|
41
|
8.1 |
HIGH
Network
|
-
|
-
|
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…
New
|
CWE-285
Improper Authorization
|
CVE-2026-32821
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
42
|
7.5 |
HIGH
Network
|
-
|
-
|
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before an…
New
|
CWE-285
Improper Authorization
|
CVE-2026-32806
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
43
|
8.4 |
HIGH
Adjacent
|
-
|
-
|
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or a…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-28220
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
44
|
- |
|
-
|
-
|
Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input…
New
|
-
|
CVE-2026-26483
|
2026-07-21 03:16 |
2026-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
45
|
8.8 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based…
New
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-16097
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
46
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulatio…
New
|
CWE-287 CWE-294
Improper Authentication Authentication Bypass by Capture-replay
|
CVE-2026-16083
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
47
|
- |
|
-
|
-
|
SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass …
New
|
CWE-674
Uncontrolled Recursion
|
CVE-2025-71393
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
48
|
7.5 |
HIGH
Network
|
-
|
-
|
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenticated attackers can send crafted HTTP requests wit…
New
|
CWE-248
Uncaught Exception
|
CVE-2024-58368
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
49
|
8.8 |
HIGH
Network
|
-
|
-
|
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. W…
New
|
CWE-75
Special Element Injection
|
CVE-2024-58362
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
50
|
8.8 |
HIGH
Network
|
-
|
-
|
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database a…
New
|
CWE-276
Incorrect Default Permissions
|
CVE-2023-54366
|
2026-07-21 03:16 |
2026-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|