Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-59205 — Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mod…

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image wh…

pillow | Remote | Memory Corruption
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-59204 — Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial …

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile…

pillow | Remote | Denial of Service
Jul 14, 2026 Jul 21, 2026
Jul 14, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-59203 — Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of se…

Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file …

pillow | Remote | Denial of Service
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-59199 — Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate o…

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in …

pillow | Remote | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-59198 — Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated im…

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process h…

pillow | Remote | Memory Corruption
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
9.1 CRITICAL
CVE-2026-55954 — Missing ID token claim validation in ueberauth_apple allows account takeover

Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.Strategy.Apple.Token.payload/2 function verifies t…

ueberauth_apple | Remote | Authentication
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.1 HIGH
CVE-2026-55651 — Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure

Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointmen…

easy\!appointments | Remote | Information Disclosure
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
3.1 LOW
CVE-2026-52841 — Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend…

Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session,…

easy\!appointments | Remote | Authorization
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
2.7 LOW
CVE-2026-52840 — Easy!Appointments has server-side request forgery in CalDAV connection test that exposes …

Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzz…

easy\!appointments | Remote | Server-Side Request Forgery
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
3.3 LOW
CVE-2026-52839 — Easy!Appointments appointments/store and appointments/update allow cross-provider appoint…

Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation …

easy\!appointments | Remote | Authorization
Jul 14, 2026 Jul 29, 2026
Jul 14, 2026
Jul 29, 2026
2.6 LOW
CVE-2026-52838 — Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — S…

Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is s…

easy\!appointments | Remote | Cross-Site Scripting
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
6.1 MEDIUM
CVE-2026-23573 — Fortinet FortiOS, FortiPAM, and FortiProxy Cross-Site Scripting Vulnerability

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS…

fortios fortiproxy fortios fortipam | Remote | Cross-Site Scripting
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-15699 — spencermountain compromise Public Root API extend.js nlp.extend prototype pollution

A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the…

compromise | Remote | Misconfiguration
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
6.5 MEDIUM
CVE-2026-15698 — kofrasa mingo Update API updateMany prototype pollution

A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of the component Update API. Executing a manipulation of the argument Set can lead t…

mingo | Remote | Misconfiguration
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
6.5 MEDIUM
CVE-2026-15697 — svgdotjs svg.js npm Package API EventTarget.on prototype pollution

A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. Performing a manipulation results in i…

svg.js | Remote | Misconfiguration
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.7 HIGH
CVE-2026-15392 — DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to…

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking w…

dbi | Path Traversal
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
8.2 HIGH
CVE-2026-14504 — Nexus Repository 3 - Authorization Bypass in Component Upload API

An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, b…

nexus_repository_manager | Remote | Authorization
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-12707 — Unbounded path event queue growth in quiche via peer-driven source connection ID rotation

Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connect…

quiche | Remote | Denial of Service
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-12659 — Rockwell Automation Flex 5000® Adapter - Denial of Service

A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. …

Remote | Denial of Service
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.5 HIGH
CVE-2026-12523 — Resource exhaustion in quiche HTTP/3 and QPACK layers

Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple fr…

quiche | Remote | Denial of Service
Jul 14, 2026 Aug 06, 2026
Jul 14, 2026
Aug 06, 2026
Showing 20 of 10891 Results