Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-96877 — Reflected XSS through Cargo Drilldown full-text search

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension…

cargo | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.9 MEDIUM
CVE-2026-96876 — Anonymous reflected XSS in CargoExport invalid-alias errors

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension…

cargo | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.9 MEDIUM
CVE-2026-96875 — Reflected XSS in Cargo Drilldown hierarchy filters

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: …

cargo | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.8 MEDIUM
CVE-2026-93682 — Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Loc…

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. …

php | Remote | Memory Corruption
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.5 HIGH
CVE-2026-5267 — Unauthenticated Event Stream Exposure of Session Tokens in Navigator NCS

Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with ne…

Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.1 MEDIUM
CVE-2026-100373 — OpenMetadata through 2.0.2 SSRF via Webhook URL Validation Bypass

OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. …

openmetadata | Remote | Server-Side Request Forgery
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.6 HIGH
CVE-2026-100372 — ClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.php

ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal s…

clipbucket | Remote | Path Traversal
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.4 HIGH
CVE-2026-100368 — CliInvoke.Specializations: Command injection in PowerShell and Cmd shell wrappers

CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. `Cl…

| Injection
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.3 HIGH
CVE-2026-100310 — GNU libextractor before 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX

GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this b…

libextractor | Misconfiguration
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.5 HIGH
CVE-2026-100208 — Microsoft Office Outlook Remote Code Execution Vulnerability

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
5.1 MEDIUM
CVE-2026-97897 — Krayin laravel-crm TinyMCE Media Upload Sanitizer.php cross site scripting

A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation res…

laravel-crm | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
4.0 MEDIUM
CVE-2026-97896 — krayin laravel-crm Upload Functionality ConfigurationForm.php rules cross site scripting

A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationFor…

laravel-crm | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.5 MEDIUM
CVE-2026-97895 — krayin laravel-crm User Management UserController.php privileges management

A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User…

laravel-crm | Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.3 CRITICAL
CVE-2026-97064 — X-SpringBoot through 6.0 Authentication Bypass via Static Master Code

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitt…

x-springboot | Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
9.3 CRITICAL
CVE-2026-97063 — X-SpringBoot through 6.0 Authentication Bypass via Login Code

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attacke…

x-springboot | Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
8.6 HIGH
CVE-2026-97060 — X-SpringBoot through 6.0 Authorization Bypass via User Management

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-manag…

x-springboot | Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.1 HIGH
CVE-2026-84465 — Zammad: S/MIME signature verification allows forged sender impersonation

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing ce…

zammad | Remote | Cryptography
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
7.1 HIGH
CVE-2026-84464 — Zammad: IDOR in External Data Source rendering exposes ticket, user, group, and organizat…

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's External Data Source feature, used to look up records from an external system, did not properly verify whe…

zammad | Remote | Authorization
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.3 MEDIUM
CVE-2026-84463 — Zammad: Stored HTML injection in Knowledge Base video widget enables forced session switc…

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a published answer with a spec…

zammad | Remote | Cross-Site Scripting
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
6.9 MEDIUM
CVE-2026-84461 — Zammad: Missing rate limiting allows password brute-forcing during two-factor login

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad'…

zammad | Remote | Authentication
Sep 25, 2026 Sep 25, 2026
Sep 25, 2026
Sep 25, 2026
Showing 20 of 14463 Results