Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2026-35590 — Possible out-of-bounds read leading to crash when decoding well-crafted EXIF metadata

libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing da…

| Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.5 MEDIUM
CVE-2026-35217 — NanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectabl…

NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Options` field, the broker may still accept the malfor…

Remote | Injection
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
9.8 CRITICAL
CVE-2026-35048 — Piwigo RCE via PHP Code Injection into Config File in Installer

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, t…

Remote | Injection
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.8 MEDIUM
CVE-2026-33328 — Possible integer overflow on 32-bit systems when reading GIF images

libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to …

| Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.0 HIGH
CVE-2026-33327 — Possible integer overflow leading to potential heap-based buffer overflow

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer o…

| Memory Corruption
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.3 HIGH
CVE-2026-32825 — dataCycle No Brute-Force Protection On Web And API Login Endpoints

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Authentication
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.3 HIGH
CVE-2026-32824 — dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Controlled Redir…

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Server-Side Request Forgery
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
4.3 MEDIUM
CVE-2026-32823 — dataCycle State-Changing GET Endpoints Enable CSRF

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Cross-Site Request Forgery
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.1 HIGH
CVE-2026-32821 — API Collection Impersonation Via user_email And Missing Object- Level Authorization

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.5 HIGH
CVE-2026-32820 — dataCycle Public Markdown Path Traversal Via /docs/*path

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Path Traversal
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
4.3 MEDIUM
CVE-2026-32819 — dataCycle User Directory Enumeration Via /users/search

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Information Disclosure
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
7.5 HIGH
CVE-2026-32806 — dataCycle Authorization Bypass Via /remote_render

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…

Remote | Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.4 MEDIUM
CVE-2026-6793 — Stored XSS in Bifra Engineering's Q-smart NexT Poll

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects Q-smar…

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
8.6 HIGH
CVE-2026-63429 — HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no aut…

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no se…

Remote | Authentication
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.8 MEDIUM
CVE-2026-63428 — HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without va…

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from the submitter and stores it verbatim in `submission.…

Remote | Injection
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.4 MEDIUM
CVE-2026-63102 — rConfig Core < 8.2.8 Privilege Escalation via Users API role field

rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Us…

Remote | Authorization
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
9.9 CRITICAL
CVE-2026-51027 — FileThingie Information Disclosure Vulnerability

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

Remote | Information Disclosure
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
6.5 MEDIUM
CVE-2026-51026 — FileThingie Directory Traversal Vulnerability

Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.

Remote | Path Traversal
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
5.3 MEDIUM
CVE-2026-48824 — Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messag…

Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a default 50MB p/m limit to prevent DoS via unlimited …

mailpit | Remote | Denial of Service
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
4.4 MEDIUM
CVE-2026-46671 — Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files…

Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook…

| Path Traversal
Jul 20, 2026 Jul 20, 2026
Jul 20, 2026
Jul 20, 2026
Showing 20 of 8271 Results