Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 HIGH
CVE-2026-15511 — Comfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command inject…

A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI B…

cf-wr631ax_v3 | Remote | Injection
Jul 12, 2026 Jul 14, 2026
Jul 12, 2026
Jul 14, 2026
6.5 MEDIUM
CVE-2026-15510 — Leantime API saveSetting improper authorization

A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed …

leantime | Remote | Authorization
Jul 12, 2026 Jul 13, 2026
Jul 12, 2026
Jul 13, 2026
6.5 MEDIUM
CVE-2026-15509 — Leantime JSON-RPC Endpoint addUser improper authorization

A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authoriz…

leantime | Remote | Authorization
Jul 12, 2026 Jul 15, 2026
Jul 12, 2026
Jul 15, 2026
6.5 MEDIUM
CVE-2026-15508 — Helicone ai-gateway AWS Metadata Service service.rs build_target_url server-side request …

A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_target_url of the file ai-gateway/src/dispatcher/service.rs of the component AWS Metadata Service. Ex…

ai-gateway | Remote | Server-Side Request Forgery
Jul 12, 2026 Jul 13, 2026
Jul 12, 2026
Jul 13, 2026
6.5 MEDIUM
CVE-2026-15507 — coollabsio Coolify Policy Policies authorization

A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation resul…

coolify | Remote | Authorization
Jul 12, 2026 Jul 13, 2026
Jul 12, 2026
Jul 13, 2026
7.8 HIGH
CVE-2026-15506 — SecureAge CatchPulse Driver saappctl.sys heap-based overflow

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation lea…

catchpulse | Memory Corruption
Jul 12, 2026 Jul 14, 2026
Jul 12, 2026
Jul 14, 2026
4.0 MEDIUM
CVE-2026-15505 — vnotex vnote YAML Frontmatter markdownit.js cross site scripting

A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra/web/js/markdownit.js of the component YAML Frontmatter. This manipulation of t…

vnote | Remote | Cross-Site Scripting
Jul 12, 2026 Jul 14, 2026
Jul 12, 2026
Jul 14, 2026
4.6 MEDIUM
CVE-2026-10668 — Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver

The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage unconditionally (base->CEPTXCNT = len in numaker_hsusbd_ep_trigger). Because th…

zephyr zephyr | Denial of Service
Jul 12, 2026 Jul 16, 2026
Jul 12, 2026
Jul 16, 2026
7.8 HIGH
CVE-2026-10667 — SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable…

Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel objects. Iteration over t…

zephyr zephyr | Race Condition
Jul 12, 2026 Jul 16, 2026
Jul 12, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-10666 — Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/n…

parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed 17-byte stack buffer (char ipaddr[NET_IPV4_ADDR_LE…

zephyr zephyr | Remote | Memory Corruption
Jul 12, 2026 Jul 17, 2026
Jul 12, 2026
Jul 17, 2026
7.4 HIGH
CVE-2026-10665 — Heap buffer overflow on WireGuard receive path via unbounded incoming packet length

In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbound transport-data payload into a fixed pool buffer of CONFIG_WIREGUARD_BUF_LEN …

zephyr zephyr | Memory Corruption
Jul 12, 2026 Jul 16, 2026
Jul 12, 2026
Jul 16, 2026
5.0 MEDIUM
CVE-2026-10664 — Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow co…

The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drivers/wifi/nrf_wifi/src/wifi_mgmt.c copied TWT (Target Wake Time) flow entries from an nrf_wifi_umac_e…

zephyr zephyr | Memory Corruption
Jul 12, 2026 Jul 16, 2026
Jul 12, 2026
Jul 16, 2026
6.1 MEDIUM
CVE-2026-10663 — Use-after-free / double-free of the root USB device in the experimental USB host stack

In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) freed the root usb_device slab object without clearing the cached pointer ctx…

zephyr zephyr | Memory Corruption
Jul 12, 2026 Jul 16, 2026
Jul 12, 2026
Jul 16, 2026
8.3 HIGH
CVE-2026-58596 — Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

Jul 12, 2026 Jul 14, 2026
Jul 12, 2026
Jul 14, 2026
Showing 20 of 10234 Results