Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-15427 — OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v

An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input…

Jul 14, 2026 Aug 06, 2026
Jul 14, 2026
Aug 06, 2026
4.9 MEDIUM
CVE-2026-14646 — Nexus Repository 3 - Server-Side Request Forgery (SSRF) via HTTP Redirect

Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a pro…

nexus_repository_manager | Remote | Server-Side Request Forgery
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
5.1 MEDIUM
CVE-2026-14645 — Nexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global Capability

Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration…

nexus_repository_manager | Remote | Server-Side Request Forgery
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
8.2 HIGH
CVE-2026-9636 — Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Modul…

A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the control…

Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.4 HIGH
CVE-2026-9292 — Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site Scripting

A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows con…

Remote | Cross-Site Scripting
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.3 HIGH
CVE-2026-9128 — Studio 5000 Logix Designer® – Multiple Vulnerabilities

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools conf…

studio_5000_logix_designer | Misconfiguration
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.3 HIGH
CVE-2026-9127 — Studio 5000 Logix Designer® – Multiple Vulnerabilities

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of e…

studio_5000_logix_designer | Authorization
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
5.4 MEDIUM
CVE-2026-9108 — Studio 5000 Logix Designer® – Multiple Vulnerabilities

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embe…

studio_5000_logix_designer | Path Traversal
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
5.3 MEDIUM
CVE-2026-7494 — Nexus Repository - SSRF in SSL Certificate Retrieval

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to in…

nexus_repository_manager | Remote | Server-Side Request Forgery
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
9.8 CRITICAL
CVE-2026-62644 — Roundcube Webmail Password Plugin Username Spoofing Vulnerability

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

webmail | Remote | Authentication
Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
10.0 CRITICAL
CVE-2026-62643 — Roundcube Webmail CSS Sanitization Bypass Information Disclosure

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if styleshe…

webmail | Remote | Server-Side Request Forgery
Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
6.5 MEDIUM
CVE-2026-62642 — Roundcube Webmail TNEF Decoder Denial of Service Vulnerability

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.

webmail | Remote | Denial of Service
Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
6.5 MEDIUM
CVE-2026-62641 — Roundcube Webmail TNEF Decoder Denial of Service Vulnerability

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.

webmail | Remote | Denial of Service
Jul 14, 2026 Jul 20, 2026
Jul 14, 2026
Jul 20, 2026
5.4 MEDIUM
CVE-2026-60119 — Hi.Events < 1.11.0 XSS via Event Title JSON.stringify Injection

Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by embedding …

hi.events | Remote | Cross-Site Scripting
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
6.9 MEDIUM
CVE-2026-60118 — Hi.Events < 1.11.0 Hidden Ticket Enumeration via Order Creation Endpoint

Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price ID…

hi.events | Remote | Authorization
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
9.1 CRITICAL
CVE-2026-60082 — DBI versions before 1.651 for Perl do not enforce statement handle consistency with the r…

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper …

dbi | Remote | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-60081 — DBI::ProfileData versions before 1.651 for Perl do not limit the path index

DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allow…

dbi | Remote | Denial of Service
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-59841 — Fortinet FortiSIEMWindowsAgent Improper Restriction of Communication Channel Vulnerability

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert att…

Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
4.3 MEDIUM
CVE-2026-59840 — Fortinet FortiOS and FortiProxy Buffer Over-read Vulnerability

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 t…

fortios fortiswitchmanager fortiproxy fortios fortipam | Remote | Memory Corruption
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
5.5 MEDIUM
CVE-2026-59839 — Fortinet Path Traversal Vulnerability

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS …

fortios fortiproxy fortios fortipam | Path Traversal
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
Showing 20 of 10874 Results