Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-15630 — CVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) an…

| Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-10697 — MFA Bypass in MOVEit Transfer

Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

moveit_transfer | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-65706 — FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing

FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame wit…

| Memory Corruption
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-65705 — FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame()

FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video str…

| Memory Corruption
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-65704 — FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder

FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer'…

| Memory Corruption
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.8 HIGH
CVE-2026-65703 — FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder

FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that cha…

| Memory Corruption
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
0.0 NA
CVE-2026-64785 — SwiftNIO HTTP/2 Improper Input Validation HTTP Request Smuggling

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HT…

| Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.8 CRITICAL
CVE-2026-63359 — Appriss Insights VINE SQLI

The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access othe…

Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.5 HIGH
CVE-2026-60122 — gpsd gpsprof Code Injection via SKY.satellites used Field

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS comman…

| Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.1 MEDIUM
CVE-2026-48013 — Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbi…

shopware | Remote | Server-Side Request Forgery
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
4.3 MEDIUM
CVE-2026-48012 — Shopware SSO referer trust leading to an arbitrary redirect target

Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without …

Remote | Misconfiguration
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.7 HIGH
CVE-2026-47722 — nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `List…

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.4 CRITICAL
CVE-2026-47670 — DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code…

DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS comman…

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.3 CRITICAL
CVE-2026-47669 — DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file p…

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-25800 — quinn-proto has remote memory exhaustion from unbounded out-of-order stream reassembly

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that assembles unordered s…

Remote | Denial of Service
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.8 HIGH
CVE-2026-15212 — WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 - Cross-Site…

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp…

Remote | Cross-Site Request Forgery
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-12353 — Rhcs: memory leak during https connection leads to denial of service

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is co…

Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.6 MEDIUM
CVE-2026-65010 — Datasets Symlink-following Arbitrary File Write via Extractor.extract()

Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at pred…

| Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.8 HIGH
CVE-2026-63765 — Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant acc…

Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.7 HIGH
CVE-2026-16756 — Allocation of resources without limits in the default aws-smithy-http-server serve() path…

Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial …

Remote | Denial of Service
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Showing 20 of 9775 Results