Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-50290 — @asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString

SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and `url(javascript:` using simple regex, but could be bypassed…

Remote | Injection
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.7 HIGH
CVE-2026-50288 — @asymmetric-effort/specifyjs: URL parse failure silently allows request

SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently all…

Remote | Misconfiguration
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.5 HIGH
CVE-2026-30866 — Combodo iTop: Insecured access to uploaded images via sniffed url

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.

itop | Remote | Information Disclosure
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.3 HIGH
CVE-2026-30819 — Combodo iTop: Reflected XSS in /pages/ajax.render.php dashboard_id parameter

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboar…

itop | Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.5 HIGH
CVE-2026-27490 — Combodo iTop: Weak secret generation for inline image

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue h…

itop | Remote | Cryptography
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
5.3 MEDIUM
CVE-2026-27463 — Combodo iTop: Version disclosure via login page logo

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version…

itop | Remote | Information Disclosure
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.5 HIGH
CVE-2026-27462 — Combodo iTop: User enumeration via password reset

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, lea…

itop | Remote | Authentication
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.5 MEDIUM
CVE-2026-77795 — Dromara RuoYi-Vue-Plus Workflow Endpoint TestLeaveController improper authorization

A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/FlwCategoryController/FlwSpelController/TestLeaveCo…

ruoyi-vue-plus | Remote | Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
4.1 MEDIUM
CVE-2026-63466 — Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Sl…

Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function b…

Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.5 HIGH
CVE-2026-63462 — Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lo…

Remote | Denial of Service
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
5.5 MEDIUM
CVE-2026-63004 — Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enab…

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/we…

Remote | Server-Side Request Forgery
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
5.3 MEDIUM
CVE-2026-55850 — Element Web: A malicious homeserver can inject HTML in Element Web using its homepage

Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content…

Remote | Misconfiguration
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.2 HIGH
CVE-2026-54682 — DiscordChatExporter: Stored XSS in HTML export when markdown formatting is disabled

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and Forma…

| Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
4.1 MEDIUM
CVE-2026-54681 — DiscordChatExporter: HTML attribute injection via unescaped emoji name in HTML export

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates emoji.Name into the alt at…

| Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.0 HIGH
CVE-2026-54134 — OctoPrint: File exfiltration possible via query parameters on upload endpoints

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse request parameters diffe…

octoprint | Path Traversal
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
4.6 MEDIUM
CVE-2026-54073 — VeraCrypt: Hidden volume quick format weakens plausible deniability

VeraCrypt provides disk encryption with strong security based on TrueCrypt. From 1.26.6 until 1.26.29, file-hosted hidden volume creation forces quick format and the FormatNoFs function in src/Common…

veracrypt | Cryptography
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
7.8 HIGH
CVE-2026-54071 — BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/c…

BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PD…

| Misconfiguration
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.2 MEDIUM
CVE-2026-53762 — VeraCryp: wolfCrypt backend bypasses VeraCrypt PBKDF2 iteration count (non-default WOLFCR…

VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRYPT_BACKEND route SHA-256 and SHA-512 volume-header…

veracrypt | Cryptography
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
4.6 MEDIUM
CVE-2026-35163 — OctoPrint: XSS in Suppressed Command Notifications

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.comm…

octoprint | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.2 HIGH
CVE-2026-77237 — Missing type validation in xQueueAddToSet in FreeRTOS-Kernel

Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel …

freertos-kernel | Information Disclosure
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
Showing 20 of 11746 Results