Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-60118 — Hi.Events < 1.11.0 Hidden Ticket Enumeration via Order Creation Endpoint

Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price ID…

hi.events | Remote | Authorization
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
9.1 CRITICAL
CVE-2026-60082 — DBI versions before 1.651 for Perl do not enforce statement handle consistency with the r…

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper …

dbi | Remote | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-60081 — DBI::ProfileData versions before 1.651 for Perl do not limit the path index

DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allow…

dbi | Remote | Denial of Service
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-59841 — Fortinet FortiSIEMWindowsAgent Improper Restriction of Communication Channel Vulnerability

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert att…

Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
4.3 MEDIUM
CVE-2026-59840 — Fortinet FortiOS and FortiProxy Buffer Over-read Vulnerability

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 t…

fortios fortiswitchmanager fortiproxy fortios fortipam | Remote | Memory Corruption
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
5.5 MEDIUM
CVE-2026-59839 — Fortinet Path Traversal Vulnerability

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS …

fortios fortiproxy fortios fortipam | Path Traversal
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
6.6 MEDIUM
CVE-2026-59837 — Fortinet FortiOS, FortiPAM, and FortiProxy Stack-Based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, Fort…

fortios fortiproxy fortios fortipam fortisase | Remote | Memory Corruption
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
9.8 CRITICAL
CVE-2026-59836 — Fortinet FortiClientEMS Improper Certificate Validation Information Disclosure

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information d…

forticlientems | Remote | Cryptography
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
8.6 HIGH
CVE-2026-59835 — Fortinet FortiSandbox Exposure of Resource to Wrong Sphere Vulnerability

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of V…

fortisandbox fortisandbox | Remote | Misconfiguration
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-59205 — Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mod…

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image wh…

pillow | Remote | Memory Corruption
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-59204 — Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial …

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile…

pillow | Remote | Denial of Service
Jul 14, 2026 Jul 21, 2026
Jul 14, 2026
Jul 21, 2026
7.5 HIGH
CVE-2026-59203 — Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of se…

Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file …

pillow | Remote | Denial of Service
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-59199 — Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate o…

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in …

pillow | Remote | Memory Corruption
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-59198 — Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated im…

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process h…

pillow | Remote | Memory Corruption
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
9.1 CRITICAL
CVE-2026-55954 — Missing ID token claim validation in ueberauth_apple allows account takeover

Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.Strategy.Apple.Token.payload/2 function verifies t…

ueberauth_apple | Remote | Authentication
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.1 HIGH
CVE-2026-55651 — Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure

Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointmen…

easy\!appointments | Remote | Information Disclosure
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
3.1 LOW
CVE-2026-52841 — Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend…

Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session,…

easy\!appointments | Remote | Authorization
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
2.7 LOW
CVE-2026-52840 — Easy!Appointments has server-side request forgery in CalDAV connection test that exposes …

Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzz…

easy\!appointments | Remote | Server-Side Request Forgery
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
3.3 LOW
CVE-2026-52839 — Easy!Appointments appointments/store and appointments/update allow cross-provider appoint…

Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation …

easy\!appointments | Remote | Authorization
Jul 14, 2026 Jul 29, 2026
Jul 14, 2026
Jul 29, 2026
2.6 LOW
CVE-2026-52838 — Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — S…

Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is s…

easy\!appointments | Remote | Cross-Site Scripting
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
Showing 20 of 11257 Results