CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2026-75421

    Last Modified: 31 Aug 2026

    aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.

    Published: 25 Aug 2026
    8.4
    High

    CVE-2026-52491

    Last Modified: 31 Aug 2026

    An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component

    Published: 25 Aug 2026
    5.4
    Medium

    CVE-2026-38474

    Last Modified: 31 Aug 2026

    GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulnerability in the IP lock manager, which allows remote authenticated users to add, modify, or delete IP lock entries for arbitrary accounts via tools.php?action=iplock.

    Published: 25 Aug 2026
    5.4
    Medium

    CVE-2026-38473

    Last Modified: 31 Aug 2026

    A Stored XSS vulnerability in the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via a crafted subtitle filename, which is stored during upload and later rendered in /subtitles.php?action=delete.

    Published: 25 Aug 2026
    4.3
    Medium

    CVE-2026-38470

    Last Modified: 31 Aug 2026

    A Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token.

    Published: 25 Aug 2026
    5.4
    Medium

    CVE-2026-38467

    Last Modified: 31 Aug 2026

    A SQL injection vulnerability in the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users with users_mod privileges to execute arbitrary SQL commands via the tagid or type parameter in a crafted POST request to tools.php?action=manage_tags.

    Published: 25 Aug 2026
    5.4
    Medium

    CVE-2026-38466

    Last Modified: 31 Aug 2026

    A Stored XSS vulnerability in the torrent remaster custom title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the remaster_custom_title parameter, which is stored during torrent upload or edit and later rendered in torrent title output.

    Published: 25 Aug 2026
    7.6
    High

    CVE-2026-80186

    Last Modified: 27 Aug 2026

    A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

    Published: 25 Aug 2026
    5.7
    Medium

    CVE-2026-80185

    Last Modified: 26 Aug 2026

    BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

    Published: 25 Aug 2026
    5.9
    Medium

    CVE-2026-63074

    Last Modified: 11 Sept 2026

    Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth. Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack. This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely. The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all. FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

    Published: 25 Aug 2026
    7.5
    High

    CVE-2026-63072

    Last Modified: 11 Sept 2026

    Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure. The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation. FIPS impact: no As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

    Published: 25 Aug 2026
    7.5
    High

    CVE-2026-63076

    Last Modified: 11 Sept 2026

    Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer. Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service. CWE: CWE-476: NULL Pointer Dereference Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted. This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable. FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

    Published: 25 Aug 2026
    7.5
    High

    CVE-2026-18798

    Last Modified: 25 Aug 2026

    Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time. The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length. FIPS impact: no The FIPS module is not affected, as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Published: 25 Aug 2026
    7.5
    High

    CVE-2026-14457

    Last Modified: 11 Sept 2026

    Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or servers that don't support raw public keys may be able to complete a TLS connection by pinning or verifying the corresponding certificate or its public key. Deployments that prefer to configure just a private key with no certificate need to upgrade to an updated release as noted below. FIPS impact: no No FIPS modules are affected by this issue, as the SSL protocol implementation is outside the OpenSSL FIPS module boundary.

    Published: 25 Aug 2026
    6.1
    Medium

    CVE-2026-38472

    Last Modified: 31 Aug 2026

    A Stored XSS vulnerability in forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote attackers to inject arbitrary JavaScript via the c parameter in /forums.php?action=ajax_get_jf which is later rendered in the data-tooltip attribute in /forums.php?action=viewthread and interpreted as HTML by the Tooltipster configuration.

    Published: 25 Aug 2026
    7.1
    High

    CVE-2026-53532

    Last Modified: 28 Aug 2026

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13.

    Published: 24 Aug 2026
    6.5
    Medium

    CVE-2026-68516

    Last Modified: 25 Aug 2026

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14.

    Published: 24 Aug 2026
    2
    Low

    CVE-2026-78435

    Last Modified: 27 Aug 2026

    A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-78282

    Last Modified: 25 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

    Published: 24 Aug 2026
    7.5
    High

    CVE-2026-78268

    Last Modified: 28 Aug 2026

    Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

    Published: 24 Aug 2026
    9.8
    Critical

    CVE-2026-78267

    Last Modified: 27 Aug 2026

    Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

    Published: 24 Aug 2026
    6.5
    Medium

    CVE-2026-78266

    Last Modified: 25 Aug 2026

    Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.

