Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 CRITICAL
CVE-2026-35198 — HeyForm vulnerable to stored XSS via form field titles

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious Java…

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.1 MEDIUM
CVE-2026-32822 — dataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public Pages

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.5 HIGH
CVE-2026-32807 — dataCycle Public DataLink Text File Download Ignores Validity And Authorization

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Authentication
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.4 HIGH
CVE-2026-28220 — Wazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a …

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or a…

wazuh | Authentication
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.7 HIGH
CVE-2026-27823 — Remote Code Execution Vulnerability in EGroupware

A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-re…

egroupware | Remote | Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.9 MEDIUM
CVE-2026-26199 — Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow wh…

hdf5 | Remote | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.9 MEDIUM
CVE-2026-26197 — Array full size, element count, and element size are not checked to make sure they match …

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is corrupted such that an array datatype's size, the number of elements, and the elem…

hdf5 | Remote | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
4.8 MEDIUM
CVE-2026-26081 — HAProxy Improper Length Validation Vulnerability

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

haproxy | Remote | Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
3.7 LOW
CVE-2026-26080 — HAProxy Varint Handling Denial of Service Vulnerability

HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.

haproxy | Remote | Denial of Service
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.8 HIGH
CVE-2026-25039 — The application evaluate UNC path in workspace name

Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that workspace name is a UN…

parsec | Remote | Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.8 HIGH
CVE-2026-21824 — A privilege escalation vulnerability affects HCL Commerce

HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

Remote | Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
4.3 MEDIUM
CVE-2026-13724 — Business Logic Bypass in Gobito's Corporate Training Management System

Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipul…

Remote | Injection
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.1 HIGH
CVE-2026-63091 — ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR b…

proftpd | Remote | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.8 HIGH
CVE-2026-63090 — ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by…

proftpd | Remote | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-63071 — Apache Syncope: RCE via Groovy Sandbox bypass

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted c…

syncope | Misconfiguration
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-62418 — Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check

Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16…

syncope | Server-Side Request Forgery
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-62183 — Apache Syncope: User self-service privilege escalation

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN defini…

syncope | Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.9 MEDIUM
CVE-2026-59238 — Stored XSS in Pentestify via unsanitized finding images and report client logo

Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditData in js/app.js) in maalfer Pentestify before 1.1.0 allows a remote, auth…

pentestify | Remote | Cross-Site Scripting
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-57308 — Apache Syncope: SQL injection vulnerability in Audit Events search

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary S…

syncope | Injection
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.7 HIGH
CVE-2026-54910 — FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated u…

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query paramet…

Remote | Path Traversal
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
Showing 20 of 8278 Results