Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-67596 — CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg

CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-by…

| Cryptography
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.8 HIGH
CVE-2026-58222 — Samba: samba ad ldap compare filter injection and trusted-request confusion disclose prot…

A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to …

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.3 MEDIUM
CVE-2026-58216 — Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might cause the serv…

An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, S…

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.5 HIGH
CVE-2026-57862 — Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation

Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controll…

Remote | Server-Side Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-52680 — Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endp…

kyuubi | Path Traversal
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
9.8 CRITICAL
CVE-2026-4978 — SQLi in UMAI Vision's Traffic Analysis System

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis Sy…

Remote | Injection
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-48910 — Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing

A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the vi…

jspwiki | Cross-Site Scripting
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-44617 — Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special …

zeppelin | Injection
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-44616 — Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP fi…

zeppelin | Injection
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-44613 — Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling

Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an att…

zeppelin | Cross-Site Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-28814 — Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to …

jspwiki | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-28813 — Apache JSPWiki: JSPWiki vulnerable to JSON hijacking

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

jspwiki | Cross-Site Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-28812 — Apache JSPWiki: UserManager does not sanity-check user database at startup

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixe…

jspwiki | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-28811 — Apache JSPWiki: Error Handling - Reveals Error Details

Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

jspwiki | Information Disclosure
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
9.8 CRITICAL
CVE-2026-28323 — SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

web_help_desk | Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.3 MEDIUM
CVE-2026-23985 — Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within th…

superset | Remote | Denial of Service
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.3 MEDIUM
CVE-2026-23981 — Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification

An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updating a chart's proper…

superset | Remote | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-15658 — foreUP customer REST API allows unauthenticated endpoint access

A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns t…

| Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-15657 — foreUP customer REST API allows authenticated users to read cleartext payment-processor m…

A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.

| Information Disclosure
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.5 HIGH
CVE-2026-10842 — IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by…

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constra…

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
Showing 20 of 10029 Results