Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-15410 — SonicWall SMA1000 Appliances Code Injection Vulnerability - [Actively Exploited]

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could po…

Jul 14, 2026 Jul 16, 2026
Jul 14, 2026
Jul 16, 2026
10.0 CRITICAL
CVE-2026-15409 — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability - [Actively Exploi…

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make r…

sma1000 sma8200v sma6210_firmware sma6210 sma7210_firmware sma7210 | CISA KEV Remote | Server-Side Request Forgery
Jul 14, 2026 Jul 16, 2026
Jul 14, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-58644 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability - [Actively Exploite…

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Jul 14, 2026 Jul 17, 2026
Jul 14, 2026
Jul 17, 2026
9.8 CRITICAL
CVE-2026-56164 — Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability - …

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.8 HIGH
CVE-2026-56155 — Microsoft Active Directory Federation Services Insufficient Granularity of Access Control…

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
10.0 CRITICAL
CVE-2026-56291 — Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability - [Actively E…

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

forms | CISA KEV Remote | Misconfiguration
Jul 09, 2026 Jul 11, 2026
Jul 09, 2026
Jul 11, 2026
10.0 CRITICAL
CVE-2026-48282 — Adobe ColdFusion Path Traversal Vulnerability - [Actively Exploited]

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execu…

coldfusion | CISA KEV Remote | Path Traversal
Jun 30, 2026 Jul 08, 2026
Jun 30, 2026
Jul 08, 2026
10.0 CRITICAL
CVE-2026-56290 — Joomlack Page Builder Improper Access Control Vulnerability - [Actively Exploited]

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

page_builder_ck | CISA KEV Remote | Authentication
Jun 29, 2026 Jul 08, 2026
Jun 29, 2026
Jul 08, 2026
9.9 CRITICAL
CVE-2026-55255 — Langflow Authorization Bypass Through User-Controlled Key Vulnerability - [Actively Explo…

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authent…

langflow | CISA KEV Remote | Authorization
Jun 23, 2026 Jul 08, 2026
Jun 23, 2026
Jul 08, 2026
10.0 CRITICAL
CVE-2026-48939 — iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability - [Actively Exploi…

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

icagenda | CISA KEV Remote | Misconfiguration
Jun 20, 2026 Jul 11, 2026
Jun 20, 2026
Jul 11, 2026
10.0 CRITICAL
CVE-2026-48908 — JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability …

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

sp_page_builder | CISA KEV Remote | Misconfiguration
Jun 20, 2026 Jul 08, 2026
Jun 20, 2026
Jul 08, 2026
Showing 20 of 11 Results