Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-82732 — Declared argument constraints not enforced on AshTypescript typed controller routes

Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-controller routes. AshTypescri…

Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
2.3 LOW
CVE-2026-82731 — Unescaped path parameters in AshTypescript generated TypeScript client allow request redi…

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, and th…

Remote | Information Disclosure
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.2 HIGH
CVE-2026-82730 — Authorization-redacted field values disclosed through AshTypescript result normalization

Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute…

Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.3 MEDIUM
CVE-2026-77950 — RPC error handler fails open in AshTypescript, disclosing unredacted errors

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an e…

Remote | Information Disclosure
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.2 HIGH
CVE-2026-77856 — Unbounded atom creation from typed struct field names in AshTypescript field selector

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-suppli…

Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-75865 — WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' RE…

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in th…

Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.7 HIGH
CVE-2026-74837 — Unbounded atom creation from client-supplied RPC field names in AshTypescript field forma…

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-suppli…

Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.9 MEDIUM
CVE-2026-67395 — Sage Employee Self Service Path Traversal Vulnerability

A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and the…

Remote | Path Traversal
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.0 CRITICAL
CVE-2026-67394 — Plesk for Linux OS Command Injection Privilege Escalation

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerabil…

Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.7 HIGH
CVE-2026-65643 — cPanel Eval Injection Remote Code Execution

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
3.7 LOW
CVE-2026-48932 — Node.js HTTP Request Smuggling Vulnerability

A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the orig…

Remote | Misconfiguration
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
2.5 LOW
CVE-2026-18743 — Popt-devel: popt-static: short realloc in poptconfigfiletostring

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occ…

Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.8 HIGH
CVE-2026-19820 — Backblaze Client for Windows Improper Link Resolution Vulnerability

A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitat…

Remote | Path Traversal
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.9 CRITICAL
CVE-2026-83524 — RedPort Optimizer wXa-223 System Clock datetime.php exec command injection

A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.ph…

Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
10.0 CRITICAL
CVE-2026-82971 — QVidium Opera11 CGI Script net_tr.cgi command injection

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ip…

opera11_firmware opera11 | Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82957 — hyperledger-firefly Webhook Subscription webhooks.go ValidateOptions server-side request …

A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Su…

firefly | Remote | Server-Side Request Forgery
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
9.9 CRITICAL
CVE-2026-82954 — Dokploy Settings application.ts writeTraefikConfigInPath path traversal

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. …

dokploy | Remote | Path Traversal
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82922 — ShopEx ECShop flow.php flow_update_cart sql injection

A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argum…

ecshop | Remote | Injection
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
7.5 HIGH
CVE-2026-82921 — ShopEx ECShop pack.php check_img_type unrestricted upload

A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestr…

ecshop | Remote | Authentication
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
8.8 HIGH
CVE-2026-82882 — Devtron through 2.2.0 Missing Authorization via webhook API token endpoint

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenti…

devtron | Remote | Authorization
Aug 31, 2026 Aug 31, 2026
Aug 31, 2026
Aug 31, 2026
Showing 20 of 12164 Results