Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-80138 — ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepat…

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to …

clipbucket | Remote | Injection
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
8.3 HIGH
CVE-2026-79912 — TOTOLINK N600R cstecgi.cgi getCurrentTime command injection

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument …

n600r_firmware n600r | Remote | Injection
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
10.0 CRITICAL
CVE-2026-79911 — TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow

A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler…

n600r_firmware n600r | Remote | Memory Corruption
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
4.2 MEDIUM
CVE-2026-70665 — Doorkeeper OpenID Connect: DCR endpoint persists unvalidated client-supplied scopes

Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists cl…

Remote | Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-55805 — Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6…

drupal | Cross-Site Scripting
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.8 HIGH
CVE-2026-54757 — Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of…

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server…

| Injection
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.3 MEDIUM
CVE-2026-44476 — Doorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients wit…

Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that cl…

Remote | Authentication
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.4 HIGH
CVE-2026-41707 — Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay

Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitima…

spring_security | Remote | Denial of Service
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-18985 — Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093

Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.

| Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-18261 — Powerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092

Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.

Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-18260 — Disable Login Page - Critical - Unsupported - SA-CONTRIB-2026-091

Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.

disable_login_page | Misconfiguration
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-18259 — Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090

Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.

| Authentication
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-16646 — PanKM - Critical - Unsupported - SA-CONTRIB-2026-083

Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.

| Misconfiguration
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-16645 — PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Access byp…

Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Galler…

| Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-16644 — Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087

Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.

| Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-16643 — Lunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086

Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.

| Misconfiguration
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-16642 — Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085

Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.

| Authentication
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-16641 — Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084

Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.

| Misconfiguration
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-16640 — Search API Autocomplete - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-082

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete v…

| Cross-Site Scripting
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
0.0 NA
CVE-2026-16639 — Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-…

| Authentication
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
Showing 20 of 12296 Results