Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-75080 — SourceCodester Class and Exam Timetabling System edit_subject1.php sql injection

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the …

Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
3.5 LOW
CVE-2026-9693 — Mattermost thread memberships persist after team removal, exposing private channel thread…

Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who…

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
3.6 LOW
CVE-2026-75587 — Plaintext pre-auth secret exposure via Desktop App diagnostics report

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log …

| Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.0 MEDIUM
CVE-2026-75078 — SourceCodester Class and Exam Timetabling System BSHRM1.php cross site scripting

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course res…

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-67961 — O2OA Sandbox Remote Code Execution

An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.

| Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-67919 — Halo Remote Code Execution Vulnerability

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components

| Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-42164 — Mahara Text Block Cross-Section Information Disclosure

Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text sectio…

| Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-42162 — Mahara Artefact Unauthorized Access Vulnerability

Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.

| Path Traversal
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-38165 — XDocReport Server-Side Template Injection

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.

| Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-75079 — SourceCodester Class and Exam Timetabling System edit_subject2.php sql injection

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argumen…

Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-9859 — Mattermost Boards plugin didn’t enforce role-based authorization on board channel link al…

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated boar…

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.3 HIGH
CVE-2026-9816 — Insufficient server-side validation of board member role fields permits privilege escalat…

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or n…

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.0 MEDIUM
CVE-2026-75077 — SourceCodester Class and Exam Timetabling System BSCE2.php cross site scripting

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such manipulation of the argument …

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.6 CRITICAL
CVE-2026-71424 — Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers

Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization h…

Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.1 HIGH
CVE-2026-69148 — MLflow: CreateModelVersion source validation does not check READ permission on referenced…

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_sourc…

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-69146 — MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlfl…

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-67960 — PbootCMS Arbitrary Code Execution Vulnerability

An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components

| Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-67918 — Hermes Studio Directory Traversal Vulnerability

Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint

| Path Traversal
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-67868 — S2OPC Heap-Based Out-of-Bounds Write Vulnerability

A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary cod…

| Memory Corruption
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-67854 — Qcms SQL Injection Vulnerability

SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

| Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
Showing 20 of 11337 Results