Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-28306 — SolarWinds Serv-U Privilege Escalation Vulnerability

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployme…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.1 CRITICAL
CVE-2026-28305 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write acc…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.1 CRITICAL
CVE-2026-28304 — SolarWinds Serv-U Remote Code Execution Vulnerability

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.

serv-u | Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.1 CRITICAL
CVE-2026-28302 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administra…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-16450 — zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization

A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyB…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.5 MEDIUM
CVE-2026-16449 — zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql…

A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/de…

Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.8 HIGH
CVE-2026-8933 — snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Exec…

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applicat…

| Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.7 HIGH
CVE-2026-65052 — Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListS…

Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculatio…

Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.9 MEDIUM
CVE-2026-65051 — Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in A…

Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging att…

Remote | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.1 HIGH
CVE-2026-65050 — Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Sub…

Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenti…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.3 CRITICAL
CVE-2026-65049 — Ninja Forms Cross-Site Network-Wide Data Deletion on WordPress Multisite via nf_delete_al…

Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja…

Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
9.3 CRITICAL
CVE-2026-65048 — Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submissio…

Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() a…

Remote | Cross-Site Scripting
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.8 HIGH
CVE-2026-59851 — Libssh: libssh: authentication bypass via missing gssapi principal check

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, a…

Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-59850 — Libssh: libssh: use-after-free via data callbacks on closed channels

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or poss…

enterprise_linux enterprise_linux hardened_images | Remote | Memory Corruption
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.1 LOW
CVE-2026-59849 — Libssh: libssh: denial of service via automatic certificate authentication loop

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly …

enterprise_linux enterprise_linux hardened_images | Remote | Denial of Service
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.7 LOW
CVE-2026-56587 — HCL IEM was affected with Strict transport security not enforced

HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.

Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
3.7 LOW
CVE-2026-56584 — HCL IEM was affected with the Information disclosure nginx server

HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.

Remote | Information Disclosure
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.2 MEDIUM
CVE-2026-47122 — Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowin…

Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnec…

sparkle | Authentication
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.2 HIGH
CVE-2026-46681 — @nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without…

@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object pr…

Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.5 MEDIUM
CVE-2026-16448 — D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, …

Remote | Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
Showing 20 of 8416 Results