Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52113
Total
4140
Critical
15446
High
15158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-56349 | UNKNOWN | — | n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instructions. End users can craft … | Jul 15, 2026 |
| CVE-2026-56339 | HIGH | 7.5 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization … | Jul 15, 2026 |
| CVE-2026-59235 | UNKNOWN | — | Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Prospero Flow CRM <5.5.3, which allows a remote, authenticated attacker holding a low-privileged role … | Jul 15, 2026 |
| CVE-2026-40633 | HIGH | 7.8 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker … | Jul 15, 2026 |
| CVE-2026-8281 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 15, 2026 |
| CVE-2026-58077 | UNKNOWN | — | The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances. | Jul 15, 2026 |
| CVE-2026-57833 | UNKNOWN | — | The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relation to the AI analysis feature. | Jul 15, 2026 |
| CVE-2026-57821 | HIGH | 8.1 | A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is … | Jul 15, 2026 |
| CVE-2026-56287 | HIGH | 8.1 | A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder … | Jul 15, 2026 |
| CVE-2026-49501 | MEDIUM | 6.7 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access … | Jul 15, 2026 |
| CVE-2026-35152 | HIGH | 8.8 | A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated … | Jul 15, 2026 |
| CVE-2026-57832 | UNKNOWN | — | The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection. | Jul 15, 2026 |
| CVE-2026-57831 | UNKNOWN | — | The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection. | Jul 15, 2026 |
| CVE-2026-15804 | HIGH | 8.8 | The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the confidentiality, integrity, … | Jul 15, 2026 |
| CVE-2026-15583 | HIGH | 8.6 | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL … | Jul 15, 2026 |
| CVE-2026-14251 | HIGH | 7.7 | A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD … | Jul 15, 2026 |
| CVE-2026-42936 | HIGH | 7.8 | The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected … | Jul 15, 2026 |
| CVE-2026-12512 | HIGH | 8.6 | The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated … | Jul 15, 2026 |
| CVE-2026-12281 | HIGH | 8.1 | The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request … | Jul 15, 2026 |
| CVE-2026-11580 | MEDIUM | 5.5 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, … | Jul 15, 2026 |
| CVE-2026-11579 | MEDIUM | 5.3 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing … | Jul 15, 2026 |
| CVE-2026-8920 | UNKNOWN | — | Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to … | Jul 15, 2026 |
| CVE-2026-8919 | UNKNOWN | — | Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user … | Jul 15, 2026 |
| CVE-2026-15030 | UNKNOWN | — | Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond … | Jul 15, 2026 |
| CVE-2026-15029 | UNKNOWN | — | Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical … | Jul 15, 2026 |