Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51713
Total
4098
Critical
15342
High
14990
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-64821 | MEDIUM | 4.3 | djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated attackers to cancel sales or purchase orders on behalf of authenticated … | Jul 21, 2026 |
| CVE-2026-63764 | CRITICAL | 9.3 | lmdeploy's OpenAI-compatible API server contains a server-side request forgery vulnerability that allows unauthenticated attackers to access internal services and cloud metadata endpoints by supplying a … | Jul 21, 2026 |
| CVE-2026-63358 | HIGH | 7.3 | FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to PHP's native 'chmod()' function through 'octdec()' conversion, with … | Jul 21, 2026 |
| CVE-2026-63140 | MEDIUM | 6.5 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value … | Jul 21, 2026 |
| CVE-2026-63139 | MEDIUM | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource … | Jul 21, 2026 |
| CVE-2026-63136 | MEDIUM | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially … | Jul 21, 2026 |
| CVE-2026-63092 | MEDIUM | 4.3 | kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial … | Jul 21, 2026 |
| CVE-2026-63080 | MEDIUM | 6.5 | Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authenticated attackers to read event data across all tenants … | Jul 21, 2026 |
| CVE-2026-56147 | HIGH | 7.1 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency … | Jul 21, 2026 |
| CVE-2026-52476 | UNKNOWN | — | SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPageData method in the DatacenterQuery.java file | Jul 21, 2026 |
| CVE-2026-52475 | UNKNOWN | — | Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the UploadController.java file | Jul 21, 2026 |
| CVE-2026-52474 | UNKNOWN | — | An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file. | Jul 21, 2026 |
| CVE-2026-52472 | UNKNOWN | — | SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml file | Jul 21, 2026 |
| CVE-2026-52470 | UNKNOWN | — | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file | Jul 21, 2026 |
| CVE-2026-52469 | UNKNOWN | — | SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file | Jul 21, 2026 |
| CVE-2026-47714 | MEDIUM | 6.1 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an … | Jul 21, 2026 |
| CVE-2026-47708 | UNKNOWN | — | MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and … | Jul 21, 2026 |
| CVE-2026-47697 | HIGH | 7.1 | Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). Prior to version 1.20.2, several endpoints accepted entity … | Jul 21, 2026 |
| CVE-2026-47695 | UNKNOWN | — | CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.119.0, CC-Tweaked's HTTP API (`http.request`, … | Jul 21, 2026 |
| CVE-2026-47690 | HIGH | 7.5 | MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration … | Jul 21, 2026 |
| CVE-2026-47689 | MEDIUM | 4.6 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data values into HTML … | Jul 21, 2026 |
| CVE-2026-47688 | HIGH | 8.2 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked … | Jul 21, 2026 |
| CVE-2026-47687 | HIGH | 7.3 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<option>` labels using raw, … | Jul 21, 2026 |
| CVE-2026-47685 | HIGH | 7.3 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the unauthenticated inventory service endpoint (`/service/inventory.php`) persists client-supplied values without … | Jul 21, 2026 |
| CVE-2026-47237 | HIGH | 8.0 | Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests … | Jul 21, 2026 |