Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-72579 — NASA HyperCP - OS Command Injection via Malicious HTTP Response from Data Server

An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from oceandata.sci.gsfc.nasa.gov to execute arbitrary syste…

| Injection
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-72578 — FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher

A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.

| Cross-Site Request Forgery
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72577 — NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE an…

Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to conn…

| Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-72576 — Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload

A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Author role) to inject arbitrary JavaScript by uploading a crafted SVG file as the s…

bludit | Cross-Site Scripting
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.1 CRITICAL
CVE-2026-72575 — daptin - Authentication Bypass via Null Owner Permission Check on usergroup Objects

An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, create, update, and delete usergroup records. The permission check functions (CanRe…

| Authorization
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
6.1 MEDIUM
CVE-2026-72574 — picocms Pico - Host Header Injection Enables Script Source Hijacking

A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control the origin of JavaScript and CSS assets loaded by the default theme. When base…

| Misconfiguration
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-72573 — 4xmen pm2panel - Authenticated OS Command Injection via id Query Parameter

An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execute arbitrary system commands on the host. The pm2panel.js handler at line 188 pa…

| Injection
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-72572 — o1lab xmysql - Unauthenticated Path Traversal via name Query Parameter

A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the server. The lib/xapi.js file at lines 338 and 424…

| Path Traversal
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
7.5 HIGH
CVE-2026-72571 — mustafaakin cast-localvideo - Unauthenticated Path Traversal via dir Parameter

A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from the server. The app.js handler at lines 151-153 pas…

| Path Traversal
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
5.4 MEDIUM
CVE-2026-72570 — cube-root directory-serve - Stored Cross-Site Scripting via Malicious Filename

A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafte…

| Cross-Site Scripting
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
9.1 CRITICAL
CVE-2026-72569 — cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Deletion

A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the applicatio…

| Path Traversal
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72567 — deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Write and Delete

An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges. The a…

| Path Traversal
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
7.7 HIGH
CVE-2026-72566 — automatisch - Server-Side Request Forgery via HTTP Request Custom Action

A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow' permission to make the server fetch arbitrary UR…

| Server-Side Request Forgery
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72565 — Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form Bypass

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having o…

| Injection
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.6 CRITICAL
CVE-2026-72564 — fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication

An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued…

| Authorization
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.3 MEDIUM
CVE-2026-71394 — Heap Use of Uninitialized Memory in GNU Emacs for Android

GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to an incorrect comparison variable in the read-length check, a crafted font file t…

emacs | Remote | Memory Corruption
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.3 MEDIUM
CVE-2026-71393 — Heap Buffer Overflow in GNU Emacs for Android

GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file with…

emacs | Remote | Memory Corruption
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.3 MEDIUM
CVE-2026-71392 — Integer Overflow in GNU Emacs for Android

GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc…

emacs | Remote | Memory Corruption
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.3 MEDIUM
CVE-2026-71391 — Off-by-One Error in GNU Emacs for Android

GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a…

emacs | Remote | Memory Corruption
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-66642 — WordPress WP Umbrella plugin 2.24.2-2.26.2 - Cross Site Request Forgery (CSRF) vulnerabil…

Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 through 2.26.2.

Remote | Cross-Site Request Forgery
Aug 10, 2026 Aug 12, 2026
Aug 10, 2026
Aug 12, 2026
Showing 20 of 13964 Results