Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-28230 — In SteVe, any authenticated charger can terminate any other charger's active transaction …

SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger sends a StopTransaction message, SteVe looks up the transaction solely by transac…

steve | Remote | Authorization
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2026-28226 — Phishing Club has Authenticated Blind SQL Injection in GetOrphaned Recipient Listing

Phishing Club is a phishing simulation and man-in-the-middle framework. Prior to version 1.30.2, an authenticated SQL injection vulnerability exists in the GetOrphaned recipient listing endpoint in v…

phishing_club | Remote | Injection
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2026-28225 — Manyfold has IDOR in ModelFilesController

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version 0.133.1, the `get_model` method in `ModelFilesCon…

manyfold | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-28217 — IDOR in GraphQL userCollection Query Exposes Other Users' Private Collections

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection ID and returns the full collection data — includi…

hoppscotch | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.3 HIGH
CVE-2026-28216 — hoppscotch has IDOR in updateUserEnvironment / deleteUserEnvironment

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal environment by ID. `user-environments.resolver…

hoppscotch | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
9.1 CRITICAL
CVE-2026-28215 — hoppscotch Vulnerable to Unauthenticated Onboarding Config Takeover

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instan…

hoppscotch | Remote | Authentication
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
9.8 CRITICAL
CVE-2026-28213 — EverShop Vulnerable to Arbitrary Customer Account Takeover via Exposure of Password Reset…

EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the API response return…

evershop | Remote | Authentication
Feb 26, 2026 Feb 28, 2026
Feb 26, 2026
Feb 28, 2026
7.8 HIGH
CVE-2026-28211 — Arbitrary code execution in log reader via untrusted log file

The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability exists in versions 2.0 through 8.0 in the Log Reader feature of this add-on. A …

| Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
5.9 MEDIUM
CVE-2026-28208 — Junrar has arbitrary file write due to backslash path traversal bypass in LocalFolderExtr…

Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker…

junrar | Remote | Path Traversal
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
7.3 HIGH
CVE-2026-28207 — Zen-C Vulnerable to Command Injection via Malicious Output Filename

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C compiler allows local attackers to e…

zen_c | Injection
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
4.3 MEDIUM
CVE-2026-27839 — wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lo…

wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.objects.get(pk=pk)` — a raw ORM call…

wger | Remote | Authorization
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
3.5 LOW
CVE-2026-27838 — wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calling `self.get_object()`. In versions up to and including 2.4, ache keys are scop…

wger | Remote | Authorization
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
7.1 HIGH
CVE-2026-27638 — ActualBudget missing authorization in sync endpoints allows cross-user budget file access…

Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to …

actual | Remote | Authorization
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
8.8 HIGH
CVE-2026-3263 — go2ismail Asp.Net-Core-Inventory-Order-Management-System Security API improper authorizat…

A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the co…

Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
8.8 HIGH
CVE-2026-3262 — go2ismail Asp.Net-Core-Inventory-Order-Management-System Administrative redirect

A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulati…

asp.net-core-inventory-order-management-system | Remote | Information Disclosure
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-3261 — itsourcecode School Management System Setting index.php sql injection

A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argumen…

school_management_system | Remote | Injection
Feb 26, 2026 Feb 27, 2026
Feb 26, 2026
Feb 27, 2026
2.7 LOW
CVE-2026-28227 — Discourse Vulnerable to Unauthorized Topic Creation in Staff-Only Categories via Topic Ti…

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users can publish topics into staff-only categories via the `publish_to_category` topic timer…

discourse | Remote | Authorization
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
4.3 MEDIUM
CVE-2026-28219 — Privilege Escalation via Mass Assignment Allows Regular Users to Set Topics as Global Ban…

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an improper authorization check in the topic management logic allows authenticated users to modif…

discourse | Remote | Authorization
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
5.4 MEDIUM
CVE-2026-28218 — Discourse's Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Quer…

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugin allows any authenticated user to execute SQL que…

discourse | Remote | Authorization
Feb 26, 2026 Mar 02, 2026
Feb 26, 2026
Mar 02, 2026
4.3 MEDIUM
CVE-2026-27835 — wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout da…

wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet` and `MaxRepetitionsConfigViewSet` return all users' repetition config data bec…

wger | Remote | Authorization
Feb 26, 2026 Mar 03, 2026
Feb 26, 2026
Mar 03, 2026
Showing 20 of 5067 Results