Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-80132 — Dell Secure Connect Gateway Missing Authentication for Critical Function Vulnerability

ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
2.3 LOW
CVE-2026-86441 — MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hid…

Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.4 HIGH
CVE-2026-80133 — Dell Secure Connect Gateway Relative Path Traversal Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remot…

Remote | Path Traversal
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.1 MEDIUM
CVE-2026-86440 — MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs

Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous rendere…

Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.7 HIGH
CVE-2026-80134 — Dell Secure Connect Gateway Use of Hard-coded Credentials Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker wit…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.0 HIGH
CVE-2026-86419 — MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed …

Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed …

Remote | Server-Side Request Forgery
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.4 CRITICAL
CVE-2026-6223 — OTP Bypass in Bahçelievler Muncipality's BiHayat App

Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: from 2.1.7 through 07092…

Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
0.0 NA
CVE-2026-8279 — Masteriyo LMS <= 2.2.0 - Missing Authorization to Unauthenticated Arbitrary Course Progre…

The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsControll…

| Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
0.0 NA
CVE-2026-6431 — User Profile Builder <= 3.15.7 - Unauthenticated Stored Cross-Site Scripting via 'Biograp…

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Biographical Info' meta field…

| Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
0.0 NA
CVE-2026-4945 — Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification By…

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the…

| Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
0.0 NA
CVE-2026-12853 — Flamingo <= 2.6.2 - Authenticated (Contributor+) Missing Authorization to Unauthorized Ta…

The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. This is due to the plugin not properly verifying that a user is authorized to perf…

| Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.4 CRITICAL
CVE-2026-61410 — Dell Secure Connect Gateway Missing Authorization Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote …

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.4 MEDIUM
CVE-2026-86416 — ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods

ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations …

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
2.3 LOW
CVE-2026-86418 — MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized U…

Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-or…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.3 HIGH
CVE-2026-61409 — Dell Secure Connect Gateway OS Command Injection Vulnerability

Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. …

Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
5.3 MEDIUM
CVE-2026-86417 — MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized U…

Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the no…

Remote | Authorization
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
8.8 HIGH
CVE-2026-86404 — Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging…

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via i…

Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
4.0 MEDIUM
CVE-2026-86301 — code-projects Hospital Information System Patient Management editPatient.php cross site s…

A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Suc…

hospital_information_system | Remote | Cross-Site Scripting
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
7.5 HIGH
CVE-2026-86300 — Tenda AC9 Web Management R7WebsSecurityHandler improper authentication

A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The attack may be in…

ac9 | Remote | Authentication
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
9.9 CRITICAL
CVE-2026-86299 — Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of …

re7000 | Remote | Injection
Sep 07, 2026 Sep 07, 2026
Sep 07, 2026
Sep 07, 2026
Showing 20 of 12392 Results