CVE ID :CVE-2026-55830 Published : July 8, 2026, 10:17 p.m. | 57 minutes ago Description :RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide…
CVE-2026-55471 – HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
CVE ID :CVE-2026-55471 Published : July 8, 2026, 10:17 p.m. | 57 minutes ago Description :HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to…
CVE-2026-44024 – Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
CVE ID :CVE-2026-44024 Published : July 8, 2026, 10:17 p.m. | 57 minutes ago Description :Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and…
CVE-2026-10037 – Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal
CVE ID :CVE-2026-10037 Published : July 8, 2026, 10:17 p.m. | 58 minutes ago Description :A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by…
CVE-2026-55429 – Coder’s workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
CVE ID :CVE-2026-55429 Published : July 8, 2026, 12:16 a.m. | 58 minutes ago Description :Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2,…
CVE-2026-55428 – Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
CVE ID :CVE-2026-55428 Published : July 8, 2026, 12:16 a.m. | 58 minutes ago Description :Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2,…
CVE-2026-55427 – Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
CVE ID :CVE-2026-55427 Published : July 8, 2026, 12:16 a.m. | 58 minutes ago Description :Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2,…
CVE-2026-59705 – mem0 – OpenMemory API Unauthenticated Access via Memory Endpoints
CVE ID :CVE-2026-59705 Published : July 7, 2026, 11:16 p.m. | 1 hour, 58 minutes ago Description :mem0’s openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete…
CVE-2026-59706 – mem0 – Server-Side Request Forgery and Plaintext API Key Exposure via Unauthenticated Config Endpoints
CVE ID :CVE-2026-59706 Published : July 7, 2026, 10:16 p.m. | 58 minutes ago Description :mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery…
CVE-2026-55418 – FastGPT: S3 presign/read handlers do not bind the object key to the caller’s team (cross-team file disclosure)
CVE ID :CVE-2026-55418 Published : July 7, 2026, 10:16 p.m. | 58 minutes ago Description :FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an…