#
356 Zafiyet
2026-07-30
CVE-2026-39155
CVE-2026-39155 - Knot DNS mod-onlinesign Authenticated Denial of Service Vulnerability
General
3.1 (MEDIUM)
2026-07-30
CVE-2026-47723
CVE-2026-47723 - nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
General
4.0 (HIGH)
2026-07-30
CVE-2026-47724
CVE-2026-47724 - nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation
General
3.1 (CRITICAL)
2026-07-29
CVE-2026-49035
CVE-2026-49035 - Stack-based Buffer Overflow in MZ Automation libIEC61850
General
4.0 (CRITICAL)
2026-07-29
CVE-2026-50032
CVE-2026-50032 - NULL Pointer Dereference in MZ Automation libIEC61850
General
4.0 (HIGH)
2026-07-29
CVE-2026-50039
CVE-2026-50039 - Stack-based Buffer Overflow in MZ Automation libIEC61850
General
4.0 (HIGH)
2026-07-29
CVE-2026-50103
CVE-2026-50103 - Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
General
4.0 (HIGH)
2026-07-29
CVE-2026-52439
CVE-2026-52439 - Beetl Remote Code Execution Vulnerability
General
3.1 (CRITICAL)
2026-07-29
CVE-2026-6924
CVE-2026-6924 - Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path
General
4.0 (HIGH)
2026-07-29
CVE-2026-65694
CVE-2026-65694 - Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
General
4.0 (HIGH)
2026-07-29
CVE-2026-16764
CVE-2026-16764 - OWASP DefectDojo API/Web serializers.py UserSerializer privileges management
General
2.0 (MEDIUM)
2026-07-29
CVE-2026-64785
CVE-2026-64785 - SwiftNIO HTTP/2 Improper Input Validation HTTP Request Smuggling
General
3.1 (MEDIUM)
2026-07-29
CVE-2026-65703
CVE-2026-65703 - FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder
General
4.0 (HIGH)
2026-07-29
CVE-2026-65704
CVE-2026-65704 - FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder
General
3.1 (HIGH)
2026-07-29
CVE-2026-65705
CVE-2026-65705 - FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame()
General
3.1 (HIGH)
2026-07-29
CVE-2026-65706
CVE-2026-65706 - FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing
General
4.0 (HIGH)
2026-07-29
CVE-2026-25800
CVE-2026-25800 - quinn-proto has remote memory exhaustion from unbounded out-of-order stream reassembly
General
3.1 (HIGH)
2026-07-29
CVE-2026-12353
CVE-2026-12353 - Rhcs: memory leak during https connection leads to denial of service
General
3.1 (MEDIUM)
2026-07-29
CVE-2026-47670
CVE-2026-47670 - DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
General
4.0 (CRITICAL)
2026-07-29
CVE-2026-47669
CVE-2026-47669 - DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE
General
4.0 (CRITICAL)
2026-07-29
CVE-2026-48013
CVE-2026-48013 - Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation
General
3.1 (MEDIUM)
2026-07-29
CVE-2026-15687
CVE-2026-15687 - Path traversal via non-tar copyDirectoryFromPod
General
3.0 (LOW)
2026-07-29
CVE-2026-16756
CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
General
4.0 (HIGH)
2026-07-29
CVE-2026-63765
CVE-2026-63765 - Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation
General
4.0 (CRITICAL)
No matching CVEs found with current filter options.