Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-33803 — Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attack…

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited informat…

junos_os_evolved | Remote | Information Disclosure
Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
6.8 MEDIUM
CVE-2026-33802 — Junos OS: EX Series: Unauthorized users can execute service-impacting CLI command

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4…

Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
3.3 LOW
CVE-2026-15276 — pdeljanov Symphonia Metadata denial of service

A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metadata Handler. This manipulation causes denial of service. The attack needs to be…

symphonia | Denial of Service
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
3.3 LOW
CVE-2026-15274 — lo48576 fbxcel Node Header parser.rs denial of service

A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v7400/parser.rs of the component Node Header Handler. The manipulation results in …

fbxcel | Denial of Service
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
7.7 HIGH
CVE-2026-15271 — TOTOLINK EX200 Web boa.conf least privilege violation

A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functionality of the file…

a3100r a3000ru cp450 ex200 a950rg cp450 +6 more | Remote | Authorization
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
5.4 MEDIUM
CVE-2026-60120 — Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php

Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator bro…

bagisto | Remote | Cross-Site Scripting
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
7.1 HIGH
CVE-2026-55865 — Python Liquid: Infinite loop when parsing malformed `{% case %}` tags

Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} or {% else %} block and no terminating {% endcase …

python_liquid | Remote | Denial of Service
Jul 09, 2026 Jul 14, 2026
Jul 09, 2026
Jul 14, 2026
7.1 HIGH
CVE-2026-55212 — Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privi…

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, the Studio API class definition creation endpoint POST /pimcore-studio/api/class/definition/configurat…

pimcore | Remote | Authorization
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
7.7 HIGH
CVE-2026-55208 — Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract…

Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated user can extract the admin password hash and other database content through ti…

pimcore | Remote | Injection
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
8.8 HIGH
CVE-2026-55207 — Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacke…

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account b…

pimcore | Remote | Authentication
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
7.5 HIGH
CVE-2026-51926 — docuForm FSM Client User Enumeration Vulnerability

An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that…

Remote | Authentication
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
8.1 HIGH
CVE-2026-51925 — docuForm GmbH Local File Inclusion

A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit…

Remote | Path Traversal
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
8.1 HIGH
CVE-2026-51924 — docuForm Client Remote Code Execution

An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component

Remote | Injection
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
8.1 HIGH
CVE-2026-51923 — docuForm GmbH Insecure Direct Object Reference Vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or re…

Remote | Authorization
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
7.1 HIGH
CVE-2026-33801 — Junos OS and Junos OS Evolved: When a specifically malformed BGP route update is received…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attack…

junos junos_os_evolved | Denial of Service
Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
7.1 HIGH
CVE-2026-33800 — Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps will cause a…

An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-S…

junos | Denial of Service
Jul 09, 2026 Jul 20, 2026
Jul 09, 2026
Jul 20, 2026
5.3 MEDIUM
CVE-2026-33799 — Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results in memory lea…

An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries …

junos junos_os_evolved | Remote | Memory Corruption
Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
8.2 HIGH
CVE-2026-33794 — Junos OS Evolved: PTX Series: Receipt of repeated ECMP routing updates results in PFE cra…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated…

junos_os_evolved ptx1000-72q ptx10000 ptx10001 ptx10001-36mr ptx100016 +13 more | Remote | Denial of Service
Jul 09, 2026 Jul 13, 2026
Jul 09, 2026
Jul 13, 2026
5.7 MEDIUM
CVE-2026-31267 — Mercusys MW302R Buffer Overflow Vulnerability

Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. A stack buffer overflow vulnerability in the administrative web interface allow…

| Memory Corruption
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
6.7 MEDIUM
CVE-2026-21901 — Junos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crash

A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific S…

junos junos_os_evolved | Denial of Service
Jul 09, 2026 Jul 10, 2026
Jul 09, 2026
Jul 10, 2026
Showing 20 of 9549 Results