Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-41262 — Fleet: Cross-Team Policy Data Exposure via Global Policy Read Endpoint

Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team own…

fleet | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.2 HIGH
CVE-2026-71171 — Dell Cloud Disaster Recovery OS Command Injection Vulnerability

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high priv…

cloud_disaster_recovery | Remote | Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-48786 — Fleet: Observer-class users can view team enroll secrets and credential-bearing configura…

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and…

fleet | Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
9.1 CRITICAL
CVE-2026-70419 — Dell Cloud Disaster Recovery OS Command Injection Vulnerability

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker …

cloud_disaster_recovery | Remote | Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.7 HIGH
CVE-2026-76784 — Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple…

Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally…

kp303 | Cryptography
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.8 HIGH
CVE-2026-58474 — whichllm < 0.5.16 Code Injection via run and snippet commands

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution …

Remote | Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
5.9 MEDIUM
CVE-2026-79940 — Dell iDRAC Improper Access Control Vulnerability

Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access could potent…

idrac9 idrac9 | Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
5.4 MEDIUM
CVE-2026-54256 — Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attac…

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget trusted an attacker-controlled file_id POST pa…

winter | Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.4 HIGH
CVE-2026-47841 — WebAuthn User Verification Bypass via Session Serialization

An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 …

Remote | Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
6.8 MEDIUM
CVE-2026-47837 — Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affec…

Remote | Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.2 HIGH
CVE-2026-47836 — Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cl…

| Misconfiguration
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
6.8 MEDIUM
CVE-2026-32639 — Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions an…

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type pe…

winter | Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
5.9 MEDIUM
CVE-2026-32593 — Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange …

winter | Remote | Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2025-56798 — Unraid OS Cross-Site Request Forgery Privilege Escalation

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's …

| Cross-Site Request Forgery
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2025-29419 — CTFd Man-in-the-Middle Vulnerability

CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.

| Cryptography
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2023-42179 — Bird Home Automation GmbH D1101V-F Incorrect Access Control

Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.

| Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-63179 — Winter: Local File Inclusion through @import directives in LESS compilation of backend cu…

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP proc…

winter | Path Traversal
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
9.3 CRITICAL
CVE-2026-19485 — Bucket Squatting in Vertex AI Search for Commerce

A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the…

Remote | Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.1 HIGH
CVE-2026-35445 — Winter: Authenticated backend users can bypass Users controller permission checks

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler P…

winter | Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.1 HIGH
CVE-2026-32258 — Winter: Stored XSS through Editor Settings custom styles

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can…

winter | Remote | Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
Showing 20 of 12328 Results