Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 CRITICAL
CVE-2026-73700 — Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Co…

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack …

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-72682 — Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servi…

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent…

kibana | Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-72654 — Execution with Unnecessary Privileges in Kibana Leading to Information Disclosure

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only…

kibana | Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-72652 — Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servi…

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted req…

kibana | Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.8 HIGH
CVE-2026-72649 — Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artif…

elasticsearch | Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-72644 — Uncaught Exception in Kibana Leading to Denial of Service

Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use th…

kibana | Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.4 MEDIUM
CVE-2026-72641 — Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized modification of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only Se…

kibana | Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
4.3 MEDIUM
CVE-2026-72633 — Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitori…

Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user ho…

kibana | Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-72628 — Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service

Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could…

kibana | Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-63138 — Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Info…

Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affect…

kibana | Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.3 HIGH
CVE-2026-63137 — Incorrect Authorization in Kibana Leading to Privilege Escalation

Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions…

kibana | Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
4.9 MEDIUM
CVE-2026-56143 — Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial o…

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a spec…

elasticsearch | Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.5 HIGH
CVE-2026-45221 — Konga < 2.1.0 Privilege Escalation via Hardcoded OpenSSL Path

Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSSL configuration or library …

| Misconfiguration
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-33465 — Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servi…

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level permissions could s…

kibana | Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.6 CRITICAL
CVE-2026-19766 — Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Ne…

An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute…

| Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-63435 — Mail: Email address spoofing via malformed RFC 2047 encoded-words

Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#…

| Misconfiguration
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-84361 — Composer: Perforce source URL permits P4PORT `rsh:` command execution

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set …

| Supply Chain
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-84311 — pypdf: Possible long runtimes/large memory usage when extracting XForm objects

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse…

| Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-84310 — pypdf: Possible long runtimes/large memory usage when retrieving outlines

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memor…

| Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.3 HIGH
CVE-2026-8712 — Wyoming < 1.10.2 SSRF via uri Query Parameter

Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a …

Remote | Server-Side Request Forgery
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
Showing 20 of 12502 Results