Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-15966 — Improper CORS handling in MOVEit Transfer

Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

moveit_transfer | Remote | Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-15630 — CVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) an…

| Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-10697 — MFA Bypass in MOVEit Transfer

Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

moveit_transfer | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.8 HIGH
CVE-2026-65604 — Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass

Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBo…

skipper | Remote | Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.9 CRITICAL
CVE-2026-63732 — 9router before 0.4.60 Remote Code Execution via default password

9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a sp…

Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.3 HIGH
CVE-2026-63313 — 9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch

9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured ext…

Remote | Server-Side Request Forgery
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
10.0 CRITICAL
CVE-2025-71389 — Cal.com before 5.9.9 Remote Code Execution via RSC

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes …

cal.diy | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.3 CRITICAL
CVE-2024-58355 — Cal.com through 4.7.15 Cross-Site Scripting via booking questions

Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) renders booking-question field l…

cal.diy | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.9 CRITICAL
CVE-2024-58354 — cal.com Repository Takeover via pull_request_target Workflow

cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with th…

cal.diy | Remote | Supply Chain
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.3 CRITICAL
CVE-2024-58353 — Cal.com through 4.7.15 Cross-Site Scripting via booking questions

Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). Booking question (form fiel…

cal.diy | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-16763 — localstack serverless-localstack Configuration index.js os command injection

A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipu…

| Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-65706 — FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing

FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame wit…

| Memory Corruption
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-65705 — FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame()

FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video str…

| Memory Corruption
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-65704 — FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder

FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer'…

| Memory Corruption
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-65703 — FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder

FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that cha…

| Memory Corruption
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-64785 — SwiftNIO HTTP/2 Improper Input Validation HTTP Request Smuggling

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HT…

| Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.8 CRITICAL
CVE-2026-63359 — Appriss Insights VINE SQLI

The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access othe…

Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.5 HIGH
CVE-2026-60122 — gpsd gpsprof Code Injection via SKY.satellites used Field

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS comman…

| Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.1 MEDIUM
CVE-2026-48013 — Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbi…

shopware | Remote | Server-Side Request Forgery
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.3 MEDIUM
CVE-2026-48012 — Shopware SSO referer trust leading to an arbitrary redirect target

Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without …

Remote | Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Showing 20 of 9765 Results