Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-69082 — Cross-Site Request Forgery in the Administrative User Deletion Endpoint

CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoint accepted HTTP GET requests for an operation tha…

Remote | Cross-Site Request Forgery
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.7 HIGH
CVE-2026-69079 — Unauthenticated Denial of Service via Unbounded Activity-Timeline Range in CTI-Transmute

CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not …

Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.8 HIGH
CVE-2026-69078 — Server-Side Request Forgery and Local File Disclosure in CTI-Transmute Evaluation PDF Ren…

CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI content, including conversion names, descriptions,…

Remote | Server-Side Request Forgery
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.5 MEDIUM
CVE-2026-68742 — Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr

A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this…

Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
10.0 CRITICAL
CVE-2026-33591 — Authentication bypass on WaptServer

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token …

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.3 HIGH
CVE-2026-0392 — eParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-update

eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch the application fetche…

| Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-69075 — Stored Cross-Site Scripting via Vue Template Injection in FlowIntel

FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted values—including case titles, ticket identifiers, …

Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-63563 — Sharp and Toshiba Tec MFPs Unauthorized Access Vulnerability

Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial confi…

| Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
2.4 LOW
CVE-2026-63545 — Sharp and Toshiba Tec MFPs Sensitive Data Exposure via Insecure Cache Persistence

Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.

| Information Disclosure
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-62416 — Sharp Corporation Network Scanner Tool Unauthenticated Arbitrary File Upload and Denial o…

Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products ar…

| Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-60011 — Sharp and Toshiba Tec MFPs Unauthorized Image Data Access Vulnerability

Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.

| Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-8794 — PaperCut NG/MF: User enumeration via timing attack

PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measurin…

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2026-8793 — PaperCut NG/MF: Insufficient brute-force protection

PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute…

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
5.4 MEDIUM
CVE-2026-28147 — WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.…

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. …

Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21555 — Modem Improper Input Validation Denial of Service

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

udx710 | Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21554 — Modem Improper Input Validation Vulnerability

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

udx710 | Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21553 — Modem Improper Input Validation Denial of Service

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21552 — Modem Improper Input Validation Denial of Service

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21551 — Modem Improper Input Validation Denial of Service

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-21550 — Modem Improper Input Validation Denial of Service

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
Showing 20 of 9252 Results