Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-0284 — PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML cont…

Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
7.2 HIGH
CVE-2026-0283 — PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)

An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass security restrictions and estab…

Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
6.5 MEDIUM
CVE-2026-0282 — PAN-OS: File Deletion Vulnerability in Management Web Interface

A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory…

Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
7.1 HIGH
CVE-2026-0281 — PAN-OS: Information Disclosure Vulnerability in Management Web Interface

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. Th…

Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
7.2 HIGH
CVE-2026-0280 — PAN-OS: IPv6 Firewall Policy Bypass

An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing network tr…

Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
6.1 MEDIUM
CVE-2026-0279 — PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities

Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-O…

Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
7.5 HIGH
CVE-2025-63579 — Kyocera Command Center RX Information Disclosure Vulnerability

Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerabilit…

Remote
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
6.9 MEDIUM
CVE-2026-61344 — Superior Court of California Hearing Reminder Service unauthenticated information disclos…

The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that returns court reminder records containing potentially sensitive information wit…

Remote | Authentication
Jul 09, 2026 Jul 21, 2026
Jul 09, 2026
Jul 21, 2026
8.6 HIGH
CVE-2026-61343 — LibreBooking path traversal

LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbi…

Remote | Path Traversal
Jul 09, 2026 Jul 09, 2026
Jul 09, 2026
Jul 09, 2026
9.9 CRITICAL
CVE-2026-59827 — Metabase: Unsafe Deserialization of H2 Query Results

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the defau…

metabase | Remote | Injection
Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
9.1 CRITICAL
CVE-2026-59826 — Metabase: Arbitrary Code Execution via Database Connection Detail Bypass

Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on …

metabase | Remote | Injection
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
5.3 MEDIUM
CVE-2026-59817 — Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain ful…

ghost | Remote | Authentication
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
8.8 HIGH
CVE-2026-59734 — Coolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_comma…

coolify coolify | Remote | Injection
Jul 09, 2026 Jul 09, 2026
Jul 09, 2026
Jul 09, 2026
10.0 CRITICAL
CVE-2026-59726 — Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentica…

Remote | Authentication
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
7.2 HIGH
CVE-2026-59721 — Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and…

hoppscotch | Remote | Injection
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
7.5 HIGH
CVE-2026-59720 — Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection D…

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPubl…

hoppscotch | Remote | Authorization
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
7.7 HIGH
CVE-2026-59221 — open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitize_proxy_path in backend/open_webui/routers/terminals.py decoded proxy paths onl…

open_webui | Remote | Path Traversal
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
8.8 HIGH
CVE-2026-58378 — Allwinner TV Box TV98 ADB exposed on network

Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access.

Remote | Authentication
Jul 09, 2026 Jul 21, 2026
Jul 09, 2026
Jul 21, 2026
8.1 HIGH
CVE-2026-55420 — Discourse: Remote code execution via pdf uploads

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be exploited to obtain …

discourse | Remote | Misconfiguration
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
4.9 MEDIUM
CVE-2026-43752 — FileMaker Server Arbitrary Code Execution via File Upload

An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vu…

filemaker_server | Remote | Authentication
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
Showing 20 of 9554 Results