Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-59139 — Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unv…

Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header chec…

Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.8 HIGH
CVE-2026-55084 — SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 app…

dhis_2 | Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.7 HIGH
CVE-2026-55082 — DHIS2 SQL injection in SQL View filter values

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL View data endpoints allowed authenticated users with SQL View access to provide…

dhis_2 | Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.3 HIGH
CVE-2026-55081 — DHIS2 Reflected XSS in OpenAPI HTML scope parameter

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into th…

dhis_2 | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.9 MEDIUM
CVE-2026-16441 — Eclipse OpenJ9 : Method resolution default method precedence failure

In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface def…

openj9 | Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
4.2 MEDIUM
CVE-2026-12548 — Libsoup: heap out-of-bounds read in libsoup due to integer truncation

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be in…

enterprise_linux enterprise_linux | Remote | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
3.4 LOW
CVE-2026-12547 — Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on p…

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy…

enterprise_linux enterprise_linux | Remote | Information Disclosure
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2016-20096 — Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name para…

Remote | Injection
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
3.1 LOW
CVE-2026-56583 — HCL MyCloud was affected with Concurrent Login Vulnerability.

HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.

mycloud | Remote | Authentication
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
3.1 LOW
CVE-2026-56582 — HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.

HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.

mycloud | Remote | Cryptography
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
2.6 LOW
CVE-2026-56581 — HCL MyCloud was affected with Cookie Attribute Path Not Set

HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.

mycloud | Remote | Misconfiguration
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
2.2 LOW
CVE-2026-56580 — HCL MyCloud was affected by Using Components with Known Vulnerability

HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.

mycloud | Remote | Supply Chain
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
3.1 LOW
CVE-2026-56579 — HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor.

HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.

mycloud | Remote | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
2.2 LOW
CVE-2026-56578 — HCL MyCloud was affected by Server Version Disclosure

HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.

mycloud | Remote | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
3.1 LOW
CVE-2026-56577 — HCL MyCloud affected by Weak Password Policy

HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.

mycloud | Remote | Authentication
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-47657 — HumHub Missing Authorization on Remove All Space Members Action

HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigge…

humhub | Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.9 MEDIUM
CVE-2026-47425 — Rattler vulnerable to entry-point path traversal in noarch:python install (arbitrary file…

Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the `comman…

| Path Traversal
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
8.3 HIGH
CVE-2026-47419 — praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD endpoints (`GET / PATCH / DELETE…

Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-47418 — praisonai-platform: Project endpoints accept any project_id without workspace ownership c…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD endpoints (`GET / PATCH / DELET…

Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-47417 — praisonai-platform: Comment endpoints accept any issue_id without workspace ownership che…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints (`POST /workspaces/{worksp…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
Showing 20 of 9598 Results