Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-85516 — code-projects Vehicle Management System busprofile.php sql injection

A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid r…

Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.9 HIGH
CVE-2026-85649 — Actualizer Password Validation Bypass Vulnerability

(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The …

| Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-85514 — StackStorm st2 API Key auth.py privileges management

A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component API Key Handler. Such manip…

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-85513 — StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management

A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecu…

| Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.5 MEDIUM
CVE-2026-74237 — GFI Exinda AI < 7.6.5 Argument Injection via Tools Iperf Client

GFI Exinda AI before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an iperf command using the server and options …

Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.5 MEDIUM
CVE-2026-74236 — GFI Exinda AI < 7.6.5 Path Traversal via Diagnostic File Deletion Handler

GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and append…

Remote | Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
4.9 MEDIUM
CVE-2026-74235 — GFI Exinda AI < 7.6.5 Path Traversal via Configuration Download Handler

GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_…

Remote | Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-82309 — Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS …

Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns i…

| Denial of Service
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.8 HIGH
CVE-2026-85617 — snipe-it before 8.6.3 Authorization Bypass via Bulk Delete

snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attacke…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.5 HIGH
CVE-2026-85616 — Snipe-IT before 8.6.2 Authorization Bypass via Checkout-Acceptance

Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.4 MEDIUM
CVE-2026-85615 — Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts

Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized proje…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
9.2 CRITICAL
CVE-2026-85614 — OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker

OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no priva…

Remote | Server-Side Request Forgery
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.4 HIGH
CVE-2026-85613 — OpenPanel Unauthenticated XSS via SVG Favicon Proxy

OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SV…

Remote | Cross-Site Scripting
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.7 HIGH
CVE-2026-85612 — OpenPanel before 2.3.0 SSRF via favicon and og endpoints

OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficie…

Remote | Server-Side Request Forgery
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.4 MEDIUM
CVE-2026-85611 — OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures

OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to …

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.8 HIGH
CVE-2026-85610 — OpenPanel before 2.3.0 Remote Code Execution via chart formulas

OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Func…

Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-85609 — Openpanel before 2.3.0 SSRF via Site Checker Endpoint

Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). T…

Remote | Server-Side Request Forgery
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.8 HIGH
CVE-2026-85604 — Grav before 2.0.19 Remote Code Execution via sort filter

Grav before 2.0.19 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argumen…

grav | Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.1 HIGH
CVE-2026-85603 — Grav Admin Plugin Path Traversal via Save As Language Code

Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pag…

grav | Remote | Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
9.3 CRITICAL
CVE-2026-85602 — Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass

The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On…

grav | Remote | Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
Showing 20 of 12549 Results