Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 CRITICAL
CVE-2026-48381 — Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL…

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the …

campaign campaign_classic | Remote | Injection
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.8 HIGH
CVE-2026-47940 — Lightroom Classic | Integer Overflow or Wraparound (CWE-190)

Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires …

lightroom windows | Memory Corruption
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
9.6 CRITICAL
CVE-2026-47705 — TypeBot vulnerable to CSV injection in result export

TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating…

typebot | Remote | Injection
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
10.0 CRITICAL
CVE-2026-27302 — Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this v…

campaign campaign_classic | Remote | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
4.0 MEDIUM
CVE-2026-20917 — Intel Processor Transient Execution Information Disclosure

Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. Sy…

| Information Disclosure
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-20901 — Intel Xeon Processor Firmware Improper Input Validation Privilege Escalation

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complex…

Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
4.0 MEDIUM
CVE-2026-20712 — Intel UEFI Firmware Information Disclosure

Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low co…

| Information Disclosure
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
5.6 MEDIUM
CVE-2026-0465 — AMD Ryzen Master Utility Driver Use-After-Free Vulnerability

A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentially resulting in loss of availability

Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
7.0 HIGH
CVE-2025-54512 — AMD Ryzen Master DLL Hijacking Privilege Escalation

A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to escalate privileges, potentially resulting in arbitrary code execution.

ryzen_master ryzen_master | Misconfiguration
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
7.0 HIGH
CVE-2025-0046 — Incorrect Directory Permissions Privilege Escalation

Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.

| Misconfiguration
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
8.7 HIGH
CVE-2022-50997 — Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp

Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the b…

e-cology | Remote | Injection
Aug 11, 2026 Sep 08, 2026
Aug 11, 2026
Sep 08, 2026
8.7 HIGH
CVE-2016-20097 — Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad

Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT p…

Remote | Injection
Aug 11, 2026 Sep 08, 2026
Aug 11, 2026
Sep 08, 2026
7.5 HIGH
CVE-2026-73089 — Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, lea…

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache an…

browserslist | Remote | Denial of Service
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
7.5 HIGH
CVE-2026-73088 — Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json cust…

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() …

browserslist | Remote | Misconfiguration
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
2.3 LOW
CVE-2026-73087 — Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook no…

Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, used by safeDialContext for webhook notifi…

dozzle | Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.4 HIGH
CVE-2026-73086 — nanoid: Integer Overflow or Wraparound

nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size …

nanoid | Remote | Misconfiguration
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
5.3 MEDIUM
CVE-2026-73085 — Audiobookshelf: Refresh Token Accepted on Resource Endpoints

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens…

audiobookshelf | Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.1 MEDIUM
CVE-2026-73084 — Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script…

activepieces | Remote | Cross-Site Scripting
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
7.6 HIGH
CVE-2026-73083 — Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading

Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine loads the compiled user module with importFresh(), a wrapper around Node.js requ…

activepieces | Remote | Misconfiguration
Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
5.3 MEDIUM
CVE-2026-73082 — Activepieces: Server-side request forgery in MCP tool validation endpoint

Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request…

activepieces | Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
Showing 20 of 14281 Results