Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51943
Total
4127
Critical
15407
High
15098
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48009 | MEDIUM | 6.8 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by … | Jul 17, 2026 |
| CVE-2026-48008 | MEDIUM | 6.5 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by … | Jul 17, 2026 |
| CVE-2025-59866 | LOW | 3.3 | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to … | Jul 17, 2026 |
| CVE-2026-9588 | UNKNOWN | — | A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to … | Jul 17, 2026 |
| CVE-2026-9587 | UNKNOWN | — | An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and … | Jul 17, 2026 |
| CVE-2026-9586 | UNKNOWN | — | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates … | Jul 17, 2026 |
| CVE-2026-9585 | UNKNOWN | — | An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter … | Jul 17, 2026 |
| CVE-2026-8297 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab … | Jul 17, 2026 |
| CVE-2026-63309 | MEDIUM | 4.3 | SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to leak the relative ordering of restricted field values. … | Jul 17, 2026 |
| CVE-2026-63308 | MEDIUM | 4.3 | Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template helper in pkg/engine/files.go that allows attackers to trigger … | Jul 17, 2026 |
| CVE-2026-63307 | MEDIUM | 6.5 | Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{id} endpoint. The handler calls dataSourceService.queryExistent(id, ...) without an ownership check and … | Jul 17, 2026 |
| CVE-2026-63101 | HIGH | 7.5 | Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email … | Jul 17, 2026 |
| CVE-2026-57860 | HIGH | 7.8 | ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without user confirmation. A … | Jul 17, 2026 |
| CVE-2026-54496 | CRITICAL | 9.3 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar … | Jul 17, 2026 |
| CVE-2026-49216 | UNKNOWN | — | Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _createAutocompleteWithRemoteData() … | Jul 17, 2026 |
| CVE-2026-49215 | UNKNOWN | — | Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventListener\LiveComponentSubscriber::isLiveComponentRequest() gates #[LiveAction] invocations on Accept: application/vnd.live-component+html, but the Accept header … | Jul 17, 2026 |
| CVE-2026-49212 | UNKNOWN | — | Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop key/value pairs … | Jul 17, 2026 |
| CVE-2026-49211 | UNKNOWN | — | Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\EntitySearchUtil::addSearchClause() builds the LIKE expression used by the autocomplete endpoint by … | Jul 17, 2026 |
| CVE-2026-49210 | UNKNOWN | — | Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubscriber and InterceptChildComponentRenderSubscriber directly … | Jul 17, 2026 |
| CVE-2026-49209 | UNKNOWN | — | Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full … | Jul 17, 2026 |
| CVE-2026-49208 | UNKNOWN | — | Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format … | Jul 17, 2026 |
| CVE-2026-44722 | MEDIUM | 6.2 | pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in … | Jul 17, 2026 |
| CVE-2026-21764 | LOW | 3.1 | HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior … | Jul 17, 2026 |
| CVE-2026-21762 | LOW | 3.7 | HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type … | Jul 17, 2026 |
| CVE-2026-21761 | MEDIUM | 4.2 | HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to … | Jul 17, 2026 |