Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-44880 — Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution…

A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code…

Remote | Memory Corruption
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-47657 — HumHub Missing Authorization on Remove All Space Members Action

HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigge…

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-47425 — Rattler vulnerable to entry-point path traversal in noarch:python install (arbitrary file…

Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the `comman…

| Path Traversal
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
5.7 MEDIUM
CVE-2026-16243 — Eclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compa…

In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.

omr | Remote | Memory Corruption
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.1 LOW
CVE-2026-56583 — HCL MyCloud was affected with Concurrent Login Vulnerability.

HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.

Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.1 LOW
CVE-2026-56582 — HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.

HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.

Remote | Cryptography
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
2.6 LOW
CVE-2026-56581 — HCL MyCloud was affected with Cookie Attribute Path Not Set

HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.

Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
2.2 LOW
CVE-2026-56580 — HCL MyCloud was affected by Using Components with Known Vulnerability

HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.

Remote | Supply Chain
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.1 LOW
CVE-2026-56579 — HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor.

HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.

Remote | Information Disclosure
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
2.2 LOW
CVE-2026-56578 — HCL MyCloud was affected by Server Version Disclosure

HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.

Remote | Information Disclosure
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.1 LOW
CVE-2026-56577 — HCL MyCloud affected by Weak Password Policy

HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.

Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-47419 — praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD endpoints (`GET / PATCH / DELETE…

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
5.8 MEDIUM
CVE-2026-16439 — Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow

In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.

openj9 | Remote | Memory Corruption
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-47418 — praisonai-platform: Project endpoints accept any project_id without workspace ownership c…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD endpoints (`GET / PATCH / DELET…

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.8 HIGH
CVE-2026-16493 — Ansible-core: argument injection in ansible-galaxy collection install via git clone (inco…

A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator be…

Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-47417 — praisonai-platform: Comment endpoints accept any issue_id without workspace ownership che…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints (`POST /workspaces/{worksp…

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
0.0 NA
CVE-2026-47416 — praisonai-platform: Any workspace member can promote themselves (or any other member) to …

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/mem…

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2026-47410 — praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowin…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcod…

Remote | Cryptography
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.1 HIGH
CVE-2026-47409 — praisonai-platform: Any workspace member can remove any other member (including the owner…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.5 MEDIUM
CVE-2026-47408 — praisonai-platform: list_issue_activity returns activity log for any issue regardless of …

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issu…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
Showing 20 of 8426 Results