Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-90848 — Governikus AusweisApp StartPAOSResponse cross site scripting

A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage…

Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.7 HIGH
CVE-2026-91752 — GNU libextractor before 1.15 Stack Overflow via OLE2

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream dat…

libextractor | Remote | Memory Corruption
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.3 HIGH
CVE-2026-91751 — Flextype CMS through 1.0.0-alpha.3 Path Traversal via Entries REST API

Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries dire…

Remote | Path Traversal
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.1 HIGH
CVE-2026-91750 — WeKnora before 0.7.0 SSRF via Unvalidated HTTP Redirects

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attack…

weknora | Remote | Server-Side Request Forgery
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
9.1 CRITICAL
CVE-2026-90847 — EFM ipTIME C200E System Setup iux_set.cgi os command injection

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command inject…

Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-90846 — PHPGurukul Daily Expense Tracker System forgot-password.php sql injection

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno …

daily_expense_tracker_system | Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
4.0 MEDIUM
CVE-2026-90845 — PHPGurukul Daily Expense Tracker System sidebar.php cross site scripting

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullN…

daily_expense_tracker_system | Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-90844 — PHPGurukul Daily Expense Tracker System Login index.php sql injection

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of t…

daily_expense_tracker_system | Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
8.3 HIGH
CVE-2026-90843 — SabyasachiRana WebMap New Nmap Scan functions_nmap.py nmap_newscan os command injection

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the compone…

Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.4 MEDIUM
CVE-2026-85657 — Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors…

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_valu…

Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
6.4 MEDIUM
CVE-2026-85575 — The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with…

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘…

Remote | Cross-Site Scripting
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
3.7 LOW
CVE-2026-90842 — PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in file

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipul…

blood_donor_management_system | Remote | Cryptography
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-90841 — PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injection

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php o…

blood_donor_management_system | Remote | Injection
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
7.5 HIGH
CVE-2026-90840 — PHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __construct impr…

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Co…

blood_donor_management_system | Remote | Authentication
Sep 15, 2026 Sep 15, 2026
Sep 15, 2026
Sep 15, 2026
5.4 MEDIUM
CVE-2026-91201 — DocsGPT through 0.20.0 OAuth Token Disclosure via Wildcard postMessage

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provi…

docsgpt | Remote | Information Disclosure
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.8 HIGH
CVE-2026-91200 — DevSpace through 6.3.21 Path Traversal via tar extraction

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal seque…

Remote | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.3 MEDIUM
CVE-2026-91199 — Refly through 1.1.0 Server-Side Request Forgery via scrape endpoint

Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved addres…

Remote | Server-Side Request Forgery
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.9 MEDIUM
CVE-2026-91198 — GrowthBook through 5.0.1 Information Disclosure via Public Endpoints

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge o…

Remote | Information Disclosure
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.1 HIGH
CVE-2026-91197 — Flowable flowable-engine through 8.0.0 XXE via ProcessDiagramLayoutFactory

Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing …

Remote | XML External Entity
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
4.0 MEDIUM
CVE-2026-90835 — michaelliao itranswarp Page Content Rendering Markdown.java Markdown.toHtml cross site sc…

A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation c…

itranswarp | Remote | Cross-Site Scripting
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
Showing 20 of 12965 Results