This page offers a live ATOM feed of the latest CVEs and Vulnerabilities from cvefeed.io. HIGH or CRITICAL
- CVE-2026-5430 - Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
- CVE-2026-1728 - Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover
- CVE-2025-15039 - Account Takeover via Conditional Authentication Script Logic in Multiple WSO2 Products
- CVE-2026-15459 - WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint
- CVE-2026-15991 - File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter
- CVE-2026-67531 - FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool
- CVE-2026-19024 - HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message
- CVE-2026-71319 - Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution
- CVE-2026-71315 - Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
- CVE-2026-71309 - rclone: Incomplete path validation allows backend root escape in serve restic
- CVE-2026-17583 - Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check
- CVE-2026-70615 - boringproxy 0.10.0 SSH authorized_keys Injection via Tunnel Creation
- CVE-2026-66298 - JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
- CVE-2026-18953 - Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server
- CVE-2026-17556 - Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header
- CVE-2026-9196 - Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
- CVE-2026-8478 - Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
- CVE-2026-8182 - Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
- CVE-2026-48168 - PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name