Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-58586 — Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp

Image::WebP versions through 0.2 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-…

| Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.9 MEDIUM
CVE-2026-66007 — Datasets Path Traversal via Unsanitized file_name Metadata

Datasets through 5.0.0, fixed in f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to …

Remote | Path Traversal
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.9 MEDIUM
CVE-2026-66006 — lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs

lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata …

Remote | Authentication
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.3 MEDIUM
CVE-2026-66005 — Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploi…

Remote | Misconfiguration
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-49326 — Apache HBase: Missing scanner instance owner check in thrift delegation service

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open ste…

hbase | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-16802 — Devolutions PowerShell Universal Cleartext Storage of Sensitive Information

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via sec…

powershell_universal | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-16801 — Devolutions PowerShell Universal Code Injection Vulnerability

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission…

powershell_universal | Injection
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-16800 — Devolutions PowerShell Universal Code Injection Vulnerability

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permissi…

powershell_universal | Injection
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-16799 — Devolutions PowerShell Universal Improper Access Control Vulnerability

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute autom…

powershell_universal | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-16798 — Devolutions PowerShell Universal Sensitive Information Disclosure

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permi…

powershell_universal | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.0 MEDIUM
CVE-2026-66004 — BlenderMCP Path Traversal via download_polyhaven_asset API

BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in API …

blender-mcp | Remote | Path Traversal
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
10.0 CRITICAL
CVE-2026-56163 — Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

None

Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
10.0 CRITICAL
CVE-2026-58630 — Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability

None

Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
10.0 CRITICAL
CVE-2026-57106 — Data Quality Elevation of Privilege Vulnerability

None

Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-8789 — Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Arbi…

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` …

| Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
5.5 MEDIUM
CVE-2026-17048 — Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via ad…

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in…

single_sign-on data_grid build_of_keycloak | Remote | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.1 MEDIUM
CVE-2026-8308 — Reflected XSS Polen Media's Website Template

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue …

Remote | Cross-Site Scripting
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.5 MEDIUM
CVE-2026-17059 — Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypa…

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system …

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.7 HIGH
CVE-2026-55732 — Loytec LINX firmware: Out-of-bounds Read in BACnet packet parsing (bacdt_datetime_to_tod)

Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthe…

Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.6 MEDIUM
CVE-2026-55731 — Loytec LINX firmware: Unchecked input for loop condition in the SNMP agent

Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote a…

Remote | Denial of Service
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
Showing 20 of 9713 Results