CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2026-59538

    Last Modified: 27 Jul 2026

    Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.

    Published: 27 Jul 2026
    7.6
    High

    CVE-2026-59537

    Last Modified: 27 Jul 2026

    Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.

    Published: 27 Jul 2026
    7.5
    High

    CVE-2026-59536

    Last Modified: 27 Jul 2026

    Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.

    Published: 27 Jul 2026
    7.3
    High

    CVE-2026-59535

    Last Modified: 27 Jul 2026

    Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.

    Published: 27 Jul 2026
    7.5
    High

    CVE-2026-59534

    Last Modified: 27 Jul 2026

    Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.

    Published: 27 Jul 2026
    9.3
    Critical

    CVE-2026-59533

    Last Modified: 27 Jul 2026

    Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.

    Published: 27 Jul 2026
    7.5
    High

    CVE-2026-59532

    Last Modified: 28 Jul 2026

    Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.

    Published: 27 Jul 2026
    7.5
    High

    CVE-2026-59531

    Last Modified: 27 Jul 2026

    Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.

    Published: 27 Jul 2026
    7.5
    High

    CVE-2026-59530

    Last Modified: 27 Jul 2026

    Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.

    Published: 27 Jul 2026
    7.5
    High

    CVE-2026-59529

    Last Modified: 27 Jul 2026

    Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.

    Published: 27 Jul 2026
    7.5
    High

    CVE-2026-59528

    Last Modified: 27 Jul 2026

    Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

    Published: 27 Jul 2026
    9.3
    Critical

    CVE-2026-59527

    Last Modified: 27 Jul 2026

    Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

    Published: 27 Jul 2026
    1.9
    Low

    CVE-2026-17514

    Last Modified: 27 Jul 2026

    A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 27 Jul 2026
    5.6
    Medium

    CVE-2026-15003

    Last Modified: 28 Jul 2026

    A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.

    Published: 27 Jul 2026
    9.2
    Critical

    CVE-2026-65876

    Last Modified: 12 Aug 2026

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of catid parameters in the loadMoreArticles endpoint leads to an SQL injection vector.

    Published: 27 Jul 2026
    8.2
    High

    CVE-2026-65877

    Last Modified: 27 Jul 2026

    Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.

    Published: 27 Jul 2026
    9.8
    Critical

    CVE-2026-65879

    Last Modified: 3 Aug 2026

    Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

    Published: 27 Jul 2026
    9.2
    Critical

    CVE-2026-65766

    Last Modified: 27 Jul 2026

    Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint leads to an SQL injection vector.

    Published: 27 Jul 2026
    8.3
    High

    CVE-2026-65878

    Last Modified: 27 Jul 2026

    Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.

    Published: 27 Jul 2026
    1.9
    Low

    CVE-2026-17513

    Last Modified: 27 Jul 2026

    A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in reachable assertion. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 27 Jul 2026
    9.3
    Critical

    CVE-2026-61511

    Last Modified: 29 Jul 2026

    vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.

    Published: 27 Jul 2026
    1.9
    Low

    CVE-2026-17512

    Last Modified: 27 Jul 2026

    A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The pull request to fix this issue awaits acceptance.

    Published: 27 Jul 2026
    8
    High

    CVE-2026-59690

    Last Modified: 11 Aug 2026

    A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.

    Published: 27 Jul 2026
    8
    High

    CVE-2026-59689

    Last Modified: 11 Aug 2026

    An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.

    Published: 27 Jul 2026
    8.4
    High

    CVE-2026-59688

    Last Modified: 11 Aug 2026

    An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.

    Published: 27 Jul 2026
    8.4
    High

    CVE-2026-59687

    Last Modified: 11 Aug 2026

    An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.

    Published: 27 Jul 2026
    8.4
    High

    CVE-2026-59686

    Last Modified: 11 Aug 2026

    An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.

    Published: 27 Jul 2026
    3.5
    Low

    CVE-2026-56538

    Last Modified: 20 Aug 2026

    An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.

    Published: 27 Jul 2026
    3.5
    Low

    CVE-2026-56537

    Last Modified: 20 Aug 2026

    HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.

    Published: 27 Jul 2026
    8.7
    High

    CVE-2026-12991

    Last Modified: 27 Jul 2026

    The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and manipulate packets between the legitimate operator and the robot. This allows the attacker to disconnect the original controller, establish unauthorized communications, and prevent the operator from regaining control of the device, seriously compromising the confidentiality, integrity, and availability (CIA) of operations.

    Published: 27 Jul 2026
    7.7
    High

    CVE-2026-12990

    Last Modified: 27 Jul 2026

    An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session. This allows the attacker to bypass control restrictions, intercept sensitive information (such as real-time video), and partially interact with the system unnoticed and without disconnecting the legitimate user, compromising confidentiality and operational security.

    Published: 27 Jul 2026
    8.7
    High

    CVE-2026-12989

    Last Modified: 27 Jul 2026

    A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can view real-time camera feeds, control the robot’s movements, manage sensors (GPS, RTK, SAM, LIDAR), and execute critical operational commands (Play, Pause, Stop, E-Stop). Successful exploitation completely compromises the confidentiality, integrity, and physical security of the system.

    Published: 27 Jul 2026
    5.9
    Medium

    CVE-2026-66053

    Last Modified: 27 Jul 2026

    Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

    Published: 27 Jul 2026
    8.7
    High

    CVE-2026-58662

    Last Modified: 27 Jul 2026

    Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    8.7
    High

    CVE-2026-58389

    Last Modified: 27 Jul 2026

    Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    6.9
    Medium

    CVE-2026-58023

    Last Modified: 27 Jul 2026

    Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    9.3
    Critical

    CVE-2026-55971

    Last Modified: 30 Jul 2026

    Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    6.9
    Medium

    CVE-2026-55970

    Last Modified: 27 Jul 2026

    Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    8.7
    High

    CVE-2026-55969

    Last Modified: 27 Jul 2026

    Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    8.7
    High

    CVE-2026-55968

    Last Modified: 27 Jul 2026

    Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    7.5
    High

    CVE-2026-49158

    Last Modified: 27 Jul 2026

    Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    8.7
    High

    CVE-2026-48586

    Last Modified: 27 Jul 2026

    Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    8.2
    High

    CVE-2026-48145

    Last Modified: 3 Aug 2026

    Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    9.1
    Critical

    CVE-2026-48144

    Last Modified: 27 Jul 2026

    Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    6.9
    Medium

    CVE-2026-45112

    Last Modified: 27 Jul 2026

    Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    8.7
    High

    CVE-2026-43871

    Last Modified: 4 Aug 2026

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    7.5
    High

    CVE-2026-41608

    Last Modified: 28 Jul 2026

    Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

    Published: 27 Jul 2026
    5.3
    Medium

    CVE-2026-12495

    Last Modified: 28 Jul 2026

    Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.

    Published: 27 Jul 2026
    4.8
    Medium

    CVE-2026-57917

    Last Modified: 27 Jul 2026

    proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”. This issue was fixed in version 9.4.3.90.

    Published: 27 Jul 2026
    4.6
    Medium

    CVE-2026-57916

    Last Modified: 27 Jul 2026

    proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened). This issue was fixed in version 9.4.3.90.

    Published: 27 Jul 2026