CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2026-16526

    Last Modified: 18 Aug 2026

    A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.

    Published: 30 Jul 2026
    7.6
    High

    CVE-2026-18381

    Last Modified: 12 Aug 2026

    A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.

    Published: 30 Jul 2026
    5.5
    Medium

    CVE-2026-63623

    Last Modified: 11 Aug 2026

    A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2025-69931

    Last Modified: 5 Aug 2026

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.

    Published: 30 Jul 2026
    6.1
    Medium

    CVE-2025-65342

    Last Modified: 3 Aug 2026

    code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.

    Published: 30 Jul 2026
    6.1
    Medium

    CVE-2025-65341

    Last Modified: 3 Aug 2026

    Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.

    Published: 30 Jul 2026
    5.5
    Medium

    CVE-2022-4994

    Last Modified: 3 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __emulator_pio_in() directly for fast PIO instead of bouncing through emulator_pio_in() now that __emulator_pio_in() fills "val" when handling in-kernel PIO. vcpu->arch.pio.count is guaranteed to be '0', so this a pure nop. emulator_pio_in_emulated is now the last caller of emulator_pio_in. No functional change intended.

    Published: 30 Jul 2026
    9.1
    Critical

    CVE-2026-52539

    Last Modified: 4 Aug 2026

    Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2025-69947

    Last Modified: 4 Aug 2026

    SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2025-69941

    Last Modified: 3 Aug 2026

    SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.

    Published: 30 Jul 2026
    7.3
    High

    CVE-2026-16527

    Last Modified: 18 Aug 2026

    An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2025-69936

    Last Modified: 3 Aug 2026

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2026-35847

    Last Modified: 5 Aug 2026

    An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2025-69938

    Last Modified: 4 Aug 2026

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2025-69934

    Last Modified: 4 Aug 2026

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2025-69935

    Last Modified: 3 Aug 2026

    CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2025-69933

    Last Modified: 31 Jul 2026

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2025-69930

    Last Modified: 3 Aug 2026

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2025-65336

    Last Modified: 2 Aug 2026

    Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.

    Published: 30 Jul 2026
    6.1
    Medium

    CVE-2025-51684

    Last Modified: 2 Aug 2026

    CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by renderCustomHtml, results in execution of arbitrary JavaScript in the context of the hosting site.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2025-69937

    Last Modified: 4 Aug 2026

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

    Published: 30 Jul 2026
    Unknown

    CVE-2026-51295

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 30 Jul 2026
    Unknown

    CVE-2026-51294

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 30 Jul 2026
    Unknown

    CVE-2026-51293

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 30 Jul 2026
    Unknown

    CVE-2026-51292

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2026-51291

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2026-51272

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 30 Jul 2026
    9.8
    Critical

    CVE-2026-38709

    Last Modified: 5 Aug 2026

    TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.

    Published: 30 Jul 2026
    9.1
    Critical

    CVE-2026-51290

    Last Modified: 31 Jul 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 30 Jul 2026
    6.8
    Medium

    CVE-2026-18382

    Last Modified: 12 Aug 2026

    A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this user-controlled URL, allowing the attacker to obtain the credentials.

    Published: 30 Jul 2026
    5.3
    Medium

    CVE-2026-16531

    Last Modified: 30 Jul 2026

    An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.

    Published: 30 Jul 2026
    6.5
    Medium

    CVE-2026-16530

    Last Modified: 21 Aug 2026

    A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.

    Published: 30 Jul 2026
    7.5
    High

    CVE-2026-16529

    Last Modified: 18 Aug 2026

    A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.

    Published: 30 Jul 2026
    4.7
    Medium

    CVE-2026-62343

    Last Modified: 30 Jul 2026

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

    Published: 29 Jul 2026
    5.3
    Medium

    CVE-2026-64685

    Last Modified: 30 Jul 2026

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27.

    Published: 29 Jul 2026
    9.2
    Critical

    CVE-2026-67595

    Last Modified: 14 Aug 2026

    VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added inputs, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite the rendered page.

    Published: 29 Jul 2026
    4.2
    Medium

    CVE-2026-15157

    Last Modified: 3 Aug 2026

    undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob shapes from user input can reach the vulnerable path. This is the same defect class as CVE-2022-35948 and CVE-2026-1527, on a header sink that the earlier fixes did not cover. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.

    Published: 29 Jul 2026
    5.9
    Medium

    CVE-2026-14643

    Last Modified: 3 Aug 2026

    undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the parser either drops the directive or stores a field name with literal quote characters, so the cache decision fails to recognize the qualification and the response is stored. In shared-cache mode, this lets a response containing one user's authenticated data be served from cache to a later caller, including an unauthenticated one, when both requests resolve to the same cache key. It affects applications that enable the cache interceptor in shared mode, forward Authorization headers upstream, and receive cacheable responses with qualified directives padded with whitespace around the equals sign. This is the whitespace-around-equals variant that the fix for CVE-2026-9678 did not normalize, and it is fixed in undici 7.29.0 and 8.9.0.

