Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-52474 — Aiflowy Information Disclosure Vulnerability

An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.

Remote | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-52472 — Wgcloud SQL Injection Vulnerability

SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-52470 — Crocus SQL Injection Vulnerability

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-52469 — Crocus SQL Injection Privilege Escalation

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.1 MEDIUM
CVE-2026-47714 — libheif has integer overflow in inline mask size calculation that causes undersized buffe…

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `width` and `height` a…

libheif | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.3 CRITICAL
CVE-2026-47708 — MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper

MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata c…

Remote | Injection
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-47697 — Shelf has cross-organization IDOR: authenticated users could read/attach another workspac…

Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). Prior to version 1.20.2, several endpoints accepted entity IDs from request inp…

Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-47695 — CC-Tweaked has an SSRF Protection Bypass with NAT64

CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.119.0, CC-Tweaked's HTTP API (`http.request`, `http.websocket`) blocks requests…

cc-tweaked | Remote | Server-Side Request Forgery
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-47690 — MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workfl…

MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration…

Remote | Supply Chain
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
4.6 MEDIUM
CVE-2026-47689 — FOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group In…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data …

fogproject | Cross-Site Scripting
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
8.2 HIGH
CVE-2026-47688 — FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be in…

fogproject | Remote | Authentication
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.3 HIGH
CVE-2026-47687 — FOGProject has stored XSS via unescaped option label in selectForm() accessible from unau…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<optio…

fogproject | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.3 HIGH
CVE-2026-47685 — FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/invent…

fogproject | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
8.0 HIGH
CVE-2026-47237 — Kubeflow Community Distribution: Overly Permissive Istio Permissions Allows Kubeflow Auth…

Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other pa…

Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
5.1 MEDIUM
CVE-2026-47143 — Capstone has a NULL Pointer Dereference with 3DNow! opcodes

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds…

capstone | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-46556 — FlaskBB: SSRF in get_image_info() via unrestricted avatar URL

FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated …

Remote | Server-Side Request Forgery
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.9 MEDIUM
CVE-2026-45383 — libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-boun…

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` in `…

libde265 | Remote | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.9 MEDIUM
CVE-2026-45382 — libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS t…

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` a…

libde265 | Remote | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.2 HIGH
CVE-2026-44879 — Authenticated Command Injection allows arbitrary command execution in CLI Interface

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitat…

Remote | Injection
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.2 HIGH
CVE-2026-44878 — Authenticated Path Traversal allows Unauthorized Access in Web Interface

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of th…

Remote | Path Traversal
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
Showing 20 of 9583 Results