Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-72638 — Uncontrolled Recursion in Elasticsearch Leading to Denial of Service

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions c…

elasticsearch | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72636 — Uncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial of Service

Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns agai…

elasticsearch | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-72632 — Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent Elasticsear…

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the res…

kibana | Remote | Information Disclosure
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72631 — Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Ke…

Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the…

kibana | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-72630 — Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation

Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific inte…

kibana | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-72629 — Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Space Access …

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is …

kibana | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-59714 — Open WebUI: Cross-channel message overwrite via chat completion API (single-model and mul…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not …

open_webui | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.6 HIGH
CVE-2026-49864 — wetty vulnerable to DOM XSS via file-download filename

wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toa…

Remote | Cross-Site Scripting
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.3 MEDIUM
CVE-2026-49096 — Uncaught Exception in Kibana Cases Leading to Denial of Service

Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when t…

kibana | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-49089 — Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servi…

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting opera…

kibana | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-48099 — WsgiDAV encoded dot segments can escape filesystem share roots

WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesy…

wsgidav | Remote | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.9 MEDIUM
CVE-2026-45774 — compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relat…

compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves `trestle://` URIs and…

Remote | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-45725 — compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path T…

compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPF…

Remote | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
10.0 HIGH
CVE-2026-19747 — Tenda CH7 ATE Module Kylin HandleCmd command injection

A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the co…

cp3 cp7 cp3_pro | Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.3 MEDIUM
CVE-2026-19746 — Calix GigaSpire traceroute.cmd denial of service

A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file traceroute.cmd. The manipulation leads to denial of service. The attack may be initia…

Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.3 MEDIUM
CVE-2026-19745 — Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service

A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave.cgi of the component Web Management Interface. Executing a manipulation of the…

Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.5 HIGH
CVE-2026-18846 — IBM i is Affected By Multiple Vulnerabilities in Host Servers

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the host servers, a remote attacker could leverage this …

i i | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.1 HIGH
CVE-2026-18164 — Flow Neuroscience FL-100 Use of Hard-coded Credentials

An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation p…

| Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.5 HIGH
CVE-2026-17229 — IBM i is Affected By Multiple Vulnerabilities in Host Servers

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.

i i | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-17223 — IBM i is Affected By Multiple Vulnerabilities in Host Servers

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.

i i | Remote | Memory Corruption
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
Showing 20 of 10654 Results