Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.6 MEDIUM
CVE-2026-47689 — FOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group In…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data …

fogproject | Cross-Site Scripting
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
8.2 HIGH
CVE-2026-47688 — FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be in…

fogproject | Remote | Authentication
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.3 HIGH
CVE-2026-47687 — FOGProject has stored XSS via unescaped option label in selectForm() accessible from unau…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<optio…

fogproject | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.3 HIGH
CVE-2026-47685 — FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/invent…

fogproject | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
8.0 HIGH
CVE-2026-47237 — Kubeflow Community Distribution: Overly Permissive Istio Permissions Allows Kubeflow Auth…

Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other pa…

Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
5.1 MEDIUM
CVE-2026-47143 — Capstone has a NULL Pointer Dereference with 3DNow! opcodes

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds…

capstone | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-46556 — FlaskBB: SSRF in get_image_info() via unrestricted avatar URL

FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated …

Remote | Server-Side Request Forgery
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.9 MEDIUM
CVE-2026-45383 — libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-boun…

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` in `…

libde265 | Remote | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.9 MEDIUM
CVE-2026-45382 — libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS t…

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` a…

libde265 | Remote | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.2 HIGH
CVE-2026-44879 — Authenticated Command Injection allows arbitrary command execution in CLI Interface

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitat…

Remote | Injection
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.2 HIGH
CVE-2026-44878 — Authenticated Path Traversal allows Unauthorized Access in Web Interface

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of th…

Remote | Path Traversal
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-30633 — Knowns Directory Traversal Vulnerability

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.

Remote | Path Traversal
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-30631 — Bytebot-AI Arbitrary Code Execution Vulnerability

An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.

Remote | Path Traversal
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.9 MEDIUM
CVE-2026-16318 — QUIC Transport Parameters Memory Leak During HelloRetryRequest in s2n-tls

The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRe…

s2n-tls s2n-tls | Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.3 HIGH
CVE-2026-16317 — Silent Drop of TLS 1.3 Encrypted Records in s2n-tls

Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either end…

s2n-tls | Remote | Misconfiguration
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
4.4 MEDIUM
CVE-2026-12139 — Tanium addressed an information disclosure vulnerability in Connect.

Tanium addressed an information disclosure vulnerability in Connect.

connect | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
2.7 LOW
CVE-2026-11925 — Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerab…

Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.

server | Remote | Misconfiguration
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
4.0 MEDIUM
CVE-2026-65069 — Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap back…

Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h with open(path, O_RDWR|O_C…

| Misconfiguration
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
3.8 LOW
CVE-2026-65068 — Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap back…

Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h with open(path, O_RDWR|…

| Misconfiguration
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
3.8 LOW
CVE-2026-65067 — Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing f…

Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h with open(path, O_RDWR|O_CRE…

| Race Condition
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
Showing 20 of 9602 Results