Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-94535 — lamp-cloud through 5.10.0 Unauthorized Notification Deletion

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DE…

lamp-cloud lamp-cloud | Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.1 HIGH
CVE-2026-94534 — lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints

lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can s…

lamp-cloud lamp-cloud | Remote | Authentication
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.1 HIGH
CVE-2026-94533 — lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users'…

lamp-cloud lamp-cloud | Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.1 HIGH
CVE-2026-94532 — lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can iterate t…

lamp-cloud lamp-cloud | Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.4 HIGH
CVE-2026-93340 — Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password Endpoint

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting t…

Remote | Authentication
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
0.0 NA
CVE-2026-88756 — Pagekit CMS SQL Injection

Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate).

| Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
0.0 NA
CVE-2026-88738 — Jazzware RT1000 Edge Unrestricted File Upload Remote Code Execution

Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An authenticated attacker can upload a server-side executable file…

| Authentication
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
0.0 NA
CVE-2026-79079 — CrossWire Xiphos Arbitrary Code Execution Vulnerability

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

| Memory Corruption
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
0.0 NA
CVE-2026-78847 — gray-matter Arbitrary Code Execution

An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code ex…

| Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
0.0 NA
CVE-2026-78806 — Matter Project Chip Information Disclosure Vulnerability

An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the…

| Information Disclosure
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.9 HIGH
CVE-2026-65980 — Chartbrew: SQL Injection via Missing Backslash Escaping in ClickHouse Variable Substituti…

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.3, Chartbrew's ClickHouse protocol in server/sources/plugin…

chartbrew | Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.8 MEDIUM
CVE-2026-61852 — Chartbrew: SQL Injection via row_limit Parameter in AI runQuery Tool

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in server/modules/…

chartbrew | Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
6.5 MEDIUM
CVE-2026-61851 — Chartbrew: Incomplete Read-Only Keyword Blocklist in AI runQuery Tool

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in server/modules/…

chartbrew | Remote | Injection
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
6.3 MEDIUM
CVE-2026-61743 — Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's server/modules/safeRequest.js calls validate…

chartbrew | Remote | Server-Side Request Forgery
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
8.7 HIGH
CVE-2026-61652 — Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed…

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed compressed responses relying on the chunk si…

Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
6.9 MEDIUM
CVE-2026-61541 — Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicio…

Remote | Denial of Service
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
5.4 MEDIUM
CVE-2026-59830 — Discourse: Stored XSS via unescaped actor name in post actions

Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML string passed to tr…

discourse | Remote | Cross-Site Scripting
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
4.3 MEDIUM
CVE-2026-59815 — Joplin: Pending share recipients can write items into shared folders before accepting inv…

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to items with a …

joplin | Remote | Authorization
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.6 HIGH
CVE-2026-59814 — Joplin: Stored XSS via inline-served note attachment on published shares

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's GET /shares/:id?resource_id= route serves a resource with the…

joplin | Remote | Cross-Site Scripting
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
7.4 HIGH
CVE-2026-55210 — Joplin: SAML SSO account takeover via email-based account linking (missing is_external ch…

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing account matched by a…

joplin | Remote | Authentication
Sep 21, 2026 Sep 21, 2026
Sep 21, 2026
Sep 21, 2026
Showing 20 of 13805 Results