Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-82957 — hyperledger-firefly Webhook Subscription webhooks.go ValidateOptions server-side request …

A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Su…

Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.9 CRITICAL
CVE-2026-82954 — Dokploy Settings application.ts writeTraefikConfigInPath path traversal

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. …

Remote | Path Traversal
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82922 — ShopEx ECShop flow.php flow_update_cart sql injection

A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argum…

ecshop | Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82921 — ShopEx ECShop pack.php check_img_type unrestricted upload

A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestr…

ecshop | Remote | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.8 HIGH
CVE-2026-82882 — Devtron through 2.2.0 Missing Authorization via webhook API token endpoint

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenti…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
6.9 MEDIUM
CVE-2026-82398 — pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream …

Remote | Denial of Service
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82397 — Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event…

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py …

tornado | Remote | Denial of Service
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.4 MEDIUM
CVE-2026-82396 — Sulu: Stored XSS via media download inline-disposition override

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /m…

Remote | Cross-Site Scripting
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.3 MEDIUM
CVE-2026-82395 — Sulu: Media move/update authorization bypass (IDOR)

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied …

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
5.3 MEDIUM
CVE-2026-82394 — Sulu: Fix authorization bypass when creating preview links

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manage…

Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82393 — pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/…

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackag…

Remote | Path Traversal
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
4.6 MEDIUM
CVE-2026-77353 — Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Export

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exporte…

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
4.3 MEDIUM
CVE-2026-77352 — Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user)

Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make the server open ar…

Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
3.5 LOW
CVE-2026-77351 — Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata I…

Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.2 HIGH
CVE-2026-77348 — Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable vi…

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened en…

Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
0.0 NA
CVE-2026-82971 — QVidium Opera11 CGI Script net_tr.cgi command injection

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ip…

opera11 | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.8 HIGH
CVE-2026-83596 — Webkitgtk: validate the full featurelist array once in opentypeverticaldata findfeature

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

enterprise_linux enterprise_linux | Remote | Memory Corruption
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82919 — cu silicon edit Endpoint views.py create_app missing authentication

A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to mis…

Remote | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82914 — kishan0725 Hospital-Management-System search.php sql injection

A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in …

Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
4.3 MEDIUM
CVE-2026-82909 — QuantumNous new-api Revoked API Token token session expiration

A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler.…

new-api | Remote | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
Showing 20 of 12145 Results