Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.4 HIGH
CVE-2026-71968 — OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENT

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Applicatio…

op-tee_os op-tee | Memory Corruption
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
5.7 MEDIUM
CVE-2026-71967 — OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session

OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pseudo-TA open_session handler that allows Normal World clients to cause a denial …

op-tee_os op-tee | Denial of Service
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.1 HIGH
CVE-2026-71964 — CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading …

cyberpanel | Remote | Path Traversal
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-71962 — Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download

Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private…

flowise | Remote | Authorization
Aug 10, 2026 Sep 04, 2026
Aug 10, 2026
Sep 04, 2026
6.6 MEDIUM
CVE-2026-6791 — Potential stack-based buffer clash during tilde expansion in wordexp

When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates …

glibc | Remote | Memory Corruption
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
2.1 LOW
CVE-2026-6368 — wordexp with WRDE_APPEND can return or use invalid memory

Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may ab…

glibc | Memory Corruption
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-68872 — Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard b…

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the tea…

apache-airflow-providers-amazon | Remote | Authorization
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-68871 — Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves …

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deplo…

apache-airflow-providers-apache-yandex | Remote | Authorization
Aug 10, 2026 Aug 17, 2026
Aug 10, 2026
Aug 17, 2026
5.3 MEDIUM
CVE-2026-68870 — Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope gu…

The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. …

Remote | Authorization
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
7.8 HIGH
CVE-2026-59091 — Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image …

Aug 10, 2026 Aug 24, 2026
Aug 10, 2026
Aug 24, 2026
6.9 MEDIUM
CVE-2026-12339 — Authenticated Arbitrary File Write Vulnerability in multiple devices

A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrit…

Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
7.1 HIGH
CVE-2026-72900 — Metabase information exposure

Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

metabase | Remote | Information Disclosure
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
10.0 CRITICAL
CVE-2026-72899 — Metabase SQL injection via public card or dashboard

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.

metabase | Remote | Injection
Aug 10, 2026 Aug 26, 2026
Aug 10, 2026
Aug 26, 2026
10.0 CRITICAL
CVE-2026-72898 — Metabase SQL Injection Vulnerability - [Actively Exploited]

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

metabase | CISA KEV Remote | Injection
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
9.9 CRITICAL
CVE-2026-72862 — Dokploy: OS Command Injection via dockerImage field in database service deployment functi…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment functions…

dokploy | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
9.9 CRITICAL
CVE-2026-72740 — Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan`

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with sanitizeRepoPathSSH and interp…

dokploy | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-72739 — Dokploy: Command Injection via Compose Shell Execution

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolating compose service names and configuration into b…

dokploy | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
9.9 CRITICAL
CVE-2026-72738 — Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Paramet…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passes the search parameter thro…

dokploy | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
9.6 CRITICAL
CVE-2026-72737 — Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's …

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accep…

dokploy | Remote | Authorization
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
9.9 CRITICAL
CVE-2026-72736 — Dokploy: OS Command Injection in registry credential testing and Swarm cluster management…

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal interpolation in the …

dokploy | Remote | Injection
Aug 10, 2026 Sep 08, 2026
Aug 10, 2026
Sep 08, 2026
Showing 20 of 13964 Results