Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2025-59181 — Path traversal Vulnerability

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, deny…

packet_core_controller | Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.1 MEDIUM
CVE-2025-59180 — Use of Hard-coded Credentials Vulnerability

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded c…

packet_core_controller | Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.7 HIGH
CVE-2026-66050 — NitroShare Desktop 0.3.4 Path Traversal via LAN File Transfer Server

NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending …

Remote | Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-65879 — Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-w…

Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of…

| Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.3 HIGH
CVE-2026-65878 — Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builde…

Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.2 HIGH
CVE-2026-65877 — Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7…

Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL inj…

Remote | Injection
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
9.2 CRITICAL
CVE-2026-65876 — Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6…

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vect…

Remote | Injection
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
9.2 CRITICAL
CVE-2026-65766 — Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6…

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vecto…

Remote | Injection
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
9.8 CRITICAL
CVE-2026-61511 — vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remot…

Remote | Injection
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.3 MEDIUM
CVE-2026-17514 — ZJONSSON node-unzipper extract.js Extract path traversal

A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The …

| Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
3.3 LOW
CVE-2026-17513 — ggml-org whisper.cpp ggml.c ggml_ftype_to_ggml_type assertion

A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in reachable a…

whisper.cpp | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.6 MEDIUM
CVE-2026-15003 — Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure an…

A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended …

Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.8 MEDIUM
CVE-2025-59178 — Exposure of Sensitive System Information to an Unauthorized Control Sphere Vulnerability

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other user…

packet_core_controller | Information Disclosure
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-10819 — Mattermost Server Denial of Service via Animated GIF Emoji Upload

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an…

Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.3 MEDIUM
CVE-2026-10600 — Denial of service via unbounded document content extraction in Mattermost Server

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows a…

Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.8 MEDIUM
CVE-2025-59177 — Generation of Error Message Containing Sensitive Information Vulnerability

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret…

packet_core_controller | Information Disclosure
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.5 HIGH
CVE-2025-59172 — Improper Neutralization of Special Elements used in an OS Command Vulnerability

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.

Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.3 MEDIUM
CVE-2026-66477 — WordPress Gillion theme <= 4.13 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Gillion <= 4.13 versions.

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.9 MEDIUM
CVE-2026-66476 — WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vulnerability

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

Remote | Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.9 MEDIUM
CVE-2026-66475 — WordPress Checkout Field Editor for WooCommerce &#8211; Checkout Manager plugin <= 3.0.5 …

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Showing 20 of 9027 Results