#
20 entries
2026-07-30
ID: 546
CVE-2026-63313 - 9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch
2026-07-30
ID: 545
CVE-2026-16767 - Ne-Lexa php-zip ZIP ZipFile.php extractTo path traversal
2026-07-30
ID: 532
CVE-2026-15981 - SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
2026-07-30
ID: 524
CVE-2026-47723 - nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
2026-07-29
ID: 516
CVE-2026-65694 - Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
2026-07-29
ID: 515
CVE-2026-16764 - OWASP DefectDojo API/Web serializers.py UserSerializer privileges management
2026-07-29
ID: 513
CVE-2026-64785 - SwiftNIO HTTP/2 Improper Input Validation HTTP Request Smuggling
2026-07-29
ID: 507
CVE-2026-12353 - Rhcs: memory leak during https connection leads to denial of service
2026-07-29
ID: 504
CVE-2026-48013 - Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation
2026-07-29
ID: 502
CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
2026-07-29
ID: 501
CVE-2026-63765 - Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation
2026-07-29
ID: 497
CVE-2026-65763 - Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9