Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-75079 — SourceCodester Class and Exam Timetabling System edit_subject2.php sql injection

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argumen…

class_and_exam_timetabling_system | Remote | Injection
Aug 18, 2026 Aug 20, 2026
Aug 18, 2026
Aug 20, 2026
3.5 LOW
CVE-2026-9693 — Mattermost thread memberships persist after team removal, exposing private channel thread…

Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who…

Aug 17, 2026 Aug 19, 2026
Aug 17, 2026
Aug 19, 2026
3.6 LOW
CVE-2026-75587 — Plaintext pre-auth secret exposure via Desktop App diagnostics report

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log …

mattermost_desktop legal_hold | Information Disclosure
Aug 17, 2026 Aug 19, 2026
Aug 17, 2026
Aug 19, 2026
5.0 MEDIUM
CVE-2026-75078 — SourceCodester Class and Exam Timetabling System BSHRM1.php cross site scripting

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course res…

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Aug 17, 2026 Aug 20, 2026
Aug 17, 2026
Aug 20, 2026
7.8 HIGH
CVE-2026-67961 — O2OA Sandbox Remote Code Execution

An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.

| Injection
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-67919 — Halo Remote Code Execution Vulnerability

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components

Remote | Injection
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
9.8 CRITICAL
CVE-2026-42164 — Mahara Text Block Cross-Section Information Disclosure

Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text sectio…

Remote | Information Disclosure
Aug 17, 2026 Aug 31, 2026
Aug 17, 2026
Aug 31, 2026
9.1 CRITICAL
CVE-2026-42162 — Mahara Artefact Unauthorized Access Vulnerability

Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.

Remote | Path Traversal
Aug 17, 2026 Aug 31, 2026
Aug 17, 2026
Aug 31, 2026
9.8 CRITICAL
CVE-2026-38165 — XDocReport Server-Side Template Injection

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.

Remote | Injection
Aug 17, 2026 Sep 09, 2026
Aug 17, 2026
Sep 09, 2026
Showing 20 of 14809 Results