Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-93468 — HGiga|OAKlouds - Arbitrary File Read

The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.

Remote | Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.8 CRITICAL
CVE-2026-93467 — HGiga|OAKlouds - Insecure Deserialization

The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized conte…

Remote | Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.3 HIGH
CVE-2026-93371 — marcopiovanello yt-dlp-web-ui generic.go NewGenericDownload command injection

A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manip…

Remote | Injection
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.4 MEDIUM
CVE-2026-92991 — Biggopti Library (Various Versions) - Cross-Site Scripting via display_id from Sigmative …

The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for atta…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.4 MEDIUM
CVE-2026-15650 — RT Mega Menu <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'poi…

The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute in all versions up to, and inc…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.4 MEDIUM
CVE-2026-14855 — RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmeg…

The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient input sanitization and…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.4 HIGH
CVE-2026-93456 — django-page-cms through 2.0.13 CSRF via admin mutation views

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visitin…

Remote | Cross-Site Request Forgery
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.1 HIGH
CVE-2026-93455 — django-page-cms through 2.0.13 Unauthorized Content Access via Staff Account

django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-…

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93331 — GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds

A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulatio…

Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93314 — Freedesktop Poppler FoFiTrueType.cc mapCodeToGID integer overflow

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt c…

poppler | Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.5 HIGH
CVE-2026-93313 — Freedesktop Poppler JBIG2Stream.cc readCodeTableSeg integer overflow

A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in i…

poppler | Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.5 MEDIUM
CVE-2026-82985 — Photos App Improper Access Control via Smart Album Metadata Disclosure

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. …

server | Remote | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.3 MEDIUM
CVE-2026-82982 — Approval App Insecure Direct Object Reference Vulnerability

The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after the…

approval | Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.3 MEDIUM
CVE-2026-82980 — Nextcloud DAV Plugin Improper Authorization Vulnerability

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that t…

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.3 MEDIUM
CVE-2026-77170 — Deck API Unauthorized Configuration Modification Vulnerability

The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.

deck | Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.5 MEDIUM
CVE-2026-77169 — Nextcloud Team Folders Authorization Bypass

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization co…

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.2 MEDIUM
CVE-2026-77164 — Nextcloud Circles Server-Side Request Forgery

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this requ…

server | Server-Side Request Forgery
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
3.1 LOW
CVE-2026-68493 — Insecure Direct Object Reference in Membership Retrieval

After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

server | Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.0 MEDIUM
CVE-2026-93312 — Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference

A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possibl…

poppler | Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.0 MEDIUM
CVE-2026-93311 — Freedesktop Poppler SampledFunction Function.cc integer overflow

A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The man…

poppler | Remote | Memory Corruption
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
Showing 20 of 14442 Results