Common Vulnerabilities and Exposures (CVE)

CVE-2026-62959

Jul 31, 2026 23:34:33 UTC

Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect <URL> and exposes a plaintext-TCP listener, an unauthenticated remote client can send a single ordin...

CVE-2026-55825

Jul 31, 2026 23:33:16 UTC

Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier containing ../ segments and make the job attachment download endpoint read a file from ...

CVE-2026-53504

Jul 31, 2026 23:31:37 UTC

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time...

CVE-2026-53500

Jul 31, 2026 23:30:44 UTC

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. Th...

CVE-2026-54707

Jul 31, 2026 23:28:15 UTC

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting...

CVE-2026-67350

Jul 31, 2026 23:26:27 UTC

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plug...

CVE-2026-17567

Jul 31, 2026 23:25:22 UTC

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter du...

CVE-2026-11770

Jul 31, 2026 23:24:38 UTC

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with ele...

CVE-2026-18214

Jul 31, 2026 23:21:31 UTC

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak t...

CVE-2026-18203

Jul 31, 2026 23:20:33 UTC

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to...

CVE-2026-56671

Jul 31, 2026 23:19:15 UTC

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containm...

CVE-2026-63223

Jul 31, 2026 23:16:24 UTC

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an a...

CVE-2026-55499

Jul 31, 2026 23:15:27 UTC

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authenticate...

CVE-2026-62246

Jul 31, 2026 23:12:53 UTC

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSc...

CVE-2026-0631

Jul 31, 2026 23:12:03 UTC

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full ad...