Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.3 LOW
CVE-2026-64615 — Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing fi…

Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in graph.h with open(path, O_RDWR|O_CREAT…

| Misconfiguration
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
3.8 LOW
CVE-2026-64614 — Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing fi…

Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h with open(path, O_RDWR|O_CREAT…

| Misconfiguration
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.2 MEDIUM
CVE-2026-64613 — Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing f…

Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created in buf_generic.h with open(path, O_RDWR|O_CREAT|O_…

| Misconfiguration
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
9.8 CRITICAL
CVE-2026-59147 — Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and wri…

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the hea…

Remote | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-59146 — Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and wri…

Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot. The attach-time v…

| Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.1 CRITICAL
CVE-2026-59145 — Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvali…

Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thoroug…

Remote | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-59144 — Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via …

Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity…

Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.3 MEDIUM
CVE-2026-59143 — Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via…

Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked. The attach-time validator rb_validate…

Remote | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-56852 — Infinite loop on invalid input in golang.org/x/text

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

Remote | Denial of Service
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
5.4 MEDIUM
CVE-2026-56146 — Improper Access Control in Kibana Leading to Unauthorized Data Modification and Informati…

Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user…

kibana | Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-56145 — Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL seq…

elasticsearch | Remote | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.3 MEDIUM
CVE-2026-56144 — Incorrect Authorization in Elasticsearch Leading to Information Disclosure

Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By ta…

elasticsearch | Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-50759 — Exo-explore Privilege Escalation Vulnerability

An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication.

Remote | Authentication
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-50758 — DayuanJiang next-ai-draw-io Cross-Site Scripting Vulnerability

Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter

Remote | Cross-Site Scripting
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.8 HIGH
CVE-2026-50757 — DayuanJiang next-ai-draw-io Directory Traversal Vulnerability

Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server

| Path Traversal
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-50756 — DayuanJiang next-ai-draw-io Information Disclosure Vulnerability

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

Remote | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-50755 — DayuanJiang next-ai-draw-io Sensitive Information Disclosure

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

Remote | Information Disclosure
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
4.3 MEDIUM
CVE-2026-49092 — Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Unauthorized In…

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under ce…

kibana | Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.4 MEDIUM
CVE-2026-47671 — Nhost CLI local configserver allows cross-origin unauthenticated read/write access to loc…

Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy autho…

cli | Remote | Misconfiguration
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-47667 — CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyze()` via Cra…

CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from the first 4 bytes of an Analyze/NIfTI file and…

cimg | Remote | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
Showing 20 of 9583 Results