Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.4 HIGH
CVE-2026-9292 — Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site Scripting

A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows con…

Remote | Cross-Site Scripting
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.3 HIGH
CVE-2026-9128 — Studio 5000 Logix Designer® – Multiple Vulnerabilities

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools conf…

studio_5000_logix_designer | Misconfiguration
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.3 HIGH
CVE-2026-9127 — Studio 5000 Logix Designer® – Multiple Vulnerabilities

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of e…

studio_5000_logix_designer | Authorization
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
5.4 MEDIUM
CVE-2026-9108 — Studio 5000 Logix Designer® – Multiple Vulnerabilities

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embe…

studio_5000_logix_designer | Path Traversal
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
5.3 MEDIUM
CVE-2026-7494 — Nexus Repository - SSRF in SSL Certificate Retrieval

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to in…

nexus_repository_manager | Remote | Server-Side Request Forgery
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
9.8 CRITICAL
CVE-2026-62644 — Roundcube Webmail Password Plugin Username Spoofing Vulnerability

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

webmail | Remote | Authentication
Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
10.0 CRITICAL
CVE-2026-62643 — Roundcube Webmail CSS Sanitization Bypass Information Disclosure

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if styleshe…

webmail | Remote | Server-Side Request Forgery
Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
6.5 MEDIUM
CVE-2026-62642 — Roundcube Webmail TNEF Decoder Denial of Service Vulnerability

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.

webmail | Remote | Denial of Service
Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
6.5 MEDIUM
CVE-2026-62641 — Roundcube Webmail TNEF Decoder Denial of Service Vulnerability

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.

webmail | Remote | Denial of Service
Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
5.4 MEDIUM
CVE-2026-60119 — Hi.Events < 1.11.0 XSS via Event Title JSON.stringify Injection

Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by embedding …

hi.events | Remote | Cross-Site Scripting
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
6.9 MEDIUM
CVE-2026-60118 — Hi.Events < 1.11.0 Hidden Ticket Enumeration via Order Creation Endpoint

Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price ID…

hi.events | Remote | Authorization
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
9.1 CRITICAL
CVE-2026-60082 — DBI versions before 1.651 for Perl do not enforce statement handle consistency with the r…

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper …

dbi | Remote | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-60081 — DBI::ProfileData versions before 1.651 for Perl do not limit the path index

DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allow…

dbi | Remote | Denial of Service
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-59841 — Fortinet FortiSIEMWindowsAgent Improper Restriction of Communication Channel Vulnerability

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert att…

Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
4.3 MEDIUM
CVE-2026-59840 — Fortinet FortiOS and FortiProxy Buffer Over-read Vulnerability

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 t…

fortios fortiswitchmanager fortiproxy fortios fortipam | Remote | Memory Corruption
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
5.5 MEDIUM
CVE-2026-59839 — Fortinet Path Traversal Vulnerability

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS …

fortios fortiproxy fortios fortipam | Path Traversal
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
6.6 MEDIUM
CVE-2026-59837 — Fortinet FortiOS, FortiPAM, and FortiProxy Stack-Based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, Fort…

fortios fortiproxy fortios fortipam fortisase | Remote | Memory Corruption
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
9.8 CRITICAL
CVE-2026-59836 — Fortinet FortiClientEMS Improper Certificate Validation Information Disclosure

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information d…

forticlientems | Remote | Cryptography
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
8.6 HIGH
CVE-2026-59835 — Fortinet FortiSandbox Exposure of Resource to Wrong Sphere Vulnerability

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of V…

fortisandbox fortisandbox | Remote | Misconfiguration
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-59205 — Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mod…

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image wh…

pillow | Remote | Memory Corruption
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
Showing 20 of 10850 Results