Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-82671 — IObit Unlocker IRP_MJ_DEVICE_CONTROL IObitUnlocker.sys ZwTerminateProcess privileges mana…

A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRP_MJ_DEVICE_CONTROL Handler. …

| Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.6 CRITICAL
CVE-2026-49003 — Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product

Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain root privileg…

| Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
0.0 NA
CVE-2026-82670 — IObit Uninstaller IOCTL IUForceDelete.sys IRP_MJ_DEVICE_CONTROL privileges management

A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the function IRP_MJ_DEVICE_CONTROL in the library IUForceDelete.sys of the component IOCTL Handler. Executing a manipulation can lea…

| Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.5 MEDIUM
CVE-2026-82875 — ToolJet before v3.16.208 Authorization Bypass via organizationId

ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user'…

| Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.9 CRITICAL
CVE-2026-82874 — ToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-db

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to rea…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.3 MEDIUM
CVE-2026-82873 — ToolJet through 3.0.0-ee-beta.2 Cross-workspace Schema Disclosure via Export

ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across w…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.1 CRITICAL
CVE-2026-82872 — ToolJet before v3.16.208 Cross-Workspace Authorization Bypass

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, a…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.2 HIGH
CVE-2026-82871 — ToolJet before v3.16.208 Cross-Organization Data Read via Database Routes

ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can su…

| Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.6 CRITICAL
CVE-2026-82870 — ToolJet before v3.16.208 Cross-Tenant Database Manipulation

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' datab…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.2 HIGH
CVE-2026-82869 — ToolJet Database before v3.16.44 Privilege Escalation via join_tables

ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace…

| Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
6.1 MEDIUM
CVE-2026-82868 — @pdfme/schemas before 5.5.9 Cross-Site Scripting via SVG

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can inj…

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
6.1 MEDIUM
CVE-2026-82867 — @pdfme/schemas before 5.5.9 Cross-Site Scripting via Select

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML. Attackers…

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.9 HIGH
CVE-2026-82866 — @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch

@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Atta…

Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
4.4 MEDIUM
CVE-2026-82865 — pdfme schemas before 5.5.10 Cross-Site Scripting via i18n Label

pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control label …

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.1 HIGH
CVE-2026-82864 — pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bomb

pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method that allows attackers to cause denial of service by supplying a crafted…

Remote | Denial of Service
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.7 HIGH
CVE-2026-82863 — @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection

@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors…

Remote | Misconfiguration
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.6 HIGH
CVE-2026-82862 — Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files

Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the wor…

| Misconfiguration
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.7 HIGH
CVE-2026-82861 — @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass

@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass …

Remote | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.8 CRITICAL
CVE-2026-82860 — @hulumi/policies before 1.3.2 Admin Policy Bypass

@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that byp…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.8 CRITICAL
CVE-2026-82859 — hulumi before v1.3.2 SCP Template Tag-on-Create Bypass

hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiti…

Remote | Misconfiguration
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
Showing 20 of 11960 Results