Total
230 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-15583 | 2026-07-15 | N/A | 8.6 HIGH | ||
| A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints. | |||||
| CVE-2026-12879 | 2026-07-09 | N/A | N/A | ||
| An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed. | |||||
| CVE-2022-24241 | 1 Aceware | 1 Aceweb Online Portal | 2026-07-09 | 5.0 MEDIUM | 7.5 HIGH |
| ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the txtFilePath parameter in attachments.awp. | |||||
| CVE-2026-10816 | 1 Citrix | 2 Netscaler Application Delivery Controller, Netscaler Gateway | 2026-07-02 | N/A | 7.5 HIGH |
| Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled | |||||
| CVE-2026-57301 | 1 Jenkins | 1 Official Owasp Zap | 2026-06-26 | N/A | 8.8 HIGH |
| Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. | |||||
| CVE-2026-12788 | 2026-06-22 | 6.5 MEDIUM | 6.3 MEDIUM | ||
| A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/base/barcodeDetail/import of the component XML Parser. This manipulation causes xml external entity reference. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-32204 | 1 Microsoft | 1 Azure Monitor Agent | 2026-06-18 | N/A | 7.8 HIGH |
| External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-40370 | 1 Microsoft | 5 Sql Server 2016, Sql Server 2017, Sql Server 2019 and 2 more | 2026-06-18 | N/A | 8.8 HIGH |
| External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-0418 | 1 Netgear | 70 Cbr750, Cbr750 Firmware, Ex6120 and 67 more | 2026-06-18 | N/A | 4.5 MEDIUM |
| Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system. | |||||
| CVE-2026-47643 | 1 Microsoft | 1 Azure Stack Edge | 2026-06-17 | N/A | 9.8 CRITICAL |
| External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-47358 | 1 Tenable | 1 Terrascan | 2026-06-17 | N/A | 7.5 HIGH |
| Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates via hashicorp/go-getter with all default detectors enabled, including FileDetector. An unauthenticated remote attacker can upload an ARM template containing a templateLink.uri or parametersLink.uri field, or a CloudFormation template containing an AWS::CloudFormation::Stack TemplateURL field, pointing to an attacker-controlled URL. Terrascan will fetch the attacker-controlled URL server-side. Unlike SSRF via the remote scan endpoint, file:// URLs are directly usable without requiring an X-Terraform-Get redirect, enabling local file read. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released. | |||||
| CVE-2026-47357 | 1 Tenable | 1 Terrascan | 2026-06-17 | N/A | 7.5 HIGH |
| Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as remote_url with remote_type set to "http". The URL is passed directly to hashicorp/go-getter (v1.7.5) without validation. Go-getter's HttpGetter supports the X-Terraform-Get response header, allowing the attacker's server to redirect the download to a file:// URL, enabling local file read. Additionally, HttpGetter has Netrc set to true, causing it to read ~/.netrc and send stored credentials to attacker-controlled hostnames. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released. | |||||
| CVE-2026-45760 | 2026-06-17 | N/A | 8.1 HIGH | ||
| (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the Pod generation in a namespace of their choice, including the operator namespace. This issue affects Apache Camel K: from 2.0.0 before 2.8.1, from 2.9.0 before 2.9.2, from 2.10.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1 (or 2.8.1 or 2.9.2), which fixes the issue. | |||||
| CVE-2026-41107 | 1 Microsoft | 1 Edge Chromium | 2026-06-17 | N/A | 7.4 HIGH |
| External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-3404 | 1 Jeesite | 1 Jeesite | 2026-06-17 | 4.6 MEDIUM | 5.0 MEDIUM |
| A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulation can lead to xml external entity reference. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |||||
| CVE-2026-34327 | 1 Microsoft | 1 Partner Center | 2026-06-17 | N/A | 8.2 HIGH |
| Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-32008 | 1 Openclaw | 1 Openclaw | 2026-06-17 | N/A | 6.5 MEDIUM |
| OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigationAllowed() function that allows authenticated users with browser-tool access to navigate to file:// URLs. Attackers can exploit this by accessing local files readable by the OpenClaw process user through browser snapshot and extraction actions to exfiltrate sensitive data. | |||||
| CVE-2026-30905 | 1 Zoom | 1 Workplace Virtual Desktop Infrastructure | 2026-06-17 | N/A | 7.8 HIGH |
| External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access. | |||||
| CVE-2026-30903 | 1 Zoom | 2 Workplace Desktop, Workplace Virtual Desktop Infrastructure | 2026-06-17 | N/A | 9.6 CRITICAL |
| External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access. | |||||
| CVE-2026-30817 | 1 Tp-link | 2 Archer Ax53, Archer Ax53 Firmware | 2026-06-17 | N/A | 5.7 MEDIUM |
| An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213. | |||||
