Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.4 HIGH
CVE-2026-50236 — Openshift/console: authenticated ssrf with full response reflection and path neutralizati…

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbi…

openshift_container_platform | Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.4 HIGH
CVE-2026-50237 — Openshift/console: namespace tenant ssrf with egress bypass, catalog poisoning, and admin…

A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the con…

openshift_container_platform | Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.3 MEDIUM
CVE-2026-72610 — Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the borrowers => edit_borrowers permission to cause a time-based denial…

| Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.1 HIGH
CVE-2026-72609 — Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl

An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the acquisition => order_receive permission to read arbitrary database conten…

| Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-72608 — Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_creator permission to execute arbitrary SQL via the …

| Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.1 HIGH
CVE-2026-72607 — Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications b…

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_batchmod permission to execute arbitrary SQL via the…

| Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
10.0 CRITICAL
CVE-2026-58231 — Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploi…

commerce_cloud | Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.5 HIGH
CVE-2026-72606 — Pinry Pinry - Server-Side Request Forgery

A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the pin-…

| Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.5 HIGH
CVE-2026-72605 — Swing Music Swing Music - Missing Authentication

A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allow…

| Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-72604 — Intelliants Subrion CMS - Path Traversal

A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server via the admin panel file deletion endpoint. The end…

subrion_cms | Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.9 CRITICAL
CVE-2026-72603 — wg-easy wg-easy - OS Command Injection

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directive…

| Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.5 HIGH
CVE-2026-72602 — AsyncFuncAI deepwiki-open - Path Traversal

A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-re…

| Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.5 HIGH
CVE-2026-72601 — CSZ CMS CSZ CMS - Broken Access Control

A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin form-submission…

| Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.5 HIGH
CVE-2026-72600 — Idurar IDURAR ERP CRM - Broken Access Control

A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router…

| Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.8 CRITICAL
CVE-2026-72599 — e107 e107 - SQL Injection

An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into …

| Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-72598 — Apioo Fusio - Server-Side Request Forgery

A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the server issue HTTP requests to internal network addresses by registering a webhook…

| Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-72597 — Friendica Friendica - Server-Side Request Forgery

A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered account to probe internal network services via the link-…

| Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.1 HIGH
CVE-2026-72596 — Ghost Foundation Ghost - Broken Access Control

A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the br…

| Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.1 HIGH
CVE-2026-72595 — BadChoice Handesk - Broken Access Control

A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to other teams via the TicketsController@update endpoint.…

| Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.1 HIGH
CVE-2026-72563 — BadChoice Handesk - Broken Access Control

A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging to other teams via the LeadsController@update endpoint. …

| Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
Showing 20 of 10181 Results