Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.2 MEDIUM
CVE-2026-65699 — AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation

AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run…

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-47769 — APIFold Vulnerable to Unauthenticated Webhook Event Injection

APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the `/webhooks/:serverS…

Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-47755 — ITFlow Vulnerable to Authenticated Cross-Tenant Credential Disclosure via Unprotected Cre…

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials…

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.9 CRITICAL
CVE-2026-47752 — Tugtainer has Server-Side Template Injection in notification templates that leads to Remo…

Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The …

tugtainer | Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.7 HIGH
CVE-2026-47743 — Shopper: Multiple data integrity and disclosure issues in admin Livewire components

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Live…

Remote | Authentication
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
10.0 CRITICAL
CVE-2026-47668 — DbGate: Unauthenticated Remote Code Execution via JSON Script Runner

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` param…

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.8 MEDIUM
CVE-2026-44210 — Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled P…

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default config…

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.3 CRITICAL
CVE-2026-65761 — Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension…

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, …

Remote | Injection
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
9.2 CRITICAL
CVE-2026-65760 — Joomla Extension - joomshaper.com - cross-customer order and personal information disclos…

Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and c…

| Information Disclosure
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.7 HIGH
CVE-2026-65759 — Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store e…

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client sid…

Remote | Cross-Site Request Forgery
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.0 MEDIUM
CVE-2026-65698 — Void 1.3.4 Path Traversal via AI Agent File-Reading Tools

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrary host files outside the open workspace by injecti…

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
6.1 MEDIUM
CVE-2026-65697 — Fathom Lite 1.3.1 Stored XSS via /collect Endpoint

Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attackers to inject a javascript: URI into the Top Page…

Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.4 MEDIUM
CVE-2026-65696 — Overseerr 1.35.0 Authorization Bypass via pushSubscriptions API

Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other us…

Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.6 HIGH
CVE-2026-65695 — Office-Word-MCP-Server 1.1.11 Path Traversal via document tools

Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or crea…

Remote | Path Traversal
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-44909 — Proxygen HTTP/2 Flow Control Denial of Service Vulnerability

Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW…

proxygen | Denial of Service
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.3 MEDIUM
CVE-2026-16768 — Gdk-pixbuf: out-of-bounds read in ico parser

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking agai…

enterprise_linux enterprise_linux | Remote | Information Disclosure
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.8 HIGH
CVE-2026-65917 — CyberPanel IncBackups IDOR via Sequential Backup ID

CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRe…

cyberpanel | Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
8.1 HIGH
CVE-2026-65916 — CyberPanel Missing Authorization in cancelBackupCreation Handler

CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt othe…

cyberpanel | Remote | Authorization
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.4 MEDIUM
CVE-2026-48539 — GFI Archiver < 15.13 Stored XSS via MailInsights.aspx

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or…

archiver | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
5.4 MEDIUM
CVE-2026-48538 — GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated attackers to inject arbitrary web script or HTML …

archiver | Remote | Cross-Site Scripting
Jul 23, 2026 Jul 23, 2026
Jul 23, 2026
Jul 23, 2026
Showing 20 of 9774 Results