Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.8 MEDIUM
CVE-2026-10686 — Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS)…

Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branches of ipv6_route_packet() (subsys/net/ip) were affected: the explicit-rou…

zephyr zephyr | Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.3 MEDIUM
CVE-2025-62347 — HCL iControl Improper Input Validation Vulnerability

HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an a…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.3 MEDIUM
CVE-2026-67350 — Serendipity < 2.6.1 Open Redirect via exit.php

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encode…

serendipity | Remote | Misconfiguration
Jul 31, 2026 Aug 01, 2026
Jul 31, 2026
Aug 01, 2026
7.5 HIGH
CVE-2026-18446 — fast-uri vulnerable to host confusion via backslash authority introducer

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash…

fast-uri | Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.6 HIGH
CVE-2026-10685 — Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called par…

zephyr zephyr | Memory Corruption
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
2.1 LOW
CVE-2026-65636 — YAML injection via unescaped newlines in ymlr document comments

Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inject arbitrary content into generated YAML documents through document comments. …

ymlr | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-28145 — WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability

Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.

masterstudy_lms | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.3 MEDIUM
CVE-2026-28144 — WordPress WP Maps plugin <= 4.9.6 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6.

Remote | Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-18358 — Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection thro…

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection th…

Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.8 CRITICAL
CVE-2026-17561 — Unauthenticated RCE in Innotim Software's Logsign SIEM

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects L…

Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-15227 — Missing Authorization Allows Editing of Foreign Reports

Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.

checkmk | Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.1 MEDIUM
CVE-2026-46594 — Reflected XSS in PHP Poll Script

A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arb…

php_poll_script | Remote | Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.6 HIGH
CVE-2026-46593 — Authenticated SQL Injection in PHP Poll Script

A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticat…

php_poll_script | Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.9 MEDIUM
CVE-2025-67651 — CSRF in PHP Jabbers scripts

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthoriz…

Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.6 HIGH
CVE-2025-67650 — Authenticated SQL Injection in PHP Jabbers scripts

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for so…

Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.3 CRITICAL
CVE-2025-67649 — Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script

A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an un…

car_rental_script car_rental_script | Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-64607 — Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to P…

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header valu…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.1 HIGH
CVE-2026-62391 — Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf …

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via…

kyuubi | Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.5 MEDIUM
CVE-2026-44615 — Path traversal in NotebookRepo note and folder path composition

Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply tr…

zeppelin | Remote | Path Traversal
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-17567 — Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direc…

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,…

Remote | Information Disclosure
Jul 31, 2026 Aug 01, 2026
Jul 31, 2026
Aug 01, 2026
Showing 20 of 9400 Results