Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.0 MEDIUM
CVE-2026-75082 — Webkul Bagisto Customer-Registration Notification Email register cross site scripting

A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipul…

bagisto | Remote | Cross-Site Scripting
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
4.3 MEDIUM
CVE-2026-75081 — Webkul Bagisto store behavioral workflow

A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reaso…

bagisto | Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.5 HIGH
CVE-2026-75080 — SourceCodester Class and Exam Timetabling System edit_subject1.php sql injection

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the …

class_and_exam_timetabling_system | Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
7.5 HIGH
CVE-2026-75079 — SourceCodester Class and Exam Timetabling System edit_subject2.php sql injection

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argumen…

class_and_exam_timetabling_system | Remote | Injection
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
0.0 NA
CVE-2026-75086 — itsourcecode Hospital Management System viewroom.php sql injection

A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php. Such manipulation of the argument delid leads to …

Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
3.5 LOW
CVE-2026-9693 — Mattermost thread memberships persist after team removal, exposing private channel thread…

Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who…

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
3.6 LOW
CVE-2026-75587 — Plaintext pre-auth secret exposure via Desktop App diagnostics report

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log …

| Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.0 MEDIUM
CVE-2026-75078 — SourceCodester Class and Exam Timetabling System BSHRM1.php cross site scripting

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course res…

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-67961 — O2OA Sandbox Remote Code Execution

An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.

| Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-67919 — Halo Remote Code Execution Vulnerability

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components

| Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-42164 — Mahara Text Block Cross-Section Information Disclosure

Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text sectio…

| Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-42162 — Mahara Artefact Unauthorized Access Vulnerability

Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.

| Path Traversal
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-38165 — XDocReport Server-Side Template Injection

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.

| Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-9859 — Mattermost Boards plugin didn’t enforce role-based authorization on board channel link al…

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated boar…

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.3 HIGH
CVE-2026-9816 — Insufficient server-side validation of board member role fields permits privilege escalat…

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or n…

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.0 MEDIUM
CVE-2026-75077 — SourceCodester Class and Exam Timetabling System BSCE2.php cross site scripting

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such manipulation of the argument …

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.6 CRITICAL
CVE-2026-71424 — Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers

Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization h…

Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.1 HIGH
CVE-2026-69148 — MLflow: CreateModelVersion source validation does not check READ permission on referenced…

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_sourc…

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-69146 — MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlfl…

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-67960 — PbootCMS Arbitrary Code Execution Vulnerability

An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components

| Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
Showing 20 of 11338 Results