Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-61392 — Hikvision Camera Information Disclosure Vulnerability

There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.

Remote | Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.2 HIGH
CVE-2026-61391 — Hikvision Camera Stack-Based Buffer Overflow

There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.

Remote | Memory Corruption
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.7 HIGH
CVE-2026-61390 — Hikvision Camera Heap Buffer Overflow

There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.

Remote | Memory Corruption
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-57600 — Hikvision Cameras Input Validation Vulnerability

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.

Remote | Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.6 MEDIUM
CVE-2026-57599 — Hikvision Camera Privilege Escalation Vulnerability

There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the d…

Remote | Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-4773 — OTP Bypass in Magarsus' IDM-MFA

Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.

Remote | Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.6 MEDIUM
CVE-2026-44192 — Ansible-lightspeed: ansible lightspeed mcp server: remote code execution and data exfiltr…

A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injec…

ansible_automation_platform | Path Traversal
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.8 HIGH
CVE-2026-44190 — Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execu…

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. Th…

Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.8 HIGH
CVE-2026-44189 — Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execu…

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename co…

Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
3.3 LOW
CVE-2026-44187 — Ansible-lightspeed: ansible lightspeed extension for visual studio code: information disc…

A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges,…

ansible_automation_platform | Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.9 MEDIUM
CVE-2026-16551 — Denial-of-Service in OpenCanary's MongoDB module

Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only.

Remote | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-16544 — Awx: websocket eventconsumer missing authorization for inventory_update_events, project_u…

A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_c…

ansible_automation_platform | Remote | Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2025-13146 — Contact Form 7 – Dynamic Text Extension <= 5.0.6 - Unauthenticated Arbitrary Shortcode Ex…

The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due to the software allowing u…

Remote | Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.8 HIGH
CVE-2026-44191 — Ansible-lightspeed: visual studio code ansible lightspeed extension: remote code executio…

A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptio…

Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
4.3 MEDIUM
CVE-2026-16473 — Sbc: sbc: heap out-of-bounds read via crafted sbc audio frame

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an a…

enterprise_linux enterprise_linux | Memory Corruption
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.8 HIGH
CVE-2026-14551 — Local Privilege Escalation in servereye client (sensorhub)

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recover…

| Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.3 MEDIUM
CVE-2026-63264 — Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3

The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.

Remote | Cross-Site Scripting
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-2406 — IDOR in Universe Software's Online Registration and Workflow Management System

Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Tru…

Remote | Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.4 MEDIUM
CVE-2026-15787 — Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site S…

The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and i…

ultimate_addons_for_elementor | Remote | Cross-Site Scripting
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
9.4 CRITICAL
CVE-2026-63048 — Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2

The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

Remote | Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
Showing 20 of 9693 Results