Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-81203 — SourceCodester Simple Online Food Ordering System ajax.php login2 sql injection

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument e…

simple_online_food_ordering_system | Remote | Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
5.5 MEDIUM
CVE-2026-80158 — Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_lo…

A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keyta…

ceph_storage openstack_platform | Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-75340 — JetLinks Community Server-Side Request Forgery

The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).

| Server-Side Request Forgery
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-75338 — Disconf Incorrect Access Control Vulnerability

disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config…

| Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-75336 — Funiture SQL Injection

Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.

| Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-75332 — Zyplayer-Doc Server-Side Request Forgery

Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().

| Server-Side Request Forgery
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-75330 — Super-diamond-server SQL Injection

The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL…

| Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
5.8 MEDIUM
CVE-2026-69129 — KubePi: Insufficient per-cluster authorization checks in cluster management APIs

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not consistently validate per-cluster access, allowing an authenticated user with …

Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
10.0 CRITICAL
CVE-2026-65956 — KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and…

Remote | Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.6 HIGH
CVE-2026-47666 — Penpot: Stored XSS via custom font family name injected into a @font-face style rule

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are inter…

Remote | Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.7 HIGH
CVE-2026-47665 — Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as…

Remote | Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
4.1 MEDIUM
CVE-2026-21808 — HCL BigFix Quantum Risk Analyzer is affected by logging sensitive information

HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logi…

| Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
3.9 LOW
CVE-2026-21807 — HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflow

HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.

| Memory Corruption
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
3.7 LOW
CVE-2025-62341 — HCL Connections is vulnerable to server-side request forgery (SSRF)

HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to …

Remote | Server-Side Request Forgery
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.5 HIGH
CVE-2026-81202 — itsourcecode Payroll System CRUD Operation ajax.php delete missing authentication

A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a mani…

payroll_system | Remote | Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.1 HIGH
CVE-2026-77611 — SeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwriting a diff…

SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested object key can overwrite a different object…

Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.6 HIGH
CVE-2026-77368 — SeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbitrary Write t…

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a …

Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.1 HIGH
CVE-2026-77317 — SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwrite

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a …

Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.7 HIGH
CVE-2026-77298 — SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy

SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external OIDC JWT sent directly in the Authorization header and maps it to an IAM ro…

Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-75333 — YX Image Recognition Path Traversal

yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist val…

| Path Traversal
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
Showing 20 of 12190 Results