Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-57106 — Data Quality Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
10.0 CRITICAL
CVE-2026-56163 — Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.7 HIGH
CVE-2026-55732 — Loytec LINX firmware: Out-of-bounds Read in BACnet packet parsing (bacdt_datetime_to_tod)

Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthe…

Remote | Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.6 MEDIUM
CVE-2026-55731 — Loytec LINX firmware: Unchecked input for loop condition in the SNMP agent

Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote a…

Remote | Denial of Service
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.7 HIGH
CVE-2026-55730 — Loytec LWEB802: Reflected Cross-Site Scripting in LWEB802

Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and…

Remote | Cross-Site Scripting
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
7.7 HIGH
CVE-2026-55729 — Loytec LWEB802: Exposure of Sensitive Information in browser localStorage

Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management cred…

Remote | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
3.8 LOW
CVE-2026-55728 — Loytec LINX firmware: Stack-based Buffer Overflow in cmd_ipaddr_conflict

Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `super…

| Memory Corruption
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-49326 — Apache HBase: Missing scanner instance owner check in thrift delegation service

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open ste…

hbase | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
6.5 MEDIUM
CVE-2026-17059 — Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypa…

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system …

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-16802 — Devolutions PowerShell Universal Cleartext Storage of Sensitive Information

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via sec…

powershell_universal | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-16801 — Devolutions PowerShell Universal Code Injection Vulnerability

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission…

powershell_universal | Injection
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-16800 — Devolutions PowerShell Universal Code Injection Vulnerability

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permissi…

powershell_universal | Injection
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-16799 — Devolutions PowerShell Universal Improper Access Control Vulnerability

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute autom…

powershell_universal | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
0.0 NA
CVE-2026-16798 — Devolutions PowerShell Universal Sensitive Information Disclosure

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permi…

powershell_universal | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.4 HIGH
CVE-2026-12504 — Loytec LINX firmware: Improper Authentication in PAM configuration

Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticat…

| Authentication
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
9.2 CRITICAL
CVE-2026-12503 — Loytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter

Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to ma…

| Path Traversal
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.4 HIGH
CVE-2026-12502 — Loytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo

Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker…

| Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
8.7 HIGH
CVE-2026-12496 — Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server

Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticate…

Remote | Cross-Site Scripting
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
5.5 MEDIUM
CVE-2026-17048 — Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via ad…

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in…

single_sign-on data_grid build_of_keycloak | Remote | Information Disclosure
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
7.1 HIGH
CVE-2026-9765 — CVE-2026-9765 CVE Record

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are not authorized to access. An…

Remote | Authorization
Jul 24, 2026 Jul 24, 2026
Jul 24, 2026
Jul 24, 2026
Showing 20 of 9750 Results