Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-64857 — tirreno has Session Fixation in Login Authentication

tirreno, a security framework, has a session fixation issue in versions prior to 0.10.0. During authentication, tirreno validates the user's credentials and establishes the authenticated session, but…

| Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.5 HIGH
CVE-2026-79950 — Dell Secure Connect Gateway Use of Hard-coded Credentials Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker wit…

Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.8 HIGH
CVE-2026-86775 — knowns before 0.30.0 Path Traversal via Document API

knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in internal/server/routes/docs.go normalizes the user-supplied document path with …

Remote | Path Traversal
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
6.3 MEDIUM
CVE-2026-86774 — Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy

Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-86773 — Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints

Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predef…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-86772 — Snipe-IT 8.6.3 Stored XSS via Department Names

Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for…

Remote | Cross-Site Scripting
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.3 HIGH
CVE-2026-86771 — Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num

Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() fu…

Remote | Server-Side Request Forgery
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.6 HIGH
CVE-2026-86770 — Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case var…

Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-86769 — Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout

Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column inst…

Remote | Misconfiguration
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-86768 — Snipe-IT before 8.7.0 Improper Input Validation via API Checkout

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can s…

Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-86767 — Snipe-IT before 8.7.0 Cross-Company Read via requested-assets

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.vi…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86766 — Snipe-IT 8.6.3 Race Condition via Consumable Checkout

Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout). The requested quantity is va…

Remote | Race Condition
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86765 — Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86764 — Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.1 MEDIUM
CVE-2026-86763 — snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer

Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.6 HIGH
CVE-2026-86762 — Snipe-IT before 8.7.0 Authentication Bypass via API Middleware

Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal ac…

Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-86761 — snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints

snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to enforce per-model authorization checks. Authenticated attackers with location vi…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-86760 — snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag

Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activat…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86759 — Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV fi…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86758 — Snipe-IT before 8.7.0 License Key Exposure via CSV Export

Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access produc…

Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
Showing 20 of 13980 Results