Common Vulnerabilities and Exposures (CVE)

CVE-2026-63730

Jul 21, 2026 11:08:18 UTC

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by supplying a caller-controlled URL to the w...

CVE-2026-63102

Jul 21, 2026 11:08:17 UTC

rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile u...

CVE-2026-63091

Jul 21, 2026 11:08:17 UTC

ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UI...

CVE-2026-63090

Jul 21, 2026 11:08:16 UTC

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments ex...

CVE-2026-57852

Jul 21, 2026 11:08:15 UTC

Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. At...

CVE-2026-1617

Jul 21, 2026 11:07:22 UTC

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This issue affects Turkhotspot 5651 Loglama: from 5.1...

CVE-2026-15588

Jul 21, 2026 11:06:15 UTC

A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated ...

CVE-2026-60080

Jul 21, 2026 10:54:19 UTC

Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure....

CVE-2026-64606

Jul 21, 2026 10:43:51 UTC

Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users ar...

CVE-2026-22104

Jul 21, 2026 09:51:24 UTC

Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.

CVE-2026-64609

Jul 21, 2026 09:34:57 UTC

Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature;...

CVE-2026-64608

Jul 21, 2026 09:34:12 UTC

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input wi...

CVE-2026-58148

Jul 21, 2026 09:19:33 UTC

The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.

CVE-2026-62415

Jul 21, 2026 09:19:19 UTC

The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.

CVE-2026-15370

Jul 21, 2026 09:07:34 UTC

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficientl...