Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-28317 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower i…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28316 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the r…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
6.2 MEDIUM
CVE-2026-28315 — SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.

serv-u | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28314 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.

serv-u | Remote | Authentication
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28313 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deploym…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28312 — SolarWinds Serv-U Privilege Escalation Vulnerability

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows dep…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28310 — SolarWinds Serv-U Privilege Escalation Vulnerability

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows …

serv-u | Remote | Authorization
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28309 — SolarWinds Serv-U Broken Access Control Vulnerability

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.

serv-u | Remote | Authorization
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28308 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windo…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28307 — SolarWinds Serv-U Privilege Escalation Vulnerability

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.

serv-u | Remote | Authorization
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28306 — SolarWinds Serv-U Privilege Escalation Vulnerability

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployme…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28305 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write acc…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28304 — SolarWinds Serv-U Remote Code Execution Vulnerability

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.

serv-u | Remote | Injection
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.1 CRITICAL
CVE-2026-28302 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administra…

serv-u | Remote | Authorization
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
4.3 MEDIUM
CVE-2026-16450 — zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization

A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyB…

zs-admin | Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
6.5 MEDIUM
CVE-2026-16449 — zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql…

A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/de…

zs-admin | Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.8 HIGH
CVE-2026-8933 — snap-confine Local Privilege Escalation via Capabilities Misconfiguration or Flaw in Exec…

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applicat…

| Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.7 HIGH
CVE-2026-65052 — Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListS…

Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculatio…

ninja_forms | Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.9 MEDIUM
CVE-2026-65051 — Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in A…

Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging att…

ninja_forms | Remote | Authentication
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.1 HIGH
CVE-2026-65050 — Ninja Forms Missing Authorization in submissions-table Gutenberg Block Discloses Form Sub…

Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenti…

ninja_forms | Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
Showing 20 of 12302 Results