    Published: 24 Aug 2026
    9.8
    Critical

    CVE-2026-78265

    Last Modified: 25 Aug 2026

    Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-78264

    Last Modified: 25 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-78263

    Last Modified: 25 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

    Published: 24 Aug 2026
    9.8
    Critical

    CVE-2026-78262

    Last Modified: 27 Aug 2026

    Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

    Published: 24 Aug 2026
    7.3
    High

    CVE-2026-78259

    Last Modified: 25 Aug 2026

    Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

    Published: 24 Aug 2026
    9.8
    Critical

    CVE-2026-32563

    Last Modified: 25 Aug 2026

    Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

    Published: 24 Aug 2026
    8.8
    High

    CVE-2026-32561

    Last Modified: 25 Aug 2026

    Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.

    Published: 24 Aug 2026
    8.8
    High

    CVE-2026-32560

    Last Modified: 28 Aug 2026

    Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.

    Published: 24 Aug 2026
    9.9
    Critical

    CVE-2026-32559

    Last Modified: 27 Aug 2026

    Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.

    Published: 24 Aug 2026
    7.1
    High

    CVE-2026-32556

    Last Modified: 28 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.

    Published: 24 Aug 2026
    9.3
    Critical

    CVE-2026-32555

    Last Modified: 28 Aug 2026

    Unauthenticated SQL Injection in Boost <= 2.0.4 versions.

    Published: 24 Aug 2026
    9.3
    Critical

    CVE-2026-32554

    Last Modified: 25 Aug 2026

    Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.

    Published: 24 Aug 2026
    6.5
    Medium

    CVE-2026-27364

    Last Modified: 25 Aug 2026

    Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.

    Published: 24 Aug 2026
    8.6
    High

    CVE-2026-78284

    Last Modified: 25 Aug 2026

    Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

    Published: 24 Aug 2026
    5.5
    Medium

    CVE-2026-78434

    Last Modified: 25 Aug 2026

    A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 24 Aug 2026
    9.1
    Critical

    CVE-2026-77337

    Last Modified: 25 Aug 2026

    CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CPU or memory exhaustion when CookieAuthenticator uses unencrypted, forgeable legacy tokens. This issue is fixed in versions 2.11.2, 3.3.7, and 4.2.1.

    Published: 24 Aug 2026
    5.9
    Medium

    CVE-2026-45404

    Last Modified: 27 Aug 2026

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/write access, concurrent SetBaggageItem and correlation.MapFromContext calls on the same hooked bridgeSpan can trigger a fatal runtime error—such as concurrent map read and map write or concurrent map iteration and map write—terminating the process and causing denial of service. This issue is fixed in version 1.45.0.

    Published: 24 Aug 2026
    7.5
    High

    CVE-2026-77384

    Last Modified: 25 Aug 2026

    libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE requests for the same reservation, causing unbounded listener and closure growth in @libp2p/circuit-relay-v2 relay servers and leading to denial of service. This issue is fixed in version 4.2.9.

    Published: 24 Aug 2026
    7.8
    High

    CVE-2026-19568

    Last Modified: 28 Aug 2026

    A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

    Published: 24 Aug 2026
    7.8
    High

    CVE-2026-7455

    Last Modified: 28 Aug 2026

    A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 24 Aug 2026
    7.8
    High

    CVE-2026-16783

    Last Modified: 28 Aug 2026

    A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 24 Aug 2026
    5.3
    Medium

    CVE-2026-16782

    Last Modified: 28 Aug 2026

    A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 24 Aug 2026
    5.5
    Medium

    CVE-2026-16781

    Last Modified: 28 Aug 2026

    A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service.

    Published: 24 Aug 2026
    6
    Medium

    CVE-2026-17113

    Last Modified: 27 Aug 2026

    A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI `Envs` field, CRI-O falls back to using the target OCI image's `config.Env` entries unfiltered, in contrast to the normal merge path, which validates each entry for a `key=value` form before use. An OCI image whose `config.Env` contains an entry with no `=` character (e.g. a bare `NOEQUALS` string) causes CRI-O to split that entry into a single-element slice and then index its second element, which is out of range. This triggers an unrecovered Go runtime panic in the `crio` daemon process, crashing it and terminating the container-runtime service for all workloads on the node until it is restarted.

    Published: 24 Aug 2026
    4.3
    Medium

    CVE-2026-55468

    Last Modified: 25 Aug 2026

    Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.

    Published: 24 Aug 2026
    8.2
    High

    CVE-2026-77634

    Last Modified: 25 Aug 2026

    CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection when user-controlled data is used in message headers. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7.

    Published: 24 Aug 2026
    6.8
    Medium

    CVE-2026-5006

    Last Modified: 25 Aug 2026

    A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy. This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.

    Published: 24 Aug 2026
    9.2
    Critical

    CVE-2026-77635

    Last Modified: 28 Aug 2026

    CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7.

    Published: 24 Aug 2026