Common Vulnerabilities and Exposures (CVE)

CVE-2026-66139

Jul 24, 2026 23:22:06 UTC

OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

CVE-2026-66138

Jul 24, 2026 23:22:05 UTC

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server ...

CVE-2026-66337

Jul 24, 2026 23:01:20 UTC

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a cra...

CVE-2026-66338

Jul 24, 2026 23:01:20 UTC

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid cha...

CVE-2026-66339

Jul 24, 2026 23:01:15 UTC

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allo...

CVE-2026-15786

Jul 24, 2026 22:39:47 UTC

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. T...

CVE-2026-60134

Jul 24, 2026 22:20:20 UTC

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

CVE-2026-61892

Jul 24, 2026 22:16:58 UTC

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

CVE-2026-15648

Jul 24, 2026 22:10:51 UTC

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes ...

CVE-2026-15420

Jul 24, 2026 22:10:12 UTC

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenti...

CVE-2026-61886

Jul 24, 2026 22:10:03 UTC

Weintek cMT3092X HMI stores user account passwords in plaintext.

CVE-2026-56191

Jul 24, 2026 22:09:12 UTC

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

CVE-2026-49159

Jul 24, 2026 22:08:25 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

CVE-2025-71389

Jul 24, 2026 22:07:11 UTC

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attac...

CVE-2026-60135

Jul 24, 2026 22:06:12 UTC

An attacker can modify data that should be restricted to read‑only access.