Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-63136 — Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search re…

elasticsearch | Remote | Denial of Service
Jul 21, 2026 Aug 07, 2026
Jul 21, 2026
Aug 07, 2026
5.3 MEDIUM
CVE-2026-63092 — kirby-modules License Key Disclosure via modules/activate Dialog

kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license…

Remote | Information Disclosure
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-63080 — Aptabase SQL Injection via ClickHouse query backend

Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authenticated attackers to read event data across all tenants by injecting unsanitiz…

Remote | Injection
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-56147 — Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Inform…

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An incon…

kibana | Remote | Authorization
Jul 21, 2026 Aug 06, 2026
Jul 21, 2026
Aug 06, 2026
7.5 HIGH
CVE-2026-52476 — Aiflowy SQL Injection Vulnerability

SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPageData method in the DatacenterQuery.java file

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.1 MEDIUM
CVE-2026-52475 — Aiflowy Cross-Site Scripting Vulnerability

Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the UploadController.java file

Remote | Cross-Site Scripting
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-52474 — Aiflowy Information Disclosure Vulnerability

An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.

Remote | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-52472 — Wgcloud SQL Injection Vulnerability

SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-52470 — Crocus SQL Injection Vulnerability

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-52469 — Crocus SQL Injection Privilege Escalation

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.1 MEDIUM
CVE-2026-47714 — libheif has integer overflow in inline mask size calculation that causes undersized buffe…

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `width` and `height` a…

libheif | Memory Corruption
Jul 21, 2026 Jul 30, 2026
Jul 21, 2026
Jul 30, 2026
9.3 CRITICAL
CVE-2026-47708 — MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper

MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata c…

Remote | Injection
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-47697 — Shelf has cross-organization IDOR: authenticated users could read/attach another workspac…

Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). Prior to version 1.20.2, several endpoints accepted entity IDs from request inp…

Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-47695 — CC-Tweaked has an SSRF Protection Bypass with NAT64

CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.119.0, CC-Tweaked's HTTP API (`http.request`, `http.websocket`) blocks requests…

cc-tweaked | Remote | Server-Side Request Forgery
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-47690 — MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workfl…

MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration…

Remote | Supply Chain
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
5.2 MEDIUM
CVE-2026-47689 — FOGProject has stored XSS via unescaped inventory data in buildRow() rendered on Group In…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data …

fogproject | Cross-Site Scripting
Jul 21, 2026 Aug 07, 2026
Jul 21, 2026
Aug 07, 2026
8.2 HIGH
CVE-2026-47688 — FOGProject has unauthenticated clearAES and clearPMTasks that allow remote destruction of…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be in…

fogproject | Remote | Authentication
Jul 21, 2026 Aug 07, 2026
Jul 21, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-47687 — FOGProject has stored XSS via unescaped option label in selectForm() accessible from unau…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<optio…

fogproject | Remote | Cross-Site Scripting
Jul 21, 2026 Aug 07, 2026
Jul 21, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-47685 — FOGProject has stored XSS via unauthenticated inventory service renders unescaped in Host…

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/invent…

fogproject | Remote | Cross-Site Scripting
Jul 21, 2026 Aug 07, 2026
Jul 21, 2026
Aug 07, 2026
8.0 HIGH
CVE-2026-47237 — Kubeflow Community Distribution: Overly Permissive Istio Permissions Allows Kubeflow Auth…

Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other pa…

Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
Showing 20 of 12347 Results