CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2026-19500

    Last Modified: 19 Aug 2026

    The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions.

    Published: 18 Aug 2026
    4.8
    Medium

    CVE-2026-75904

    Last Modified: 18 Aug 2026

    libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array. The index is the smpno field of a parsed MIDI event, which is initialised to zero and only later overwritten from a program-change parameter, so an event reaching the note test before an instrument is assigned carries zero. A 32-byte MIDI file supplied to the library's public ModPlug_Load entry point drives the path through CSoundFile::Create, CSoundFile::ReadMID, and MID_ReadPatterns to the read. The byte read out of bounds determines whether a note event is treated as looping, so adjacent static storage influences playback state.

    Published: 18 Aug 2026
    8.7
    High

    CVE-2026-75859

    Last Modified: 18 Aug 2026

    CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.

    Published: 18 Aug 2026
    8.5
    High

    CVE-2026-75858

    Last Modified: 18 Aug 2026

    CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine treats as 'never prompt,' causing arbitrary model-supplied Python code to run in a python3 interpreter without consulting the user's configured --approval-policy and without any approval prompt or audit step. An attacker can induce the agent to execute arbitrary code via prompt injection in untrusted content the agent reads (a web page, fetched URL, repository file, or MCP tool result); the companion rlm_open tool can stage such content. Code runs on the user's machine at the user's privilege level. Fixed in 0.8.64.

    Published: 18 Aug 2026
    7.3
    High

    CVE-2026-75857

    Last Modified: 19 Aug 2026

    CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-executing tools, so LLM-controlled stdin is written into an already-approved long-running interactive shell (e.g., a python3 -i REPL, mysql, ssh, or sudo -i session) without any approval prompt. An attacker who can inject instructions via untrusted content the agent ingests (a fetched page, MCP result, or repo file) can cause commands to run at the privilege level of that approved process. Fixed in 0.8.64.

    Published: 18 Aug 2026
    9.2
    Critical

    CVE-2026-75856

    Last Modified: 18 Aug 2026

    CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, allowing requests to internal IP addresses and bypassing SSRF mitigations.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-19501

    Last Modified: 21 Aug 2026

    CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is opened in a vulnerable spreadsheet application.

    Published: 18 Aug 2026
    2.7
    Low

    CVE-2026-62684

    Last Modified: 18 Aug 2026

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandler, and shareGetsHandler through renderJSON, causing POST /api/share/{path} and GET /api/shares to expose password_hash and the bypass token, while an administrator can retrieve these secrets for every user's shares, enabling offline password cracking and direct access to protected shares. This issue is fixed in version 2.63.17.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-62357

    Last Modified: 19 Aug 2026

    Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose width times depth times sizeof(int64_t) overflows in src/core/cms.cc, allocating an undersized counter buffer while CMS.INCRBY and CMS.QUERY use the unbounded dimensions, which allows an unauthenticated remote client to corrupt or disclose adjacent heap memory and crash the server. This issue is fixed in version 1.40.0.

    Published: 18 Aug 2026
    6.8
    Medium

    CVE-2026-63328

    Last Modified: 18 Aug 2026

    Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who persuades a user to install or run a malicious plugin to write the manifest and plugin binary to arbitrary user-writable paths, while plugins from the official Trivy plugin index are not affected. This issue is fixed in version 0.72.0.

    Published: 18 Aug 2026
    8.3
    High

    CVE-2026-45733

    Last Modified: 18 Aug 2026

    Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron enables nodeIntegration and disables contextIsolation, run operating-system commands as the victim. This issue is fixed in version 0.103.0.

    Published: 18 Aug 2026
    2
    Low

    CVE-2026-68939

    Last Modified: 18 Aug 2026

    Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-50187

    Last Modified: 21 Aug 2026

    Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT=false or after the default prompt accepts an empty Enter response. This issue is fixed in versions released after 2026-05-28.

    Published: 18 Aug 2026
    7.4
    High

    CVE-2026-59825

    Last Modified: 21 Aug 2026

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq background jobs remain unaffected. This issue is fixed in versions 4.4.19 and 4.5.12.

    Published: 18 Aug 2026
    7.6
    High

    CVE-2026-69189

    Last Modified: 18 Aug 2026

    Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0.

    Published: 18 Aug 2026
    7.7
    High

    CVE-2026-71365

    Last Modified: 25 Aug 2026

    A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload without validating the target host against the expected Git provider. This URL is persisted in job extra variables and later used to send authenticated status updates. A user with admin role on a webhook-enabled job template can read the template's webhook signing key, forge a signed GitHub webhook payload with an arbitrary statuses_url, and cause AWX to POST status updates to an attacker-controlled or internal URL. The status update request includes the configured Git Personal Access Token (PAT) in the Authorization header, resulting in credential leakage to the attacker-specified endpoint.

    Published: 18 Aug 2026
    5.9
    Medium

    CVE-2026-50139

    Last Modified: 18 Aug 2026

    goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served — exceeding the operator's intended cap. Version 2.1.0 patches the issue.

