Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-72918 — Rocket.Chat: Insecure implementation of websocket notifications

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the WebSocke…

rocket.chat rocket.chat | Remote | Authorization
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
5.9 MEDIUM
CVE-2026-72917 — AnythingLLM: Password recovery accepts one recovery code twice after whitespace normaliza…

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow i…

anythingllm | Remote | Authentication
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
6.3 MEDIUM
CVE-2026-72916 — Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.private_address? in app/lib/private_address_check.rb …

mastodon | Remote | Server-Side Request Forgery
Aug 10, 2026 Aug 13, 2026
Aug 10, 2026
Aug 13, 2026
7.5 HIGH
CVE-2026-72915 — Mastodon: Personally-identifying information disclosure due to incorrect access control v…

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show action in app/controllers/admin…

mastodon | Remote | Authorization
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
7.5 HIGH
CVE-2026-72914 — Mastodon: Exhausting data by an unauthenticated request to the admin retention API

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::Measur…

mastodon | Remote | Denial of Service
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
4.4 MEDIUM
CVE-2026-6426 — Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds acc…

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int3…

Aug 10, 2026 Aug 31, 2026
Aug 10, 2026
Aug 31, 2026
4.9 MEDIUM
CVE-2025-32736 — PingFederate Administrative Console CSRF weaknesses

Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered…

pingfederate pingfederate | Remote | Cross-Site Request Forgery
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.3 MEDIUM
CVE-2026-73035 — npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences

npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability that allows an attacker to embed arbitrary terminal control characters in a depe…

Remote | Injection
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
7.0 HIGH
CVE-2026-73033 — Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php

Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrator…

Remote | Path Traversal
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
8.1 HIGH
CVE-2026-73030 — unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to…

unearth | Remote | Path Traversal
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
7.3 HIGH
CVE-2026-72913 — Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS es…

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remot…

kitty | Injection
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
4.3 MEDIUM
CVE-2026-72912 — CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when pa…

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #…

cyberchef | Remote | Denial of Service
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-72911 — ERPNext: Possibility of server-side template injection due to missing validation

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_ac…

erpnext | Remote | Injection
Aug 10, 2026 Aug 13, 2026
Aug 10, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-72910 — ERPNext: Unauthorised modification of master data due to missing validation

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_cen…

erpnext | Remote | Authorization
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
7.1 HIGH
CVE-2026-72909 — ERPNext: Broken Access Control on certain endpoints

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/…

erpnext | Remote | Authorization
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-72908 — ERPNext: Possibility of SQL injection due to missing validation

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WH…

erpnext | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-72907 — ERPNext: Broken Access Control on certain endpoint

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without en…

erpnext | Remote | Authorization
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-72906 — ERPNext: Unauthorised triggering of automated emails due to missing validation

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_stat…

erpnext | Remote | Authorization
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
9.3 CRITICAL
CVE-2026-72904 — Firecrawl: Arbitrary file read via JSON Schema $ref expansion

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe…

Remote | Path Traversal
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
8.1 HIGH
CVE-2026-72903 — Tabby: Windows SFTP path traversal allows a malicious server to write files outside the s…

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/…

tabby | Remote | Path Traversal
Aug 10, 2026 Aug 11, 2026
Aug 10, 2026
Aug 11, 2026
Showing 20 of 13969 Results