Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-78337 — Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-…

Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permis…

prospero_flow_crm | Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-78245 — itsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unr…

A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manip…

| Misconfiguration
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
0.0 NA
CVE-2026-78244 — itsourcecode Real Estate Management System search.php sql injection

A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument …

| Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.4 MEDIUM
CVE-2026-10618 — Hugo 0.93.0 through 0.165.0 Stored Cross-Site Scripting via Unescaped Code-Fence Attribut…

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go c…

| Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.3 HIGH
CVE-2026-10582 — Hugo 0.91.0 through 0.165.0 Server-Side Request Forgery via security.http.urls Lacking De…

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go a…

| Server-Side Request Forgery
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-78317 — DIAEnergie - SQL Injection

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

diaenergie | Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-78316 — DIAEnergie - SQL Injection

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

diaenergie | Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-78315 — DIAEnergie - SQL Injection

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

diaenergie | Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.8 HIGH
CVE-2026-78314 — DIAEnergie - SQL Injection

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

diaenergie | Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-75975 — fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and…

Remote | Server-Side Request Forgery
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-75931 — fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative…

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes i…

Remote | Misconfiguration
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-75899 — fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to no…

Remote | Server-Side Request Forgery
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.9 CRITICAL
CVE-2026-66897 — Instance template path traversal allows arbitrary host file write as root

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the hos…

lxd | Remote | Path Traversal
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.9 MEDIUM
CVE-2026-59295 — Micrometer Instrumentation of Apache HttpAsyncClient Denial of Service Vulnerability

Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when asynchronous requests fail before receiving a response (e.g. con…

Remote | Memory Corruption
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.5 HIGH
CVE-2026-76172 — fast-uri vulnerable to host confusion via percent-encoded scheme normalization

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, u…

| Server-Side Request Forgery
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.0 MEDIUM
CVE-2026-78321 — DJI Drone HTTP Media Server Denial of Service via Connection Pool Exhaustion

The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's conne…

mavic_3 mini_2 | Denial of Service
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.5 HIGH
CVE-2026-78306 — DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution

DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC addres…

mavic_3 mini_2 | Misconfiguration
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.7 HIGH
CVE-2026-78255 — DJI Drone HTTP Media Server Allows Unauthenticated Access to Stored Media

The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing a…

mavic_3 mini_2 | Remote | Authentication
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.3 CRITICAL
CVE-2026-77994 — Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5

Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method o…

Remote | Injection
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
5.3 MEDIUM
CVE-2026-77993 — Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5

Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected XSS via the iscontenttype parameter.

Remote | Cross-Site Scripting
Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11233 Results