Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.1 MEDIUM
CVE-2026-81814 — Flowintel Stored XSS in Calendar via Malicious Case Title

Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case titles, a user able to create or modify a case title could store HTML or script…

Remote | Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.1 MEDIUM
CVE-2026-81753 — Flowintel Stored XSS in Case Notes via Malicious Mermaid Diagram Content

Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing attacker-controlled markup. Because Mermaid note content is persisted and later r…

Remote | Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-81743 — Flowintel Arbitrary Log File Path Allows Remote Code Execution via Template Injection

Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without restricting it to a filename inside the intended log directory. Because the appl…

Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.8 HIGH
CVE-2026-81677 — Multiple Vulnerabilities in TOOOLS' iSquad

The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks the underlying structur…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.8 HIGH
CVE-2026-81676 — Multiple Vulnerabilities in TOOOLS' iSquad

A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.3 CRITICAL
CVE-2026-81675 — Multiple Vulnerabilities in TOOOLS' iSquad

The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes groupi…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.3 CRITICAL
CVE-2026-81674 — Multiple Vulnerabilities in TOOOLS' iSquad

The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.3 CRITICAL
CVE-2026-81673 — Multiple Vulnerabilities in TOOOLS' iSquad

The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. The application does not validate or sanitize these inputs before including them …

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.3 CRITICAL
CVE-2026-81672 — Multiple Vulnerabilities in TOOOLS' iSquad

SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL querie…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.4 MEDIUM
CVE-2026-81668 — Rubygem-katello: cross-tenant content view filter rule access and modification via unauth…

A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View …

satellite satellite | Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.6 HIGH
CVE-2026-81662 — Flowintel Alert Settings Configuration Allows Remote Code Execution via Arbitrary Configu…

Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. While configuration values were normalized to Python literals, the corresponding ke…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.1 HIGH
CVE-2026-81659 — Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX Processing

Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read an…

Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.5 MEDIUM
CVE-2026-81658 — Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup

A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a temp…

satellite satellite | Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.3 MEDIUM
CVE-2026-81562 — AlexGladkov claude-in-mobile client.ts execSync os command injection

A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection…

| Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.5 MEDIUM
CVE-2026-81560 — blackms aistack Static File server.ts path traversal

A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulati…

Remote | Path Traversal
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.8 CRITICAL
CVE-2026-74233 — Zbtlink MQWrt infosrvd Command Injection

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P f…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
9.8 CRITICAL
CVE-2026-74232 — Zbtlink MQWrt yunmgrd Cloud C2 Implant

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, M…

Remote | Authentication
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.6 HIGH
CVE-2026-66155 — Element maps-ng Cross-Site Scripting Vulnerability

A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map componen…

Remote | Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
4.3 MEDIUM
CVE-2026-5218 — HTML Injection in Softtr's E-Commerce Pack

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS).…

Remote | Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.5 MEDIUM
CVE-2026-17562 — IDOR in Zirve Security's AdisyonPro

Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AdisyonPro: b…

Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Showing 20 of 12220 Results