Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.7 LOW
CVE-2026-75773 — karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication

A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation r…

karakeep | Remote | Authentication
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
9.8 CRITICAL
CVE-2026-75627 — Bastillion Authentication Bypass via Path-Prefix Routing Mismatch

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path seg…

Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
9.3 CRITICAL
CVE-2026-75626 — SpiderFoot Stored Cross-Site Scripting via Correlation Titles

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into c…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 19, 2026
Aug 18, 2026
Aug 19, 2026
5.3 MEDIUM
CVE-2026-19608 — Keycloak-services: keycloak-services: name-only group claims let same-name groups satisfy…

A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. The issue occurs when the system evaluates group-ba…

single_sign-on build_of_keycloak | Remote | Authorization
Aug 18, 2026 Aug 18, 2026
Aug 18, 2026
Aug 18, 2026
5.4 MEDIUM
CVE-2026-19447 — Stored XSS in Fileorbis Informatics's FileOrbis

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileOrbis allows Stored XSS. This issue affects FileOr…

Remote | Cross-Site Scripting
Aug 18, 2026 Aug 26, 2026
Aug 18, 2026
Aug 26, 2026
6.5 MEDIUM
CVE-2024-14046 — OpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestr…

A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.gr…

openboxes | Remote | Misconfiguration
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
6.9 MEDIUM
CVE-2026-18929 — Resource Exhaustion in Carbone

Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip decompression without validating entry sizes, allowin…

Remote | Denial of Service
Aug 18, 2026 Aug 28, 2026
Aug 18, 2026
Aug 28, 2026
6.3 MEDIUM
CVE-2026-43971 — Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/1

Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib int…

cowlib | Remote | Injection
Aug 18, 2026 Sep 16, 2026
Aug 18, 2026
Sep 16, 2026
6.5 MEDIUM
CVE-2024-14045 — OpenBoxes Product Supplier Edit Controller RoleInterceptor.groovy improper authorization

A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product S…

openboxes | Remote | Authorization
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
9.8 CRITICAL
CVE-2026-34884 — Apache SkyWalking MCP: SSRF via set_skywalking_url Tool and GraphQL Expression Injection …

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to ve…

skywalking_mcp | Remote | Server-Side Request Forgery
Aug 18, 2026 Sep 02, 2026
Aug 18, 2026
Sep 02, 2026
8.1 HIGH
CVE-2026-15371 — Velociraptor Stored XSS in URL column types

Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes all…

velociraptor | Remote | Cross-Site Scripting
Aug 18, 2026 Aug 28, 2026
Aug 18, 2026
Aug 28, 2026
7.2 HIGH
CVE-2026-75091 — Quill Forms <= 5.7.1 - Unauthenticated Stored Cross-Site Scripting

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient …

quill_forms | Remote | Cross-Site Scripting
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
9.8 CRITICAL
CVE-2026-15748 — Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Fiel…

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file typ…

forminator | Remote | Misconfiguration
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
5.3 MEDIUM
CVE-2026-75151 — SourceCodester Onlne Examination & Learning Management System cross-site request forgery

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site r…

onlne_examination_learning_management_system | Remote | Cross-Site Request Forgery
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-11801 — WPAdverts <= 2.3.2 - Missing Authorization to Unauthenticated Sensitive Information Discl…

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user…

Remote | Authorization
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
9.1 CRITICAL
CVE-2026-75094 — COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation…

cf-n1-s | Remote | Injection
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
5.0 MEDIUM
CVE-2026-75093 — sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size

A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_align of the file data/src/tensor.rs of the component ONNX Initializer Loader. Su…

tract | Remote | Memory Corruption
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
5.0 MEDIUM
CVE-2026-75090 — EricLBuehler Mistral.rs GGUF Tokenizer gguf_tokenizer.rs convert_gguf_to_hf_tokenizer out…

A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_gguf_to_hf_tokenizer of the file mistralrs-core/src/gguf/gguf_tokenizer.rs of the …

mistral.rs | Remote | Memory Corruption
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-75089 — PHPGurukul Complaint Management System check_availability.php sql injection

A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation of the ar…

complaint_management_system | Remote | Injection
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-75088 — itsourcecode Hospital Management System viewbilling.php sql injection

A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executing a manipulation of the argument delid can lead t…

hospital_management_system | Remote | Injection
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
Showing 20 of 14814 Results