Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-6952 — Zyxel AX7501-B1 Command Injection Vulnerability

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attac…

ax7501-b1_firmware | Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.8 MEDIUM
CVE-2026-63729 — TeX Live SyncTeX Parser Heap Use-After-Free via Malformed SyncTeX File

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash appli…

| Memory Corruption
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.5 MEDIUM
CVE-2026-16334 — itsourcecode Hospital Management System prescriptionorder.php sql injection

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid lea…

hospital_management_system | Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-16332 — D-Link DNS-320 multi_uploadify.php unrestricted upload

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrest…

Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.0 HIGH
CVE-2026-59776 — FeliCa IC Chips Missing Cryptographic Step Vulnerability

Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tam…

| Cryptography
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-16336 — trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect

A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing…

| Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-16331 — D-Link DNS-320 save_ajax.php unrestricted upload

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads…

dns-320_firmware | Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-16330 — D-Link DNS-320 uploadify.php unrestricted upload

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n92…

dns-320_firmware | Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-16329 — D-Link DNS-320 uploadify.php unrestricted upload

A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrest…

dns-320_firmware | Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.1 HIGH
CVE-2026-63728 — Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template…

Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitiv…

| Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-55833 — Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed heade…

netty | Remote | Denial of Service
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-55831 — Netty SPDY SETTINGS frame count materializes unbounded settings map

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry…

netty | Remote | Denial of Service
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-16327 — D-Link DNS-320 upload.php unrestricted upload

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unre…

dns-320_firmware | Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-15905 — Google Chrome Aura Use-After-Free Vulnerability

Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

chrome chrome edge_chromium | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-15904 — Google Chrome Ozone Use-After-Free

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a…

chrome chrome edge_chromium | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-15903 — Google Chrome V8 Out-of-Bounds Memory Access Vulnerability

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: …

chrome chrome edge_chromium | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-15902 — Google Chrome Cast Use-After-Free Vulnerability

Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome edge_chromium | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-15901 — Google Chrome Network Use-After-Free Vulnerability

Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

chrome chrome edge_chromium | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-15900 — Google Chrome GPU Use-After-Free Sandbox Escape

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Criti…

chrome chrome edge_chromium | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
0.0 NA
CVE-2026-15899 — Google Chrome CameraCapture Use-After-Free

Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity:…

chrome chrome edge_chromium | Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
Showing 20 of 8276 Results