Common Vulnerabilities and Exposures (CVE)

CVE-2026-16489

Jul 21, 2026 23:30:09 UTC

A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack ...

CVE-2026-16488

Jul 21, 2026 23:15:10 UTC

A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os comman...

CVE-2026-63263

Jul 21, 2026 23:10:49 UTC

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CP...

CVE-2026-63262

Jul 21, 2026 23:07:18 UTC

Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.

CVE-2026-63261

Jul 21, 2026 22:58:45 UTC

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing...

CVE-2026-63260

Jul 21, 2026 22:53:44 UTC

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a s...

CVE-2026-16486

Jul 21, 2026 22:45:09 UTC

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiate...

CVE-2026-16517

Jul 21, 2026 22:41:38 UTC

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addi...

CVE-2026-63259

Jul 21, 2026 22:37:09 UTC

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.

CVE-2026-47304

Jul 21, 2026 22:37:01 UTC

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-50462

Jul 21, 2026 22:37:00 UTC

External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-58640

Jul 21, 2026 22:37:00 UTC

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-57980

Jul 21, 2026 22:36:59 UTC

Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

CVE-2026-56171

Jul 21, 2026 22:36:59 UTC

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58529

Jul 21, 2026 22:36:58 UTC

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.