Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-40534 — Synology DiskStation Manager Video API Cross-Site Scripting Vulnerability

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2…

diskstation_manager diskstation_manager | Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.3 MEDIUM
CVE-2026-40533 — Synology DiskStation Manager Information Exposure Vulnerability

An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attac…

diskstation_manager diskstation_manager | Remote | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.5 MEDIUM
CVE-2026-40532 — Synology DiskStation Manager Wallpaper Path Improper Access Control

A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to …

diskstation_manager diskstation_manager | Remote | Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.3 MEDIUM
CVE-2026-40531 — Synology DiskStation Manager File Operation Integer Overflow

An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to con…

diskstation_manager diskstation_manager | Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.0 HIGH
CVE-2026-40530 — Synology DiskStation Manager User API CRLF Injection

An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote au…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.0 MEDIUM
CVE-2026-21848 — HCL BigFix Service Management is affected by multiple security vulnerabilities.

HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized view…

Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.3 MEDIUM
CVE-2026-21822 — A path traversal vulnerability has been identified in HCL AppScan 360° (CVE-2026-21822).

HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outsi…

Remote | Path Traversal
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.8 CRITICAL
CVE-2026-13684 — Synology DiskStation Manager SCGI Improper Output Neutralization Vulnerability

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to rea…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
2.7 LOW
CVE-2026-13683 — Synology DiskStation Manager EventScheduler API SQL Injection

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9,…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.8 HIGH
CVE-2026-13673 — Synology DiskStation Manager LDAP API Improper Privilege Management Vulnerability

An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remot…

diskstation_manager diskstation_manager | Remote | Authorization
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
3.5 LOW
CVE-2026-13666 — Synology DiskStation Manager CRLF Injection Vulnerability

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 al…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.8 CRITICAL
CVE-2026-13639 — Synology DiskStation Manager Insufficient Entropy Vulnerability

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write a…

diskstation_manager diskstation_manager | Remote | Authentication
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
5.3 MEDIUM
CVE-2026-13635 — Synology DiskStation Manager Auth API Improper Output Encoding Vulnerability

An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to…

diskstation_manager diskstation_manager | Remote | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.8 MEDIUM
CVE-2026-13623 — Synology DiskStation Manager Theme API Cross-Site Scripting Vulnerability

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86…

diskstation_manager diskstation_manager | Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.4 MEDIUM
CVE-2025-13533 — CSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Administrator+) Stored Cross-Site Scr…

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 12.0.6 via the Assignment Engine fields. This is due to insufficie…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-93494 — Netty: netty-codec-stomp: io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubfram…

A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This ca…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
0.0 NA
CVE-2026-93493 — Netty: netty-handler-ssl-ocsp: io.netty/netty-handler-ssl-ocsp: netty: ocsp validation si…

A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the opti…

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.4 MEDIUM
CVE-2026-92622 — Strong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and including, 3.3.8 due to insufficient inpu…

strong_testimonials | Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.1 MEDIUM
CVE-2026-92554 — ShopLentor <= 3.5.1 - Reflected Cross-Site Scripting via Query-String Parameter Name

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query-String Parameter Name in all versions up to, a…

Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.1 MEDIUM
CVE-2026-92249 — Qi Addons For Elementor <= 1.11 - Reflected DOM-Based Cross-Site Scripting via 's' Parame…

The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitizatio…

qi_addons_for_elementor | Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
Showing 20 of 14484 Results