Common Vulnerabilities and Exposures (CVE)

CVE-2026-15802

Jul 22, 2026 03:44:59 UTC

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possib...

CVE-2026-16492

Jul 22, 2026 00:45:11 UTC

A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the component GIT File Helper. This manipulation causes os command injec...

CVE-2026-56844

Jul 22, 2026 00:44:32 UTC

A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.

CVE-2026-16490

Jul 22, 2026 00:15:08 UTC

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /prescription.php. The manipulation of the argument editid results in sql injection. The attack can be executed ...

CVE-2026-16517

Jul 22, 2026 00:05:29 UTC

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addi...

CVE-2026-16489

Jul 21, 2026 23:30:09 UTC

A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack ...

CVE-2026-16488

Jul 21, 2026 23:15:10 UTC

A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os comman...

CVE-2026-63263

Jul 21, 2026 23:10:49 UTC

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CP...

CVE-2026-63262

Jul 21, 2026 23:07:18 UTC

Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.

CVE-2026-63261

Jul 21, 2026 22:58:45 UTC

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing...

CVE-2026-63260

Jul 21, 2026 22:53:44 UTC

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a s...

CVE-2026-16486

Jul 21, 2026 22:45:09 UTC

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiate...

CVE-2026-63259

Jul 21, 2026 22:37:09 UTC

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.

CVE-2026-47304

Jul 21, 2026 22:37:01 UTC

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-50462

Jul 21, 2026 22:37:00 UTC

External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.