Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-64821 — djangoSIGE 1.10 CSRF via GET-based Order Cancellation Views

djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated attackers to cancel sales or purchase orders on behalf of authenticated users …

Remote | Cross-Site Request Forgery
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
9.3 CRITICAL
CVE-2026-63764 — LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-…

lmdeploy | Remote | Server-Side Request Forgery
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
8.4 HIGH
CVE-2026-63358 — FileGator privilege escalation

FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with no validatio…

filegator | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-63140 — Reachable Assertion in Elasticsearch Leading to Denial of Service

Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query cl…

elasticsearch | Remote | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-63139 — Uncontrolled Resource Consumption in Kibana Leading to Denial of Service

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource con…

kibana | Remote | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-63136 — Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search re…

elasticsearch | Remote | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.3 MEDIUM
CVE-2026-63092 — kirby-modules License Key Disclosure via modules/activate Dialog

kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license…

Remote | Information Disclosure
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-63080 — Aptabase SQL Injection via ClickHouse query backend

Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authenticated attackers to read event data across all tenants by injecting unsanitiz…

Remote | Injection
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-56147 — Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Inform…

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An incon…

kibana | Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-52476 — Aiflowy SQL Injection Vulnerability

SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPageData method in the DatacenterQuery.java file

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.1 MEDIUM
CVE-2026-52475 — Aiflowy Cross-Site Scripting Vulnerability

Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the UploadController.java file

Remote | Cross-Site Scripting
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-52474 — Aiflowy Information Disclosure Vulnerability

An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.

Remote | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-52472 — Wgcloud SQL Injection Vulnerability

SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-52470 — Crocus SQL Injection Vulnerability

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-52469 — Crocus SQL Injection Privilege Escalation

SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.1 MEDIUM
CVE-2026-47714 — libheif has integer overflow in inline mask size calculation that causes undersized buffe…

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `width` and `height` a…

libheif | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.3 CRITICAL
CVE-2026-47708 — MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper

MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata c…

Remote | Injection
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-47697 — Shelf has cross-organization IDOR: authenticated users could read/attach another workspac…

Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). Prior to version 1.20.2, several endpoints accepted entity IDs from request inp…

Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-47695 — CC-Tweaked has an SSRF Protection Bypass with NAT64

CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.119.0, CC-Tweaked's HTTP API (`http.request`, `http.websocket`) blocks requests…

cc-tweaked | Remote | Server-Side Request Forgery
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-47690 — MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workfl…

MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration…

Remote | Supply Chain
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
Showing 20 of 9602 Results