Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-67607 — LightFTP 2.3.1 Race Condition DoS via worker_thread_cleanup

LightFTP 2.3.1 contains a race condition vulnerability that allows remote attackers to crash the server by racing a fresh connection that reuses the FTP context against an in-progress ABRT cleanup. A…

lightftp | Remote | Race Condition
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-59232 — Stored Cross-site Scripting in Prospero Flow CRM lead name field

Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the app…

prospero_flow_crm | Remote | Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-59231 — Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs

Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen …

Remote | Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.7 LOW
CVE-2026-56571 — HCL iControl is affected by multiple security vulnerabilities.

HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of o…

Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.7 LOW
CVE-2026-56570 — HCL iControl is affected by multiple security vulnerabilities.

HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the syste…

Remote | Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.0 MEDIUM
CVE-2026-56569 — HCL iControl is affected by multiple security vulnerabilities.

HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

| Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.7 LOW
CVE-2026-56568 — HCL iControl is affected by multiple security vulnerabilities.

HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of ge…

Remote | Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.1 MEDIUM
CVE-2026-56567 — HCL iControl is affected by multiple security vulnerabilities.

HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

| Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.5 MEDIUM
CVE-2026-52857 — Wings: Maliciously or erroneously created parsed config files can cause wings process to …

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process…

wings | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.2 HIGH
CVE-2026-18141 — Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http h…

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authenti…

ansible_automation_platform | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.9 CRITICAL
CVE-2026-17566 — pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplet…

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To sto…

Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.4 CRITICAL
CVE-2026-17351 — pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagr…

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control stateme…

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.4 MEDIUM
CVE-2026-17350 — pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers

The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool b…

Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.6 CRITICAL
CVE-2026-17349 — pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and owners…

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every c…

Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.9 MEDIUM
CVE-2026-17348 — pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Sch…

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserve…

| Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.7 HIGH
CVE-2026-17347 — pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substituti…

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by…

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.8 HIGH
CVE-2026-17346 — pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/s…

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_…

Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-16504 — VPS.org one-click Zulip template deployment instance contains multiple vulnerabilities

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

| Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-16503 — VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Dock…

| Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.8 MEDIUM
CVE-2026-10686 — Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS)…

Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branches of ipv6_route_packet() (subsys/net/ip) were affected: the explicit-rou…

zephyr zephyr | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
Showing 20 of 9517 Results