Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-56250 — Capgo - Arbitrary R2 Object Deletion via Mutable r2_path in app_versions

Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, enabling retargeting to arbitrary R2 bundle objects. Attackers can patch r2_pat…

Remote | Misconfiguration
Jul 08, 2026 Jul 08, 2026
Jul 08, 2026
Jul 08, 2026
8.1 HIGH
CVE-2026-56246 — Capgo - Cross-Organization Authorization Bypass via Scoped API Key Privilege Inheritance

Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped API key (limited_to_orgs) inherits its owner-user's permissions, allowing destru…

Remote | Authorization
Jul 08, 2026 Jul 08, 2026
Jul 08, 2026
Jul 08, 2026
8.7 HIGH
CVE-2026-56226 — Capgo - Unauthenticated Organization Data Disclosure via get_orgs_v6 RPC

Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which is SECURITY DEFINER and granted to the anon role, allowing unauthenticated acce…

Remote | Authorization
Jul 08, 2026 Jul 08, 2026
Jul 08, 2026
Jul 08, 2026
7.1 HIGH
CVE-2026-56220 — Capgo - Unauthorized Manifest Insertion via Read-Only Org Member

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows read-only org members to insert OTA manifest rows. Attackers with read-only org a…

Remote | Authorization
Jul 08, 2026 Jul 08, 2026
Jul 08, 2026
Jul 08, 2026
4.3 MEDIUM
CVE-2026-56217 — Capgo - Encrypted Bundle Policy Bypass via Direct PostgREST Update

Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped API keys to downgrade encrypted bundles to non-encrypted state. Attackers with a…

Remote | Authentication
Jul 08, 2026 Jul 08, 2026
Jul 08, 2026
Jul 08, 2026
8.8 HIGH
CVE-2026-56086 — Dell PowerProtect Data Domain Incorrect Authorization Vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 thro…

Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
9.1 CRITICAL
CVE-2026-54061 — Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication …

dgraph | Remote | Authentication
Jul 08, 2026 Jul 08, 2026
Jul 08, 2026
Jul 08, 2026
7.5 HIGH
CVE-2026-53482 — Dell PowerProtect Data Domain Integer Overflow Denial of Service Vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 thro…

Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
2.7 LOW
CVE-2026-53480 — Dell PowerProtect Data Domain Path Traversal Vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 thro…

Jul 08, 2026 Jul 08, 2026
Jul 08, 2026
Jul 08, 2026
7.5 HIGH
CVE-2026-44840 — Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in Dgraph is vulnerable to DQL (Dgraph Query Language) injection. User-supplied p…

dgraph | Remote | Injection
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
7.1 HIGH
CVE-2026-41122 — Dell PowerProtect Data Domain Stored Cross-Site Scripting Vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 thro…

powerprotect_data_domain data_domain_operating_system | Remote | Cross-Site Scripting
Jul 08, 2026 Jul 08, 2026
Jul 08, 2026
Jul 08, 2026
7.8 HIGH
CVE-2026-22927 — Omnissa Workspace ONE Tunnel Local Privilege Escalation Vulnerability

Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.

windows workspace_one_tunnel | Authorization
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
7.5 HIGH
CVE-2026-15053 — Tanium addressed a denial of service vulnerability in Tanium Server.

Tanium addressed a denial of service vulnerability in Tanium Server.

server | Remote | Denial of Service
Jul 08, 2026 Jul 10, 2026
Jul 08, 2026
Jul 10, 2026
7.8 HIGH
CVE-2026-15035 — bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injec…

A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing…

openllm | Injection
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
5.0 MEDIUM
CVE-2026-15034 — flask-dashboard Flask-MonitoringDashboard cross-site request forgery

A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to cross-site request forgery. T…

flask-monitoringdashboard | Remote | Cross-Site Request Forgery
Jul 08, 2026 Jul 08, 2026
Jul 08, 2026
Jul 08, 2026
6.5 MEDIUM
CVE-2026-15033 — christopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec …

A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the function shelljs.exec of the file dist/packageUtils.js of the component peerDepe…

check-peer-dependencies | Remote | Injection
Jul 08, 2026 Jul 08, 2026
Jul 08, 2026
Jul 08, 2026
5.4 MEDIUM
CVE-2026-8315 — Stored XSS in Webbeyaz's Mediküm Web

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Stored XSS. This issue affects Mediküm Web: through 08072…

Remote | Cross-Site Scripting
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
6.1 MEDIUM
CVE-2026-8310 — Reflected XSS in Webbeyaz's Mediküm Web

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS. This issue affects Mediküm Web: through 08…

Remote | Cross-Site Scripting
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
9.8 CRITICAL
CVE-2026-8307 — SQLi in Webbeyaz's Mediküm Web

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affects Mediküm Web: through 08…

Remote | Injection
Jul 08, 2026 Jul 09, 2026
Jul 08, 2026
Jul 09, 2026
7.2 HIGH
CVE-2026-6820 — VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Script…

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 1.8.8 due to insufficient i…

vikbooking_hotel_booking_engine_\&_pms | Remote | Cross-Site Scripting
Jul 08, 2026 Jul 08, 2026
Jul 08, 2026
Jul 08, 2026
Showing 20 of 9379 Results