Common Vulnerabilities and Exposures (CVE)

CVE-2026-55777

Jul 31, 2026 11:24:05 UTC

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offs...

CVE-2026-62845

Jul 31, 2026 11:18:41 UTC

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt....

CVE-2026-68562

Jul 31, 2026 11:14:02 UTC

A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause t...

CVE-2026-64816

Jul 31, 2026 11:10:30 UTC

RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking th...

CVE-2026-55502

Jul 31, 2026 11:09:00 UTC

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id values, ...

CVE-2026-56672

Jul 31, 2026 11:06:19 UTC

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin ...

CVE-2026-18215

Jul 31, 2026 11:00:46 UTC

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an ...

CVE-2026-18206

Jul 31, 2026 10:59:36 UTC

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can reg...

CVE-2026-18436

Jul 31, 2026 10:53:34 UTC

The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The r...

CVE-2026-15722

Jul 31, 2026 10:44:58 UTC

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without boun...

CVE-2026-22622

Jul 31, 2026 09:56:07 UTC

Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.

CVE-2026-22621

Jul 31, 2026 09:55:33 UTC

Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.

CVE-2026-22620

Jul 31, 2026 09:55:01 UTC

Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.

CVE-2026-9177

Jul 31, 2026 05:52:15 UTC

A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker with admin privileges to inject arbitrary ...

CVE-2026-65947

Jul 31, 2026 05:49:36 UTC

Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2