Live feed

CVE Feed

Last 30 days — 9,657 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-13746
LOW· 3.6

Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. A user could trigger this issue by supplying crafted values to vulnerable Cortex SQL or object listing command paths, causing Snowflake CLI to execute unintended SQL in the context of that user's Snowflake session. Successful exploitation is constrained to self-injection because the vulnerable parameters were supplied directly through local CLI arguments rather than through project files, repositories, or other external input sources, and impact is limited to the privileges already available to the current session. The fix is available in Snowflake CLI version 3.19, and users must manually upgrade.

snowflake
29d ago
CVE-2026-13744
HIGH· 8.3

Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. By supplying crafted repository content, project configuration, manifest data, or specification input, an attacker could cause Snowflake CLI to execute unintended SQL in the context of the victim user's Snowflake session. Successful exploitation requires the victim to process attacker-controlled content through a vulnerable command path and is limited by the privileges assigned to that session. The fix is available in Snowflake CLI version 3.19. Users must manually upgrade.

snowflake
29d ago
CVE-2026-13742
NONE

Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification vulnerability. An attacker could potentially exploit this vulnerability, leading to the replacement of downloaded file with a malicious one. Honeywell also recommends updating to the most recent version of this product, service, or offering [V27 SP1, V28 SP1]

29d ago
CVE-2026-13587
LOW· 3.7

A vulnerability was found in seladb PcapPlusPlus 25.05. The affected element is the function parse_by_block_type of the file light_pcapng.c of the component LightPcapNg Parser. Performing a manipulation of the argument captured_packet_length results in heap-based buffer overflow. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is described as difficult. The exploit has been made public and could be used.

29d ago
CVE-2026-13583
HIGH· 8.8

A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. Such manipulation of the argument ShareName/SelectName leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

29d ago
CVE-2026-13582
HIGH· 8.8

A flaw has been found in Edimax EW-7478APC 1.04. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. This manipulation of the argument UserName/Password causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

29d ago
CVE-2026-13581
MEDIUM· 6.3

A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. The manipulation of the argument rootAPmac results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

29d ago
CVE-2026-13580
HIGH· 8.8

A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

29d ago
CVE-2026-13437
MEDIUM· 6.5

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.

devolutions
29d ago
CVE-2026-57525
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

29d ago
CVE-2026-57523
NONE

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

29d ago
CVE-2026-57341
MEDIUM· 6.5

Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.

29d ago
CVE-2026-57340
MEDIUM· 6.5

Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.

29d ago
CVE-2026-57339
MEDIUM· 6.5

Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.

29d ago
CVE-2026-57338
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.

29d ago
CVE-2026-57337
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.

29d ago
CVE-2026-57336
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.

29d ago
CVE-2026-57335
MEDIUM· 6.5

Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.

29d ago
CVE-2026-57334
MEDIUM· 6.5

Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.

29d ago
CVE-2026-57333
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.

29d ago
CVE-2026-57332
HIGH· 7.1

Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.

29d ago
CVE-2026-57331
CRITICAL· 9.9

Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.

29d ago
CVE-2026-57330
MEDIUM· 6.5

Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.

29d ago
CVE-2026-57329
MEDIUM· 6.5

Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.

29d ago
CVE-2026-57328
MEDIUM· 6.5

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

29d ago
CVE-2026-57327
MEDIUM· 6.3

Subscriber Broken Access Control in MainWP <= 6.1.1 versions.

29d ago
CVE-2026-57326
MEDIUM· 6.1

Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.

29d ago
CVE-2026-57320
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.

29d ago
CVE-2026-56290
KEVCRITICAL· 9.8

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

joomlack
29d ago
CVE-2026-56124
HIGH· 7.5

phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints.

29d ago
CVE-2026-55844
HIGH· 7.5

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks to the internal URL as well, which can expose user's token when connected to a not secure network. This vulnerability is fixed in 2025.5.0.

29d ago
CVE-2026-55607
HIGH· 8.8

Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files in the user's home directory (such as .zshenv), leading to code execution outside of seatbelt sandbox restrictions. Reliably exploiting this required the user to clone a malicious repository containing prompt injection content and run Claude Code against it. This vulnerability is fixed in 2.1.163.

anthropic
29d ago
CVE-2026-49049
HIGH· 7.5

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

ollyo
29d ago
CVE-2026-46406
MEDIUM· 6.1

Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user's Claude response, which could contain secrets or credentials. Additionally, because the path was static and predictable, a local attacker could pre-create the directory and plant a symlink at the expected file path, causing the privileged process to follow the symlink and overwrite an attacker-chosen file with the response text. Exploiting this required a local unprivileged user on the same system and a privileged user to run the /copy command. This vulnerability is fixed in 2.1.128.

anthropic
29d ago
CVE-2026-13579
MEDIUM· 6.3

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /patientchangepassword.php. Executing a manipulation of the argument newpassword can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

29d ago
CVE-2026-13578
MEDIUM· 6.3

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patientdetail.php. Performing a manipulation of the argument editid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

29d ago
CVE-2026-13574
LOW· 3.3

A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.

29d ago
CVE-2026-13573
LOW· 3.3

A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.

29d ago
CVE-2026-13572
MEDIUM· 6.3

A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /insertbillingrecord.php. The manipulation of the argument patientid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

29d ago
CVE-2026-13571
MEDIUM· 5.3

A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a manipulation of the argument item_price can lead to business logic errors. The attack may be performed from remote. The exploit has been published and may be used.

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000