Common Vulnerabilities and Exposures (CVE)

CVE-2026-16266

Jul 21, 2026 05:00:00 UTC

Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in util.js. An attacker can modify the JavaScript prototype chain by supplying a crafted property path containing special k...

CVE-2026-8149

Jul 21, 2026 04:59:54 UTC

A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the Bouncy Castle Inc. BC-FJA bc-fips on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files...

CVE-2026-15927

Jul 21, 2026 04:45:27 UTC

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an external_reference parameter without SSRF validation, unlike the organization-level mirror hand...

CVE-2025-57847

Jul 21, 2026 04:41:56 UTC

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an att...

CVE-2023-37508

Jul 21, 2026 04:34:15 UTC

HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.

CVE-2026-15156

Jul 21, 2026 04:33:03 UTC

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insu...

CVE-2026-32591

Jul 21, 2026 04:17:27 UTC

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying...

CVE-2026-12382

Jul 21, 2026 04:16:26 UTC

A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An...

CVE-2026-12701

Jul 21, 2026 04:15:59 UTC

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authen...

CVE-2025-5278

Jul 21, 2026 04:07:25 UTC

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key forma...

CVE-2026-55144

Jul 21, 2026 03:56:16 UTC

Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.

CVE-2026-50378

Jul 21, 2026 03:56:15 UTC

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.

CVE-2026-9804

Jul 21, 2026 03:08:39 UTC

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an expor...

CVE-2026-59776

Jul 21, 2026 03:06:56 UTC

Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.

CVE-2026-16131

Jul 21, 2026 02:46:22 UTC

A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. This manipulation of the argument delid causes sql injection. It is possible to initiate th...