Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-46600 — Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

Remote | Denial of Service
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.3 MEDIUM
CVE-2026-46403 — Klever-Go KVM read-only execution can commit contract delete and upgrade side effects

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the previous …

Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-42397 — Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servi…

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted req…

kibana | Remote | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-30632 — Knowns Directory Traversal Vulnerability

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.

Remote | Path Traversal
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.7 HIGH
CVE-2026-15957 — Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows un…

Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. …

aws-sdk-rust | Remote | Denial of Service
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.6 CRITICAL
CVE-2026-64877 — Ticketing REST API SQL Injection Vulnerability

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

security_center | Remote | Injection
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
7.2 HIGH
CVE-2026-63454 — Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command l…

Remote | Path Traversal
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
7.2 HIGH
CVE-2026-63453 — Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as …

Remote | Memory Corruption
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-59142 — Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an un…

Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the h…

Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.1 CRITICAL
CVE-2026-59141 — Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unv…

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the …

Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.1 CRITICAL
CVE-2026-59140 — Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unv…

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header bound…

Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.1 CRITICAL
CVE-2026-59139 — Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unv…

Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header chec…

Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.8 HIGH
CVE-2026-55084 — SQL Injection in SqlView Filter Parameter Leading to Arbitrary Database Read

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 app…

dhis_2 | Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.7 HIGH
CVE-2026-55082 — DHIS2 SQL injection in SQL View filter values

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL View data endpoints allowed authenticated users with SQL View access to provide…

dhis_2 | Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.3 HIGH
CVE-2026-55081 — DHIS2 Reflected XSS in OpenAPI HTML scope parameter

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into th…

dhis_2 | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.9 MEDIUM
CVE-2026-16441 — Eclipse OpenJ9 : Method resolution default method precedence failure

In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface def…

openj9 | Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
4.2 MEDIUM
CVE-2026-12548 — Libsoup: heap out-of-bounds read in libsoup due to integer truncation

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be in…

enterprise_linux enterprise_linux | Remote | Memory Corruption
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
3.4 LOW
CVE-2026-12547 — Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on p…

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy…

enterprise_linux enterprise_linux | Remote | Information Disclosure
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.8 CRITICAL
CVE-2016-20096 — Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp

Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name para…

Remote | Injection
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
3.1 LOW
CVE-2026-56583 — HCL MyCloud was affected with Concurrent Login Vulnerability.

HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.

mycloud | Remote | Authentication
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
Showing 20 of 9583 Results