Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-59309 — vCenter authentication-bypass vulnerability

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and ga…

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.8 HIGH
CVE-2026-54368 — CentreStack < 17.4 SQL Injection via x-glad-filter Header

CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a cra…

centrestack | Remote | Injection
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.8 HIGH
CVE-2026-54367 — CentreStack < 17.2 Unauthenticated API Authorization Bypass

CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints …

centrestack | Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.7 HIGH
CVE-2026-54366 — CentreStack < 17.4 XXE via SharePoint Storage Configuration

CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoin…

centrestack | Remote | XML External Entity
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.7 HIGH
CVE-2026-54365 — CentreStack < 17.3 Unauthenticated User Creation via Deserialization in GSNamespace.dll

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a cr…

centrestack | Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.9 MEDIUM
CVE-2026-54364 — CentreStack < 17.4 Session Injection via SelectProvider.aspx

CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a …

centrestack | Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
9.3 CRITICAL
CVE-2026-54363 — CentreStack < 17.5 Hardcoded Key Token Forgery RCE

CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as e…

centrestack | Remote | Cryptography
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
9.3 CRITICAL
CVE-2026-47876 — VMXNET3 out-of-bounds write vulnerability

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual netwo…

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.6 HIGH
CVE-2026-41703 — Out-of-bounds read vulnerability

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to informatio…

esx workstation fusion esx cloud_foundation cloud_foundation +1 more | Remote | Memory Corruption
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.4 MEDIUM
CVE-2026-7260 — Stack overflow in phar with circular symlinks

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, fr…

| Denial of Service
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
4.3 MEDIUM
CVE-2026-5582 — FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Toggle

The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() funct…

Remote | Cross-Site Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.8 MEDIUM
CVE-2026-18382 — Project-koku/koku-metrics-operator: koku-metrics-operator: service-account client credent…

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authenticati…

Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.6 HIGH
CVE-2026-18381 — Project-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token…

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. T…

Remote | Server-Side Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.6 HIGH
CVE-2026-18378 — Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secret token exfi…

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is s…

Remote | Server-Side Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.1 HIGH
CVE-2026-17544 — Out-of-bounds write in bccomp() via crafted operand and scale

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

Remote | Memory Corruption
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.1 HIGH
CVE-2026-17543 — SQL injection in ext-pgsql via E'...' backslash breakout

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, an…

Remote | Injection
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.2 HIGH
CVE-2026-15397 — Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticated (Shop Man…

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user…

Remote | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.8 HIGH
CVE-2026-22622 — Eaton Tripp Lite PADM Improper Input Validation Privilege Escalation

Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted acces…

Remote | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.3 HIGH
CVE-2026-22621 — Eaton Tripp Lite Series PADM OS Command Injection

Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restr…

Remote | Injection
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.6 HIGH
CVE-2026-22620 — Eaton Tripp Lite PADM Authentication Bypass Vulnerability

Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user…

Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
Showing 20 of 10051 Results