Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-18690 — Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not pe…

mongodb | Remote | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-18688 — Out-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Service and Potent…

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation…

mongodb | Remote | Memory Corruption
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-18687 — Improper Validation in MongoDB Queryable Encryption Maintenance Operation Leads to Denial…

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An au…

mongodb | Remote | Denial of Service
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-15426 — AcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Take…

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1…

acymailing | Remote | Authorization
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-73219 — CVAT: Denial of service with regards to automatic annotation

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with write access to a CVAT job can submit a batch automatic annotation reques…

computer_vision_annotation_tool | Remote | Denial of Service
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
7.7 HIGH
CVE-2026-73218 — Cursor: Sandbox escape via launching privileged containers

Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are instal…

cursor | Remote | Misconfiguration
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
7.7 HIGH
CVE-2026-73217 — Cursor: Sandbox escape via tampered Python virtual environments

Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with …

cursor | Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-73216 — coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c prematurely calls dec_quota() and releases bandwidth …

coturn | Remote | Denial of Service
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.1 HIGH
CVE-2026-73215 — The coturn server can end in a state where it does not accept more requests with "even-po…

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks the unused odd sibling port as TPS_TAKEN_ODD for a…

coturn | Remote | Denial of Service
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
8.2 HIGH
CVE-2026-73214 — coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling s…

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSS…

coturn | Remote | Denial of Service
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
5.8 MEDIUM
CVE-2026-73213 — Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic…

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals …

coturn | Remote | Authorization
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
5.8 MEDIUM
CVE-2026-73212 — coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path…

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without c…

coturn | Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.8 CRITICAL
CVE-2026-73211 — PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore()

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowi…

peertube | Remote | Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.3 CRITICAL
CVE-2026-73090 — PeerTube: Cross-origin remote video takeover via Update activity

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying th…

peertube | Remote | Authorization
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
8.7 HIGH
CVE-2026-72713 — XAgent Path Traversal Arbitrary File Read via /workspace/file

XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory…

xagent | Remote | Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.9 MEDIUM
CVE-2026-72712 — Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option…

nmap | Remote | Denial of Service
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
10.0 CRITICAL
CVE-2026-71398 — Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this v…

campaign campaign_classic | Remote | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
9.1 CRITICAL
CVE-2026-71362 — Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive re…

magento_open_source commerce commerce_b2b | Remote | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-69113 — Cap v0.3.1 Broken Access Control via video comment endpoint

Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on any private video without permission by supplying…

Remote | Authorization
Aug 11, 2026 Aug 14, 2026
Aug 11, 2026
Aug 14, 2026
9.8 CRITICAL
CVE-2026-69102 — MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authen…

maxkey | Remote | Authentication
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
Showing 20 of 14302 Results