Latest Vulnerabilities

Latest CVEs with CVSS, KEV, EPSS, and public PoC indicators. Filter by severity, vendor, exploit availability. Updated hourly.

CVE-2026-62825 CRITICAL · 10.0

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

· 2026-07-24

CVE-2026-58275 CRITICAL · 10.0

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

· 2026-07-24

CVE-2026-56191 CRITICAL · 10.0

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

· 2026-07-24

CVE-2026-56167 HIGH · 8.5

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

· 2026-07-24

CVE-2026-56165 CRITICAL · 9.8

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

· 2026-07-24

CVE-2026-56160 CRITICAL · 9.1

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

· 2026-07-24

CVE-2026-54120 CRITICAL · 9.9

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

· 2026-07-24

CVE-2026-50517 CRITICAL · 9.9

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

· 2026-07-24

CVE-2026-49159 MEDIUM · 6.5

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

· 2026-07-24

CVE-2026-35425 HIGH · 8.0

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

· 2026-07-24

CVE-2026-50044 MEDIUM · 6.8

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.

· 2026-07-23

CVE-2026-44955 MEDIUM · 5.3

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.

· 2026-07-23

CVE-2026-42933 CRITICAL · 10.0

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

· 2026-07-23

CVE-2026-40430 HIGH · 7.5

Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.

· 2026-07-23

CVE-2026-28698 HIGH · 8.6

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.

· 2026-07-23

CVE-2026-16767 MEDIUM · 6.5

A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performing a manipulation of the argument entryName results in path traversal. It is possible to initiate the attack

· 2026-07-23

CVE-2026-65694 HIGH · 7.5

Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthentic

· 2026-07-23

CVE-2026-65604 HIGH · 8.2

Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OP

· 2026-07-23

CVE-2026-63732 CRITICAL · 9.9

9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when

· 2026-07-23

CVE-2026-63313 HIGH · 7.7

9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina Reader, Tavily, or Exa) to fetch content

· 2026-07-23

CVE-2026-16807

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

· 2026-07-23

CVE-2026-16806

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

· 2026-07-23

CVE-2026-16805

Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

· 2026-07-23

CVE-2026-16804

Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

· 2026-07-23

CVE-2026-16765 HIGH · 7.3

A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lead to sql injection. The attack can be executed remotely. The

· 2026-07-23

CVE-2026-16764 MEDIUM · 6.3

A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performe

· 2026-07-23

CVE-2026-16763 MEDIUM · 5.3

A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command

· 2026-07-23

CVE-2025-71389 CRITICAL · 10.0

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to th

· 2026-07-23

CVE-2024-58355 HIGH · 8.9

Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) renders booking-question field labels via React's dangerouslySetInnerHTML without sanitizing or escaping user inp

· 2026-07-23

CVE-2024-58354 CRITICAL · 9.9

cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to check-types.yml.

· 2026-07-23

CVE-2024-58353 HIGH · 8.9

Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). Booking question (form field) labels are rendered via React's dangerouslySetInnerHTML without proper input s

· 2026-07-23

CVE-2026-6924

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.

· 2026-07-23

CVE-2026-52439

An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism

· 2026-07-23

CVE-2026-50103 MEDIUM · 6.5

A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.

· 2026-07-23

CVE-2026-50039 HIGH · 7.5

The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a Read Request.

· 2026-07-23

CVE-2026-50032 HIGH · 7.5

A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.

· 2026-07-23

CVE-2026-49035 HIGH · 8.1

The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.

· 2026-07-23

CVE-2026-47724 CRITICAL · 9.9

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits this at `internal/api/hosts.go:384`: "API

· 2026-07-23

CVE-2026-47723

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal/api/` set the standard browser-security headers. `grep` for `Content-Security-Policy`, `X-Frame-Options`, `

· 2026-07-23

CVE-2026-39155

Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative c

· 2026-07-23

CVE-2026-38764

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

· 2026-07-23

CVE-2026-34496

Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.

· 2026-07-23

CVE-2026-21655

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.

· 2026-07-23

CVE-2026-21653

Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.

· 2026-07-23

CVE-2026-16796 HIGH · 7.3

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mi

· 2026-07-23

CVE-2026-16002 HIGH · 8.2

The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service.

· 2026-07-23

CVE-2026-15981 CRITICAL · 9.8

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's op

· 2026-07-23

CVE-2026-15968 HIGH · 7.1

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

· 2026-07-23

CVE-2026-15967 HIGH · 7.5

Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

· 2026-07-23

CVE-2026-15966 HIGH · 7.5

Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

· 2026-07-23

CVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

· 2026-07-23

CVE-2026-10697 HIGH · 7.5

Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

· 2026-07-23

CVE-2026-65706 HIGH · 7.8

FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer

· 2026-07-23

CVE-2026-65705 HIGH · 7.8

FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_

· 2026-07-23

CVE-2026-65704 HIGH · 7.8

FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producin

· 2026-07-23

CVE-2026-65703 HIGH · 7.8

FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to

· 2026-07-23

CVE-2026-64785

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in sw

· 2026-07-23

CVE-2026-63359 CRITICAL · 9.8

The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and du

· 2026-07-23

CVE-2026-60122 HIGH · 7.8

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is

· 2026-07-23

CVE-2026-48013 MEDIUM · 4.1

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the parallel `uploadFromURL` flow validates ta

· 2026-07-23

Vulnerabilities

CVE intelligence feed with real-time Twitter updates

CVEs (30d)

-

In KEV

-

Critical

-

Vendors:
Filters:

Loading vulnerability data...