Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.3 HIGH
CVE-2026-28216 — hoppscotch has IDOR in updateUserEnvironment / deleteUserEnvironment

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal environment by ID. `user-environments.resolver…

hoppscotch | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
9.1 CRITICAL
CVE-2026-28215 — hoppscotch Vulnerable to Unauthenticated Onboarding Config Takeover

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instan…

hoppscotch | Remote | Authentication
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-28213 — EverShop Vulnerable to Arbitrary Customer Account Takeover via Exposure of Password Reset…

EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the API response return…

evershop | Remote | Authentication
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
7.8 HIGH
CVE-2026-28211 — Arbitrary code execution in log reader via untrusted log file

The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability exists in versions 2.0 through 8.0 in the Log Reader feature of this add-on. A …

| Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
5.9 MEDIUM
CVE-2026-28208 — Junrar has arbitrary file write due to backslash path traversal bypass in LocalFolderExtr…

Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker…

junrar | Remote | Path Traversal
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
7.3 HIGH
CVE-2026-28207 — Zen-C Vulnerable to Command Injection via Malicious Output Filename

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C compiler allows local attackers to e…

zen_c | Injection
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
4.3 MEDIUM
CVE-2026-27839 — wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lo…

wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.objects.get(pk=pk)` — a raw ORM call…

wger | Remote | Authorization
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
3.5 LOW
CVE-2026-27838 — wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calling `self.get_object()`. In versions up to and including 2.4, ache keys are scop…

wger | Remote | Authorization
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
7.1 HIGH
CVE-2026-27638 — ActualBudget missing authorization in sync endpoints allows cross-user budget file access…

Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to …

actual | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-3263 — go2ismail Asp.Net-Core-Inventory-Order-Management-System Security API improper authorizat…

A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the co…

Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
8.8 HIGH
CVE-2026-3262 — go2ismail Asp.Net-Core-Inventory-Order-Management-System Administrative redirect

A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulati…

asp.net-core-inventory-order-management-system | Remote | Information Disclosure
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-3261 — itsourcecode School Management System Setting index.php sql injection

A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argumen…

school_management_system | Remote | Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
2.7 LOW
CVE-2026-28227 — Discourse Vulnerable to Unauthorized Topic Creation in Staff-Only Categories via Topic Ti…

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users can publish topics into staff-only categories via the `publish_to_category` topic timer…

discourse | Remote | Authorization
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
4.3 MEDIUM
CVE-2026-28219 — Privilege Escalation via Mass Assignment Allows Regular Users to Set Topics as Global Ban…

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an improper authorization check in the topic management logic allows authenticated users to modif…

discourse | Remote | Authorization
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
5.4 MEDIUM
CVE-2026-28218 — Discourse's Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Quer…

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugin allows any authenticated user to execute SQL que…

discourse | Remote | Authorization
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
4.3 MEDIUM
CVE-2026-27835 — wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout da…

wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet` and `MaxRepetitionsConfigViewSet` return all users' repetition config data bec…

wger | Remote | Authorization
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
4.3 MEDIUM
CVE-2026-27457 — Weblate: Missing access control for the AddonViewSet API exposes all addon configurations

Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_quer…

weblate | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
7.5 HIGH
CVE-2026-27449 — Umbraco.Engage.Forms Allows Unauthorized Access to Multiple API Endpoints

Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing…

Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.1 MEDIUM
CVE-2026-27154 — Discourse has XSS when editing a malicious post

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, a user full name can be evaluated as raw HTML when the following settings are set: `display_name_…

discourse | Remote | Cross-Site Scripting
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
2.7 LOW
CVE-2026-27153 — Discourse doesn't prevent moderators from exporting user Chat DMs

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, moderators could export user Chat DMs via the CSV export endpoint by exploiting an overly permiss…

discourse | Remote | Authorization
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
Showing 20 of 5225 Results