    Published: 18 Aug 2026
    4.3
    Medium

    CVE-2026-70657

    Last Modified: 19 Aug 2026

    Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder. This vulnerability was only reachable if both types of keys (filekeys and dirkeys) were manually enabled in the volume flags simultaneously. This issue is fixed in version 1.20.17.

    Published: 18 Aug 2026
    8.1
    High

    CVE-2026-50138

    Last Modified: 19 Aug 2026

    goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`, `MOVE`, and `COPY` despite the operator's stated intent. Version 2.1.0 patches the issue.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-59949

    Last Modified: 21 Aug 2026

    yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.

    Published: 18 Aug 2026
    7.4
    High

    CVE-2026-18534

    Last Modified: 18 Aug 2026

    ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.

    Published: 18 Aug 2026
    7.1
    High

    CVE-2026-48798

    Last Modified: 21 Aug 2026

    SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to create or overwrite files anywhere writable by the client process. This issue is fixed in version 2026.0.0.

    Published: 18 Aug 2026
    3.3
    Low

    CVE-2026-63632

    Last Modified: 18 Aug 2026

    Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.

    Published: 18 Aug 2026
    8.9
    High

    CVE-2026-71539

    Last Modified: 21 Aug 2026

    n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted repository in the community node directory that loads as a custom JavaScript node after restart and executes arbitrary code on the server. This issue is fixed in versions 1.123.64, 2.29.8, and 2.30.1.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-59940

    Last Modified: 18 Aug 2026

    Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-61407

    Last Modified: 21 Aug 2026

    Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

    Published: 18 Aug 2026
    5.5
    Medium

    CVE-2026-75485

    Last Modified: 2 Sept 2026

    A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially disclosing sensitive authentication information to anyone with access to the archive.

    Published: 18 Aug 2026
    5.5
    Medium

    CVE-2026-73834

    Last Modified: 27 Aug 2026

    A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive, potentially exposing sensitive information to anyone with access to the archive.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-66793

    Last Modified: 27 Aug 2026

    A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and privilege escalation.

    Published: 18 Aug 2026
    4.6
    Medium

    CVE-2026-73426

    Last Modified: 18 Aug 2026

    Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17.

    Published: 18 Aug 2026
    8.4
    High

    CVE-2026-75898

    Last Modified: 18 Aug 2026

    RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, requests.post, or requests.put without calling the shared assert_url_is_safe validator or pinning the resolved address, unlike the crawler, SearXNG, file-upload, and RSS fetch paths. A user who can create or trigger an agent can direct the server to fetch loopback, link-local, and RFC 1918 destinations, including cloud instance metadata endpoints and services co-located on the deployment network, and the response body is returned as the component output. Where an agent is configured to interpolate the chat query into the Invoke URL, the destination is chosen by whoever can send that query.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-63639

    Last Modified: 21 Aug 2026

    Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-56684

    Last Modified: 19 Aug 2026

    Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.

    Published: 18 Aug 2026
    8.7
    High

    CVE-2026-66046

    Last Modified: 21 Aug 2026

    Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.

    Published: 18 Aug 2026
    6.9
    Medium

    CVE-2026-75872

    Last Modified: 18 Aug 2026

    HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription request, which is interpolated unescaped into the double opt-in verification email.

    Published: 18 Aug 2026
    9.3
    Critical

    CVE-2026-74015

    Last Modified: 21 Aug 2026

    Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

    Published: 18 Aug 2026
    8.8
    High

    CVE-2026-74012

    Last Modified: 20 Aug 2026

    Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.

    Published: 18 Aug 2026
    5.3
    Medium

    CVE-2026-74009

    Last Modified: 18 Aug 2026

    Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.

    Published: 18 Aug 2026
    5.3
    Medium

    CVE-2026-74008

    Last Modified: 18 Aug 2026

    Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.

    Published: 18 Aug 2026
    5.3
    Medium

    CVE-2026-74007

    Last Modified: 21 Aug 2026

    Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.

    Published: 18 Aug 2026
    4.3
    Medium

    CVE-2026-74006

    Last Modified: 21 Aug 2026

    Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.

    Published: 18 Aug 2026
    5.4
    Medium

    CVE-2026-74004

    Last Modified: 21 Aug 2026

    Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <= 6.0 versions.

    Published: 18 Aug 2026
    4.3
    Medium

    CVE-2026-74003

    Last Modified: 18 Aug 2026

    Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-73997

    Last Modified: 21 Aug 2026

    Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.

    Published: 18 Aug 2026
    9.8
    Critical

    CVE-2026-73996

    Last Modified: 21 Aug 2026

    Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

    Published: 18 Aug 2026
    5.4
    Medium

    CVE-2026-73995

    Last Modified: 18 Aug 2026

    Subscriber Broken Authentication in User Registration <= 5.2.6 versions.

    Published: 18 Aug 2026
    7.5
    High

    CVE-2026-73994

    Last Modified: 21 Aug 2026

    Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-73404

    Last Modified: 21 Aug 2026

    Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.

    Published: 18 Aug 2026
    8.1
    High

    CVE-2026-73400

    Last Modified: 18 Aug 2026

    Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.

    Published: 18 Aug 2026
    6.5
    Medium

    CVE-2026-73399

    Last Modified: 21 Aug 2026

    Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.

    Published: 18 Aug 2026