Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-51535 — OpENer Resource Exhaustion Vulnerability

In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop.

Remote | Denial of Service
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
6.5 MEDIUM
CVE-2026-48492 — Snipe-IT's selectlist visibility is too permissive

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log into Snipe-IT - reg…

snipe-it | Remote | Authorization
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
7.2 HIGH
CVE-2026-44161 — Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, the Fluentd out_http output plugin allows placeholders such as…

fluentd | Remote | Server-Side Request Forgery
Jul 08, 2026 Jul 13, 2026
Jul 08, 2026
Jul 13, 2026
7.5 HIGH
CVE-2026-44160 — Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward plugins support gzip-compress…

fluentd | Remote | Denial of Service
Jul 08, 2026 Jul 13, 2026
Jul 08, 2026
Jul 13, 2026
7.5 HIGH
CVE-2026-44025 — Fluentd: Exposure of Sensitive Information via Monitor Agent API

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_agent exposes intern…

fluentd | Remote | Information Disclosure
Jul 08, 2026 Jul 16, 2026
Jul 08, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-44024 — Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the $…

fluentd | Remote | Path Traversal
Jul 08, 2026 Jul 13, 2026
Jul 08, 2026
Jul 13, 2026
6.3 MEDIUM
CVE-2026-39179 — SOGo SQL Injection Vulnerability

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.

Remote | Injection
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
6.3 MEDIUM
CVE-2026-39178 — SOGo SQL Injection Vulnerability

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.

Remote | Injection
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
8.1 HIGH
CVE-2026-35552 — CAXperts UPVWebServices and UDiTH Portal Improper Authorization Vulnerability

In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users.…

Remote | Authorization
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
9.8 CRITICAL
CVE-2026-31309 — Mysterium Node Improper Authorization Vulnerability

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration an…

Remote | Authorization
Jul 08, 2026 Jul 16, 2026
Jul 08, 2026
Jul 16, 2026
3.3 LOW
CVE-2026-15168 — Use of Uninitialized Variable in Wireshark

BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure

wireshark | Information Disclosure
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
8.8 HIGH
CVE-2026-10037 — Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal

A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is ins…

ubuntu ubuntu_desktop_provision | Denial of Service
Jul 08, 2026 Jul 14, 2026
Jul 08, 2026
Jul 14, 2026
4.3 MEDIUM
CVE-2026-8472 — Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticat…

gitlab | Remote | Authorization
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
5.3 MEDIUM
CVE-2026-7492 — Missing Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthent…

gitlab | Remote | Authorization
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
8.7 HIGH
CVE-2026-6896 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in G…

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authentica…

gitlab | Remote | Cross-Site Scripting
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
2.7 LOW
CVE-2026-6352 — Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticat…

gitlab | Remote | Authorization
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
8.6 HIGH
CVE-2026-60105 — Monsta FTP < 2.14.5 SSRF via IPv4-Mapped IPv6 Address Bypass

Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() function, which fails to de…

monsta_ftp | Remote | Server-Side Request Forgery
Jul 08, 2026 Jul 14, 2026
Jul 08, 2026
Jul 14, 2026
8.1 HIGH
CVE-2026-59818 — etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints …

etcd | Remote | Authentication
Jul 08, 2026 Jul 13, 2026
Jul 08, 2026
Jul 13, 2026
8.2 HIGH
CVE-2026-58525 — Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
6.5 MEDIUM
CVE-2026-58494 — Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source an…

wasmtime | Path Traversal
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
Showing 20 of 9488 Results