
CVE-2026-67307 — Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync

Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against …

wazuh | Remote | Misconfiguration
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
5.4 MEDIUM
CVE-2026-67306 — FreeRDP before 3.29.0 Out-of-Bounds Read via Planar RLE

FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functions planar_decompress_plane_rle and planar_decompress_plane_rle_only in lib…

freerdp | Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
9.4 CRITICAL
CVE-2026-67305 — FreeRDP Windows Client before 3.29.0 Heap Buffer Overflow via Cliprdr

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-p…

freerdp | Remote | Memory Corruption
Aug 01, 2026 Aug 01, 2026
Aug 01, 2026
Aug 01, 2026
Showing 20 of 9247 Results