Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-12707 — Unbounded path event queue growth in quiche via peer-driven source connection ID rotation

Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connect…

quiche | Remote | Denial of Service
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-12659 — Rockwell Automation Flex 5000® Adapter - Denial of Service

A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. …

Remote | Denial of Service
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.5 HIGH
CVE-2026-12523 — Resource exhaustion in quiche HTTP/3 and QPACK layers

Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple fr…

quiche | Remote | Denial of Service
Jul 14, 2026 Aug 06, 2026
Jul 14, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-11944 — openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download

openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary …

linux_kernel macos windows opensis opensis-classic | Remote | Path Traversal
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.2 HIGH
CVE-2026-11917 — ThinManager® - Path Traversal via API

A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this…

thinmanager | Remote | Path Traversal
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-11403 — Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation

A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format…

nexus_repository_manager | Remote | Authentication
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
4.3 MEDIUM
CVE-2025-62826 — Fortinet FortiOS and FortiProxy HTTP Response Splitting Vulnerability

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, Forti…

fortios fortiproxy fortios fortipam | Remote | Injection
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
4.3 MEDIUM
CVE-2025-62675 — Fortinet FortiOS and FortiProxy HTTP Response Splitting Vulnerability

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, Forti…

fortios fortiproxy fortios fortipam | Remote | Injection
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
7.5 HIGH
CVE-2025-53379 — Fortinet FortiAuthenticator Out-of-Bounds Read Vulnerability

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive informatio…

fortiauthenticator | Remote | Information Disclosure
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
4.3 MEDIUM
CVE-2025-43892 — Fortinet FortiOS Buffer Over-read Vulnerability

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authen…

fortios fortiproxy fortios | Remote | Memory Corruption
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
9.2 CRITICAL
CVE-2025-11698 — CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow

A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the co…

Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-9653 — 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID

A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exp…

1756-enbt | Remote | Denial of Service
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-9140 — 1718-AENTR/1719-AENTR - Denial of Service

A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose comm…

Remote | Denial of Service
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-8590 — Spotfire OAuth2 PKCE Bypass for public clients

Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Serv…

Remote | Authentication
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
8.7 HIGH
CVE-2026-60114 — Sustainable Irrigation Platform 5.2.16 Path Traversal via JSON Backup Restore

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locatio…

sustainable_irrigation_platform | Remote | Path Traversal
Jul 14, 2026 Jul 16, 2026
Jul 14, 2026
Jul 16, 2026
9.8 CRITICAL
CVE-2026-58479 — Sustainable Irrigation Platform 5.2.16 RCE via cli_control Plugin Command Injection

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery at…

sustainable_irrigation_platform | Remote | Injection
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
6.5 MEDIUM
CVE-2026-58478 — Sustainable Irrigation Platform 5.2.16 SSRF via Node-RED Callback URL

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP …

sustainable_irrigation_platform | Remote | Server-Side Request Forgery
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
8.8 HIGH
CVE-2026-58477 — Sustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying …

sustainable_irrigation_platform | Remote | Misconfiguration
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.1 HIGH
CVE-2026-58476 — Sustainable Irrigation Platform 5.2.16 CSRF via Administrative GET Requests

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by lurin…

sustainable_irrigation_platform | Remote | Cross-Site Request Forgery
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
6.1 MEDIUM
CVE-2026-58475 — Sustainable Irrigation Platform 5.2.16 Stored XSS via Program Name

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by supplying mal…

sustainable_irrigation_platform | Remote | Cross-Site Scripting
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
Showing 20 of 10874 Results