Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-64600 — xfs: resample the data fork mapping after cycling ILOCK

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a …

linux_kernel | Race Condition
Jul 23, 2026 Jul 24, 2026
Jul 23, 2026
Jul 24, 2026
6.9 MEDIUM
CVE-2026-63226 — Ricoh Multifunction Printers SSH Port Forwarding Arbitrary Connection Vulnerability

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on …

| Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.8 MEDIUM
CVE-2026-6390 — Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via…

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf f…

Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-7120 — @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths

@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affe…

fastify-static | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-15074 — @fastify/static vulnerable to route guard bypass via path traversal

@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, …

fastify-static | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-21723 — CVE-2026-21723 Record

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM an…

grafana | Remote | Denial of Service
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.5 MEDIUM
CVE-2026-16653 — boazsegev facil.io Public Folder http.c http_sendfile2 path traversal

A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a…

facil.io | Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-16632 — boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input v…

A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame…

facil.io | Remote | Denial of Service
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-16631 — publint package-manager pack.js child_process.exec os command injection

A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation resul…

publint | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…

Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…

Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…

Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…

Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
9.8 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…

Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
8.0 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…

Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
7.5 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…

Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
9.9 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…

Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…

Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
9.8 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…

Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
10.0 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…

Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
Showing 20 of 8954 Results