Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-35048 — Piwigo RCE via PHP Code Injection into Config File in Installer

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, t…

piwigo | Remote | Injection
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
6.8 MEDIUM
CVE-2026-33328 — Possible integer overflow on 32-bit systems when reading GIF images

libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to …

libvips | Memory Corruption
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
7.0 HIGH
CVE-2026-33327 — Possible integer overflow leading to potential heap-based buffer overflow

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer o…

libvips | Memory Corruption
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
7.3 HIGH
CVE-2026-32825 — dataCycle No Brute-Force Protection On Web And API Login Endpoints

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Authentication
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
7.3 HIGH
CVE-2026-32824 — dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Controlled Redir…

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-32823 — dataCycle State-Changing GET Endpoints Enable CSRF

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Cross-Site Request Forgery
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
8.1 HIGH
CVE-2026-32821 — API Collection Impersonation Via user_email And Missing Object- Level Authorization

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Authorization
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-32820 — dataCycle Public Markdown Path Traversal Via /docs/*path

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Path Traversal
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-32819 — dataCycle User Directory Enumeration Via /users/search

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Information Disclosure
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-32806 — dataCycle Authorization Bypass Via /remote_render

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Authorization
Jul 20, 2026 Jul 21, 2026
Jul 20, 2026
Jul 21, 2026
Showing 20 of 12470 Results