Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-26246 — Memory Exhaustion via Malformed PSD File Upload

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memo…

Remote | Denial of Service
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2026-4236 — itsourcecode Online Enrollment System index.php sql injection

A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=add. Such manipulation of the argument …

| Injection
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
4.3 MEDIUM
CVE-2026-2458 — Unauthorized channel enumeration in private teams after member removal

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all publi…

Remote | Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
4.3 MEDIUM
CVE-2026-2457 — WebSocket Message Spoofing via Permalink Embed Manipulation

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonati…

Remote | Authentication
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
4.3 MEDIUM
CVE-2026-2461 — Missing authorization check allows unauthorized modification of other users' comments on …

Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify…

Remote | Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
4.3 MEDIUM
CVE-2026-2463 — Unauthorized access to invite ID during team creation

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and r…

Remote | Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.6 HIGH
CVE-2026-2476 — MS Teams plugin sensitive config values not properly masked in support packets

Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported conf…

Remote | Information Disclosure
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.3 MEDIUM
CVE-2026-2456 — Denial of Service via Unbounded Memory Allocation in Integration Actions

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action endpoints, which allows an authenticated attacker t…

Remote | Denial of Service
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2026-4235 — itsourcecode Online Enrollment System login.php sql injection

A weakness has been identified in itsourcecode Online Enrollment System 1.0. This issue affects some unknown processing of the file /sms/login.php. This manipulation of the argument user_email causes…

| Injection
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
6.0 MEDIUM
CVE-2025-15554 — Admin Passwords Cached by Browsers in Truesec LAPSWebUI

Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.

| Information Disclosure
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
6.0 MEDIUM
CVE-2025-15553 — Insecure Logout Functionality in Truesec LAPSWebUI

Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.

| Authentication
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
6.0 MEDIUM
CVE-2025-15552 — Long Session Lifetime in Truesec LAPSWebUI

Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.

| Information Disclosure
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2026-4234 — SSCMS DDL SitesAddController.Submit.cs sql injection

A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddController.Submit.cs of the component DDL Handler. The manipulation of the argument tab…

| Injection
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
4.8 MEDIUM
CVE-2026-3024 — Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma application web

Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/configuracion/agenda/modelo-formulario-evento'. A user with permission to …

Remote | Cross-Site Scripting
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
5.3 MEDIUM
CVE-2026-3023 — Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma application web

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/pets/print-tags'. This vulnerability could allow an authenticated user…

Remote | Injection
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.1 HIGH
CVE-2026-3022 — Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma application web

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/hospitalization/generate-hospitalization-summary'. This vulnerability …

Remote | Injection
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
7.1 HIGH
CVE-2026-3021 — Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma application web

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/centro/equipo/empleado'. This vulnerability could allow an authenticat…

Remote | Injection
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
8.6 HIGH
CVE-2026-3020 — Identity based authorization bypass vulnerability (IDOR) in the Wakyma application web

Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user account, such as changing the victim's email address, validating the new email…

Remote | Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
0.0 NA
CVE-2026-4233 — ThingsGateway download path traversal

A vulnerability was identified in ThingsGateway 12. This affects an unknown part of the file /api/file/download. The manipulation of the argument fileName leads to path traversal. Remote exploitation…

| Path Traversal
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
6.9 MEDIUM
CVE-2026-3111 — Multiple vulnerabilities on the Educativa Campus

Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuarios/[ID]/[username]/thumb_AAxAA.jpg' (translated as 80x90 and 40x45). Successful…

Remote | Authorization
Mar 16, 2026 Mar 16, 2026
Mar 16, 2026
Mar 16, 2026
Showing 20 of 5319 Results