Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-53525 — WeeChat has Non-Constant-Time Password Hash Comparison in Relay Authentication

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcas…

| Authentication
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
0.0 NA
CVE-2026-53524 — WeeChat has a Decompression Bomb in Relay WebSocket (DoS)

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_infl…

| Denial of Service
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.9 MEDIUM
CVE-2026-53531 — ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left…

Remote | Denial of Service
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.7 HIGH
CVE-2026-53530 — ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint `ratex_parser::parse(&str)` panics on the 9-byte input `\verbéxé` (i.e. `\verb…

Remote | Denial of Service
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
4.8 MEDIUM
CVE-2026-53529 — LeafWiki vulnerable to stored XSS via search-result title (highlight() returns raw title …

LeafWiki is a self-hosted wiki. Prior to version 0.10.2, page titles returned by the search API could be rendered as raw HTML in the frontend. A user with editor or administrator permissions could cr…

Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-53528 — FileWiki has path traversal in RenameAsset via unsanitized oldFilename parameter

LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move fi…

Remote | Path Traversal
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-53527 — LeafWiki Vulnerable to Privilege Escalation via User Self-Service Update

LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate …

Remote | Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
5.7 MEDIUM
CVE-2026-53509 — @aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potentia…

CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had…

Remote | Server-Side Request Forgery
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
5.3 MEDIUM
CVE-2026-53497 — CrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (…

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all…

Remote | Information Disclosure
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
4.3 MEDIUM
CVE-2026-53487 — Kite has an authenticated cluster RBAC bypass in /api/v1/overview

Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster w…

Remote | Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
4.6 MEDIUM
CVE-2026-53468 — Typemill has Stored HTML Attribute Injection in Metadata Fields

Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Versions prior to 2.23.0 are vulnerable to stored HTML attribute injection in the …

Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
9.1 CRITICAL
CVE-2026-49849 — xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitra…

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By u…

Remote | Authentication
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.3 MEDIUM
CVE-2026-43980 — Malla: Stored XSS via Meshtastic node names in multiple frontend pages

Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite…

Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
6.5 MEDIUM
CVE-2026-34836 — Combodo iTop: Improper access control in ajax.render.php and ajax.document.php

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permission…

itop | Remote | Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.6 HIGH
CVE-2026-34741 — Combodo iTop: Authentication bypass in exec.php allows PHP file execution

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory …

itop | Remote | Authentication
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
3.5 LOW
CVE-2026-33333 — Combodo iTop: Information disclosure in ajax.render.php

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.

itop | Remote | Information Disclosure
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-33240 — Combodo iTop: Reflected XSS in foreign key search criteria

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixe…

itop | Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
4.3 MEDIUM
CVE-2026-33047 — Combodo iTop: Object can be locked by a user without write permissions

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not assigned write permissions. This issue has been fixed in version 3.2.3.

itop | Remote | Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.8 HIGH
CVE-2026-31936 — Combodo iTop: Unauthorized access to object information via search operation

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3.

itop | Remote | Authorization
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
8.7 HIGH
CVE-2026-77811 — Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards

Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute a…

Remote | Cross-Site Scripting
Aug 21, 2026 Aug 21, 2026
Aug 21, 2026
Aug 21, 2026
Showing 20 of 11745 Results