    Published: 29 Jul 2026
    Unknown

    CVE-2026-67619

    Last Modified: 21 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 29 Jul 2026
    4.8
    Medium

    CVE-2026-16728

    Last Modified: 2 Aug 2026

    undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a malicious or faulty upstream can return a partial response with a mismatched framing header, close the socket early, and have the retry interceptor assemble a body of a different length while the original Content-Length stays attached. Applications that use the retry interceptor and forward upstream headers and bodies downstream, such as proxies or gateways, may then emit an invalid HTTP response with a stale Content-Length, leading to downstream response desynchronization, connection hangs, or response corruption. Exploitation requires the retry interceptor enabled, an upstream returning a mismatched partial response, and a downstream forwarder that does not remove or recalculate Content-Length. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.

    Published: 29 Jul 2026
    4.3
    Medium

    CVE-2026-67439

    Last Modified: 30 Jul 2026

    OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints return full LogEntry output after execution without enforcing the logs permission, allowing a user with exec permission but logs:false to read action output. This issue is fixed in version 3000.17.0.

    Published: 29 Jul 2026
    6.6
    Medium

    CVE-2026-67438

    Last Modified: 30 Jul 2026

    OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go checkShellArgumentSafety function does not treat regex: custom argument types as unsafe for Shell mode actions, allowing values that pass typeSafetyCheckRegex to be interpolated by wrapCommandInShell into an sh -c command string and enabling OS command injection. This issue is fixed in version 3000.17.0.

    Published: 29 Jul 2026
    7.5
    High

    CVE-2026-67437

    Last Modified: 30 Jul 2026

    OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bounding entries, allowing an unauthenticated attacker to exhaust memory and cause a denial of service. This issue is fixed in version 3000.17.0.

    Published: 29 Jul 2026
    6.8
    Medium

    CVE-2026-54249

    Last Modified: 30 Jul 2026

    Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application's model-provider or cloud-storage account. While file URL parts are validated against a scheme allowlist, UploadedFile references — which point to a file by provider file ID or cloud-storage URI (e.g. s3://…, gs://…) — were forwarded without validation. Because the provider resolves an UploadedFile using the server-side identity (IAM role, service account, or provider API key) rather than the client's, an attacker can craft message history to make the server read objects from its own account or other tenants, given a referenceable identifier. Exploitation requires a valid file identifier, which is not always unguessable depending on how the application names objects. This issue has been fixed in versions 1.106.0 and 2.0.0b6.

    Published: 29 Jul 2026
    6.8
    Medium

    CVE-2026-46678

    Last Modified: 30 Jul 2026

    Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local' (disabling the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form (IPv4-mapped IPv6, 6to4, or NAT64), exposing cloud IAM short-term credentials on dual-stack or translated networks. This is an incomplete fix of GHSA-2jrp-274c-jhv3 / CVE-2026-25580, whose remediation did not hold for IPv6-encoded forms of the metadata IPs. An application is affected only if it explicitly opts a FileUrl (ImageUrl, AudioUrl, VideoUrl, DocumentUrl) into force_download='allow-local' on a URL influenced by untrusted input; it is not affected when using bundled integrations to ingest user input (Agent.to_web / clai web, VercelAIAdapter, AGUIAdapter / Agent.to_ag_ui), since they do not propagate force_download from external data, nor when downloading only from developer-controlled URLs. This issue has been fixed in version 1.99.0.

    Published: 29 Jul 2026
    8.1
    High

    CVE-2026-13308

    Last Modified: 30 Jul 2026

    Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of WebSocket messages related to the OCPP service. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29113.

    Published: 29 Jul 2026
    6.8
    Medium

    CVE-2026-13307

    Last Modified: 30 Jul 2026

    Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of custom USB packets. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29048.

    Published: 29 Jul 2026
    6.8
    Medium

    CVE-2026-13309

    Last Modified: 30 Jul 2026

    Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of card responses via the NFC interface. A crafted card response can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29044.

    Published: 29 Jul 2026
    4.3
    Medium

    CVE-2026-13306

    Last Modified: 30 Jul 2026

    Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the exposed USB interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-29046.

    Published: 29 Jul 2026
    6.4
    Medium

    CVE-2026-13305

    Last Modified: 30 Jul 2026

    Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of software updates. The issue results from the lack of proper validation of a user-supplied software update image. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29062.

    Published: 29 Jul 2026