Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
1.8 LOW
CVE-2026-40000 — Path Traversal Vulnerability in ZTE Blade A75 Pro 5G

The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitr…

| Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.7 HIGH
CVE-2026-17527 — Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterro…

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source…

openshift_virtualization | Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.5 MEDIUM
CVE-2026-17534 — Kimi Code FetchURL SSRF protection bypass via DNS-resolving hostnames and redirects

Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts…

| Server-Side Request Forgery
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.9 MEDIUM
CVE-2026-65765 — Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.1

Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities.

Remote | Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.1 MEDIUM
CVE-2026-65764 — Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.1.1

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.1 MEDIUM
CVE-2026-16554 — Integer Overflow Leading to Heap Buffer Overflow in cJSON

cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing s…

cjson | Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.8 HIGH
CVE-2026-17523 — Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges

A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows t…

enterprise_linux enterprise_linux | Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.7 HIGH
CVE-2026-65894 — Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HT…

Remote | Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.0 HIGH
CVE-2026-65893 — Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary…

| Misconfiguration
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-64536 — staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop The loop in is_ap_in_tkip() iterates over IEs without verifying that…

| Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-64535 — nvmet-tcp: Fix potential UAF when ddgst mismatch

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an …

| Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-64534 — nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest misma…

| Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-64533 — fs/ntfs3: validate lcns_follow in log_replay conversion

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow in log_replay conversion log_replay() converts DIR_PAGE_ENTRY_32 records into DIR_PAGE_ENTRY recor…

| Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-64532 — fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} In do_action()'s UpdateRecordDataRoot (fslog.c:3489) a…

| Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-64531 — net: openvswitch: reject oversized nested action attrs

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field…

| Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.5 HIGH
CVE-2026-14837 — SSH Enablement Signature Verification Bypass

Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable fil…

c520 c550 | Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-9830 — BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering …

The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authe…

| Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-66412 — Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone J…

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer mi…

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-14827 — Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter

The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contrib…

| Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-14820 — Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle vi…

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and returns distinc…

| Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Showing 20 of 8930 Results