Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-105050 — PeaZip OS Command Injection Vulnerability

PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.

| Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.7 HIGH
CVE-2026-97363 — Monta monta.app Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks o…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.3 HIGH
CVE-2026-97212 — Monta monta.app Insufficient Session Expiration

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predi…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.4 CRITICAL
CVE-2026-95102 — Monta monta.app Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensiti…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.1 MEDIUM
CVE-2026-94594 — Armatura LLC Armatura One Insertion of Sensitive Information into Log File

Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support b…

| Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.5 HIGH
CVE-2026-94593 — Armatura LLC Armatura One Insertion of Sensitive Information into Log File

Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this findin…

| Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.6 HIGH
CVE-2026-94592 — Armatura LLC Armatura One Use of Hard-coded Credentials

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. …

| Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.6 HIGH
CVE-2026-94591 — Armatura LLC Armatura One Use of Hard-coded Cryptographic Key

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization v…

| Cryptography
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.9 MEDIUM
CVE-2026-93474 — Monta monta.app Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Remote | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.3 MEDIUM
CVE-2026-105046 — Kentico Xperience Improper Authorization Vulnerability

Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.

xperience | Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
3.6 LOW
CVE-2026-105043 — MathWorks Simulink Arbitrary Code Execution Vulnerability

MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution.

| Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.8 MEDIUM
CVE-2026-105049 — Zilliz Attu Server-Side Request Forgery Vulnerability

Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.

Remote | Server-Side Request Forgery
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.8 CRITICAL
CVE-2026-84411 — MikroTik RouterOS Integer Underflow

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthent…

routeros routeros | Remote | Memory Corruption
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
4.0 MEDIUM
CVE-2026-105048 — Zilliz Attu Playground Server-Side Request Forgery

The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).

Remote | Server-Side Request Forgery
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.1 HIGH
CVE-2026-82045 — UTMStack < 11.2.16 JPQL Injection via searchPropertyValues

UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which bui…

Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.7 HIGH
CVE-2026-82044 — UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated ur…

Remote | Server-Side Request Forgery
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.9 MEDIUM
CVE-2026-82043 — UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint

UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.8 CRITICAL
CVE-2026-82042 — UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the …

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.9 CRITICAL
CVE-2026-82041 — UTMStack < 11.2.16 Missing Authorization via Command WebSocket

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role …

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.4 CRITICAL
CVE-2026-75937 — OS Command Injection in Digi Accelerated Linux (DAL OS)

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device…

| Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 14954 Results