Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.2 MEDIUM
CVE-2026-51298 — SQLite Use-After-Free Vulnerability

sqlite 3.41 is vulnerable to use after free in the JSON extraction function. After releasing JsonParse object memory via jsonParseFree(), the program still accesses internal member of the freed point…

| Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.8 HIGH
CVE-2026-51297 — SQLite JSON Parsing Use-After-Free Vulnerability

sqlite 3.41 has a use-after-free vulnerability in the JSON parsing logic. Remote adversaries can craft malicious JSON payload to trigger memory free followed by illegal memory access, which may lead …

Remote | Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-51296 — SQLite JSON Module Use-After-Free Vulnerability

SQLite 3.41 has a use-after-free vulnerability in jsonRemoveFunc of SQLite JSON module. The parsed JSON object is freed at line 3555, while line 3575 still calls jsonLookupStep with the released poin…

| Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.8 MEDIUM
CVE-2026-47078 — Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass

Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive. zip:unzip/1,2 and zip:extract/1,2 va…

otp | Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.3 MEDIUM
CVE-2026-42792 — epmd permanent DoS via EMFILE on accept(2) in erts

Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connect…

otp | Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.2 MEDIUM
CVE-2026-17574 — NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash w…

| Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.0 MEDIUM
CVE-2026-17573 — Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field

A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double…

| Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.5 MEDIUM
CVE-2026-17572 — HDF5 SOHM List Index Heap Buffer Overflow

Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose share…

| Memory Corruption
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-17530 — AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py…

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-17529 — AstrBotDevs AstrBot astr_main_agent.py authorization

A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads t…

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
10.0 CRITICAL
CVE-2026-16812 — VeloCloud Orchestrator OS Command Injection

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may…

Remote | Authentication
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
9.1 CRITICAL
CVE-2025-50455 — EasyAppointments SQL Injection

SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passe…

Remote | Injection
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.3 MEDIUM
CVE-2026-66477 — WordPress Gillion theme <= 4.13 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Gillion <= 4.13 versions.

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.9 MEDIUM
CVE-2026-66476 — WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vulnerability

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

Remote | Path Traversal
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.9 MEDIUM
CVE-2026-66475 — WordPress Checkout Field Editor for WooCommerce &#8211; Checkout Manager plugin <= 3.0.5 …

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
4.3 MEDIUM
CVE-2026-66474 — WordPress Insert Headers and Footers Code – HT Script plugin <= 1.1.8 - Cross Site Reques…

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

Remote | Cross-Site Request Forgery
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-66448 — WordPress Gallery PhotoBlocks plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

gallery_photoblocks | Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-66445 — WordPress Open User Map plugin <= 1.4.46 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

open_user_map | Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.4 MEDIUM
CVE-2026-66442 — WordPress YayPricing plugin <= 3.5.6 - Broken Access Control vulnerability

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.3 MEDIUM
CVE-2026-66438 — WordPress Exclusive Addons Elementor plugin <= 2.8.0 - Sensitive Data Exposure vulnerabil…

Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

Remote | Information Disclosure
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Showing 20 of 9099 Results