Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-7305 — Xuxueli xxl-job trigger Endpoint XxlJobServiceImpl.java triggerJob server-side request fo…

A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl…

xxl-job | Remote | Server-Side Request Forgery
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
6.3 MEDIUM
CVE-2026-7303 — Xuxueli xxl-job Execution Log JobLogController.java logDetailCat resource injection

A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.jav…

xxl-job | Remote | Path Traversal
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
4.8 MEDIUM
CVE-2026-7297 — SourceCodester Pizzafy Ecommerce System ajax.php save_user cross site scripting

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation…

Remote | Cross-Site Scripting
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
4.8 MEDIUM
CVE-2026-7296 — SourceCodester Pizzafy Ecommerce System ajax.php save_order cross site scripting

A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument…

Remote | Cross-Site Scripting
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
7.7 HIGH
CVE-2026-41649 — Outline has IDOR in document share creation that allows unauthorized access to private do…

Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct object reference.. When…

outline | Remote | Authorization
Apr 28, 2026 May 01, 2026
Apr 28, 2026
May 01, 2026
9.8 CRITICAL
CVE-2026-41446 — WattBox 800 & 820 Series < 2.10.0.0 RCE via Diagnostic Endpoints

Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both…

Remote | Authentication
Apr 28, 2026 Apr 30, 2026
Apr 28, 2026
Apr 30, 2026
6.1 MEDIUM
CVE-2026-37750 — School Management System by mahmoudai1 Reflected Cross-Site Scripting (XSS)

A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated remote attackers to execute arbitrary JavaScript in victim's browsers via the uns…

Remote | Cross-Site Scripting
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
5.9 MEDIUM
CVE-2026-33467 — Improper Verification of Cryptographic Signature in Elastic Package Registry Leading to P…

Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served t…

elastic_package_registry | Remote | Cryptography
Apr 28, 2026 May 05, 2026
Apr 28, 2026
May 05, 2026
Showing 20 of 6728 Results