Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-56144 — Incorrect Authorization in Elasticsearch Leading to Information Disclosure

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By ta…

elasticsearch | Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-50759 — Exo-explore Privilege Escalation Vulnerability

An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication.

Remote | Authentication
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-50758 — DayuanJiang next-ai-draw-io Cross-Site Scripting Vulnerability

Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter

Remote | Cross-Site Scripting
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.8 HIGH
CVE-2026-50757 — DayuanJiang next-ai-draw-io Directory Traversal Vulnerability

Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server

| Path Traversal
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-50756 — DayuanJiang next-ai-draw-io Information Disclosure Vulnerability

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

Remote | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-50755 — DayuanJiang next-ai-draw-io Sensitive Information Disclosure

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

Remote | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
4.3 MEDIUM
CVE-2026-49092 — Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized In…

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under ce…

kibana | Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.4 MEDIUM
CVE-2026-47671 — Nhost CLI local configserver allows cross-origin unauthenticated read/write access to loc…

Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy autho…

cli | Remote | Misconfiguration
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-47667 — CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyze()` via Cra…

CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from the first 4 bytes of an Analyze/NIfTI file and…

cimg | Remote | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-46600 — Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

Remote | Denial of Service
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.3 MEDIUM
CVE-2026-46403 — Klever-Go KVM read-only execution can commit contract delete and upgrade side effects

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the previous …

Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-42397 — Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servi…

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted req…

kibana | Remote | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-30632 — Knowns Directory Traversal Vulnerability

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.

Remote | Path Traversal
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.7 HIGH
CVE-2026-15957 — Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows un…

Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. …

aws-sdk-rust | Remote | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.6 CRITICAL
CVE-2026-64877 — Ticketing REST API SQL Injection Vulnerability

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

security_center | Remote | Injection
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
7.2 HIGH
CVE-2026-63454 — Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command l…

Remote | Path Traversal
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
7.2 HIGH
CVE-2026-63453 — Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as …

Remote | Memory Corruption
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-59142 — Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an un…

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the h…

Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.1 CRITICAL
CVE-2026-59141 — Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unv…

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the …

Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.1 CRITICAL
CVE-2026-59140 — Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unv…

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header bound…

Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
Showing 20 of 9598 Results