Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-72710 — SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection

SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing…

Remote | Injection
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.8 CRITICAL
CVE-2026-72709 — SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur

SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by su…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.7 HIGH
CVE-2026-72708 — SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitemap endpoint where the MySQL escaper spip_mysql_cite() in ecrire/req/mysql.php returns values unesca…

Remote | Injection
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.0 MEDIUM
CVE-2026-18061 — Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper Remot…

Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infras…

Remote | XML External Entity
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
0.0 NA
CVE-2026-54047 — Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Sid…

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAut…

| Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.5 MEDIUM
CVE-2026-8304 — Information Disclosure in TUBITAK BILGEM's Pardus About

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affect…

| Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-89265 — MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint

MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based p…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.3 MEDIUM
CVE-2026-89264 — MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can sup…

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-89263 — MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint

MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote …

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.7 HIGH
CVE-2026-89262 — MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal.…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-89261 — MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index.…

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.7 HIGH
CVE-2026-89260 — MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback…

MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body t…

Remote | XML External Entity
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.4 HIGH
CVE-2026-89066 — OS command injection in the task synthesis component in projen

Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a d…

| Injection
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.1 HIGH
CVE-2026-89065 — Relative path traversal in the generated file manifest cleanup component in projen

Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the proj…

| Path Traversal
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.7 HIGH
CVE-2026-89013 — Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php

Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted…

Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.1 HIGH
CVE-2026-89012 — Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter

Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by…

Remote | Injection
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.9 MEDIUM
CVE-2026-81861 — RTU Insufficiently Protected Credentials Vulnerability

CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.4 HIGH
CVE-2026-7863 — OS Command Injection in TUBITAK BILGEM's Pardus Software

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command I…

| Injection
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.5 HIGH
CVE-2026-70341 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.5 HIGH
CVE-2026-68497 — jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserializ…

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newX…

jackson-databind | Remote | Denial of Service
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
Showing 20 of 13385 Results