Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.6 MEDIUM
CVE-2026-1628 — Mattermost allows external websites to open within the app, exposing preload functionalit…

Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functiona…

mattermost_server mattermost_desktop | Remote | Misconfiguration
Mar 02, 2026 Mar 05, 2026
Mar 02, 2026
Mar 05, 2026
9.3 CRITICAL
CVE-2026-3432 — Sim Studio AI - Unauthenticated OAuth Token Theft

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` pa…

sim | Remote | Authorization
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2026-3431 — Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these end…

sim | Remote | Authentication
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2025-14532 — Remote Code Execution via Unrestricted File Upload in DobryCMS

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue wa…

dorbycms | Remote | Misconfiguration
Mar 02, 2026 Mar 05, 2026
Mar 02, 2026
Mar 05, 2026
9.3 CRITICAL
CVE-2025-12462 — Blind SQL Injection in DobryCMS

A Blind SQL injection vulnerability has been identified in DobryCMS.  A remote unauthenticated attacker is able to inject SQL syntax into URL path in multiple parameters resulting in Blind SQL Inject…

dorbycms | Remote | Injection
Mar 02, 2026 Mar 31, 2026
Mar 02, 2026
Mar 31, 2026
Showing 20 of 6265 Results