Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.7 HIGH
CVE-2026-77129 — Server-Side Template Injection in extension "Event management and registration" (sf_event…

The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can s…

Remote | Information Disclosure
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.3 MEDIUM
CVE-2026-77128 — Broken Access Control in extension "Event management and registration" (sf_event_mgt)

The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events,…

Remote | Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.0 MEDIUM
CVE-2026-77127 — Information Disclosure in extension "Modules" (modules)

The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary t…

Remote | Information Disclosure
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
8.8 HIGH
CVE-2026-63587 — SMS Password Authorization Bypass via Failed Attempt Counter

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS p…

Remote | Authentication
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
9.8 CRITICAL
CVE-2026-63586 — Unauthenticated Remote Code Execution via Shell Injection in Web Management Interface

The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is …

Remote | Injection
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.3 MEDIUM
CVE-2026-56096 — Information Disclosure in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthentic…

Remote | Injection
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.7 HIGH
CVE-2026-56095 — Insecure Deserialization in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVA…

Remote | Injection
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.3 MEDIUM
CVE-2026-56094 — Information Disclosure in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an…

Remote | Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.3 MEDIUM
CVE-2026-56093 — Broken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or gues…

Remote | Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.6 HIGH
CVE-2026-56092 — Broken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allow…

Remote | Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
5.3 MEDIUM
CVE-2026-17548 — Missing authorization for viewing background jobs

Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results.

Remote | Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
8.6 HIGH
CVE-2026-12878 — Codefresh Privilege Escalation Vulnerability

In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.

Remote | Authorization
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.5 MEDIUM
CVE-2026-78701 — 389-ds-base: 389-ds-base: cve-2026-11610 incomplete fix may introduce a connection-stall …

A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted r…

Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.5 MEDIUM
CVE-2026-78322 — File-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar han…

A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path in…

enterprise_linux enterprise_linux | Remote | Memory Corruption
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
8.7 HIGH
CVE-2026-67578 — FA-50 Authentication Bypass Vulnerability

FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration param…

| Authentication
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
2.1 LOW
CVE-2026-66882 — Reflected XSS in AshAuthentication confirmation and magic link interaction forms

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction…

ash_authentication | Remote | Cross-Site Scripting
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.6 HIGH
CVE-2026-65633 — Purpose-limited JWT accepted as full bearer authentication in AshAuthentication

Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verificat…

ash_authentication | Remote | Authentication
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
9.1 CRITICAL
CVE-2026-59769 — FA-50 Hard-Coded Credentials Vulnerability

FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to a…

| Authentication
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
7.7 HIGH
CVE-2026-19851 — Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 throu…

A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import.

Remote | Authentication
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
6.4 MEDIUM
CVE-2026-18512 — TranslatePress <= 3.2.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via App…

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Approved Comment Body Rendered in Translation Editor String…

Remote | Cross-Site Scripting
Aug 25, 2026 Aug 25, 2026
Aug 25, 2026
Aug 25, 2026
Showing 20 of 11588 Results