Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-44090 — Missing authentication for MQTT Broker

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compr…

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.1 HIGH
CVE-2026-13584 — Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communi…

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/…

| Denial of Service
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.3 MEDIUM
CVE-2026-64635 — Veeam Service Provider Console Open Redirect to Account Takeover

Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset…

Remote | Server-Side Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
4.2 MEDIUM
CVE-2026-59328 — Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips

Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoint…

Remote | Cross-Site Scripting
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
4.4 MEDIUM
CVE-2026-59327 — Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations

Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse p…

| Misconfiguration
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
3.3 LOW
CVE-2026-59326 — HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit …

| Information Disclosure
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
9.8 CRITICAL
CVE-2026-58066 — Rocket.Chat SAML SSO XML Signature Wrapping Vulnerability

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:As…

Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
9.9 CRITICAL
CVE-2026-58046 — Plesk SQL Injection Vulnerability

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise…

Remote | Injection
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.5 HIGH
CVE-2026-58043 — Node.js Permission Model Filesystem Access Control Bypass

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse b…

| Path Traversal
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.3 MEDIUM
CVE-2026-58040 — Node.js HTTPS Agent Hostname Verification Bypass

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects …

Remote | Misconfiguration
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
4.1 MEDIUM
CVE-2026-56850 — Node.js HTTPS Agent Mutual TLS Identity Confusion Vulnerability

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client ce…

| Misconfiguration
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
3.3 LOW
CVE-2026-56847 — Node.js Permission Model Security Bypass Vulnerability

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the…

| Misconfiguration
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.3 HIGH
CVE-2026-47882 — Spring Boot DevTools remote secret generated with a non-cryptographic PRNG

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared …

| Cryptography
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.0 HIGH
CVE-2026-47873 — Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on a…

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Pro…

| Misconfiguration
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.0 HIGH
CVE-2026-47858 — live information startup mode is vulnerable for remote code execution

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products…

| Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.3 MEDIUM
CVE-2026-16531 — Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentiall…

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.5 MEDIUM
CVE-2026-16530 — Pcp: pcp: remote denial of service and information leakage

A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This byp…

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.5 HIGH
CVE-2026-16529 — Pcp: pcp: denial of service due to signed integer overflow

A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulti…

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.3 HIGH
CVE-2026-16527 — Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access …

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitra…

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.8 HIGH
CVE-2026-16526 — Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
Showing 20 of 10020 Results