Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-23573 — Fortinet FortiOS, FortiPAM, and FortiProxy Cross-Site Scripting Vulnerability

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS…

fortios fortiproxy fortios fortipam | Remote | Cross-Site Scripting
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-15699 — spencermountain compromise Public Root API extend.js nlp.extend prototype pollution

A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. The manipulation of the…

compromise | Remote | Misconfiguration
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
6.5 MEDIUM
CVE-2026-15698 — kofrasa mingo Update API updateMany prototype pollution

A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of the component Update API. Executing a manipulation of the argument Set can lead t…

mingo | Remote | Misconfiguration
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
6.5 MEDIUM
CVE-2026-15697 — svgdotjs svg.js npm Package API EventTarget.on prototype pollution

A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. Performing a manipulation results in i…

svg.js | Remote | Misconfiguration
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.7 HIGH
CVE-2026-15392 — DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to…

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking w…

dbi | Path Traversal
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
8.2 HIGH
CVE-2026-14504 — Nexus Repository 3 - Authorization Bypass in Component Upload API

An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, b…

nexus_repository_manager | Remote | Authorization
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
7.5 HIGH
CVE-2026-12707 — Unbounded path event queue growth in quiche via peer-driven source connection ID rotation

Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connect…

quiche | Remote | Denial of Service
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-12659 — Rockwell Automation Flex 5000® Adapter - Denial of Service

A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. …

Remote | Denial of Service
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.5 HIGH
CVE-2026-12523 — Resource exhaustion in quiche HTTP/3 and QPACK layers

Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple fr…

quiche | Remote | Denial of Service
Jul 14, 2026 Aug 06, 2026
Jul 14, 2026
Aug 06, 2026
6.5 MEDIUM
CVE-2026-11944 — openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download

openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary …

linux_kernel macos windows opensis opensis-classic | Remote | Path Traversal
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
7.2 HIGH
CVE-2026-11917 — ThinManager® - Path Traversal via API

A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this…

thinmanager | Remote | Path Traversal
Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
8.7 HIGH
CVE-2026-11403 — Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation

A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format…

nexus_repository_manager | Remote | Authentication
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
4.3 MEDIUM
CVE-2025-62826 — Fortinet FortiOS and FortiProxy HTTP Response Splitting Vulnerability

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, Forti…

fortios fortiproxy fortios fortipam | Remote | Injection
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
4.3 MEDIUM
CVE-2025-62675 — Fortinet FortiOS and FortiProxy HTTP Response Splitting Vulnerability

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, Forti…

fortios fortiproxy fortios fortipam | Remote | Injection
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
7.5 HIGH
CVE-2025-53379 — Fortinet FortiAuthenticator Out-of-Bounds Read Vulnerability

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive informatio…

fortiauthenticator | Remote | Information Disclosure
Jul 14, 2026 Jul 15, 2026
Jul 14, 2026
Jul 15, 2026
4.3 MEDIUM
CVE-2025-43892 — Fortinet FortiOS Buffer Over-read Vulnerability

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authen…

fortios fortiproxy fortios | Remote | Memory Corruption
Jul 14, 2026 Aug 11, 2026
Jul 14, 2026
Aug 11, 2026
9.2 CRITICAL
CVE-2025-11698 — CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow

A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the co…

Jul 14, 2026 Jul 14, 2026
Jul 14, 2026
Jul 14, 2026
Showing 20 of 11257 Results