Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-77818 — Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library Automation Sy…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.…

Remote | Cross-Site Scripting
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-52691 — Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module.  This issue affects Apac…

| Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
4.3 MEDIUM
CVE-2026-19081 — Missing Authorization Allows Unauthorized Access to Critical POS Functions in Gastromenum…

Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Gastromenum Ticket and QR…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.4 MEDIUM
CVE-2026-19057 — Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu System

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS. This issue affects Gastrome…

Remote | Cross-Site Scripting
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-12483 — LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment…

The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in the 'learndash_fileupload_…

Remote | Misconfiguration
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-19205 — User Enumeration in GastroMenum's GastroMenum Web Panel

Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026.

Remote | Information Disclosure
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.1 MEDIUM
CVE-2026-19727 — HTML Injection via Improper Input Sanitization in Yordam Informatics's Library Automation…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.…

Remote | Cross-Site Scripting
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.9 HIGH
CVE-2026-85649 — Actualizer Password Validation Bypass Vulnerability

(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The …

| Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-85516 — code-projects Vehicle Management System busprofile.php sql injection

A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid r…

vehicle_management_system | Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.5 MEDIUM
CVE-2026-85514 — StackStorm st2 API Key auth.py privileges management

A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component API Key Handler. Such manip…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.5 MEDIUM
CVE-2026-85513 — StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management

A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecu…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-82309 — Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS …

Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns i…

| Denial of Service
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.1 HIGH
CVE-2026-74237 — GFI Exinda AI < 7.6.5 Argument Injection via Tools Iperf Client

GFI Exinda AI before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an iperf command using the server and options …

Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.0 HIGH
CVE-2026-74236 — GFI Exinda AI < 7.6.5 Path Traversal via Diagnostic File Deletion Handler

GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and append…

Remote | Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.9 MEDIUM
CVE-2026-74235 — GFI Exinda AI < 7.6.5 Path Traversal via Configuration Download Handler

GFI Exinda AI before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_…

Remote | Path Traversal
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.8 HIGH
CVE-2026-18198 — SQL Injection in TAC Information's GoldenHorn

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injec…

Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.8 HIGH
CVE-2026-85617 — snipe-it before 8.6.3 Authorization Bypass via Bulk Delete

snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attacke…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.5 HIGH
CVE-2026-85616 — Snipe-IT before 8.6.2 Authorization Bypass via Checkout-Acceptance

Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.4 MEDIUM
CVE-2026-85615 — Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts

Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized proje…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
9.2 CRITICAL
CVE-2026-85614 — OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker

OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no priva…

Remote | Server-Side Request Forgery
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
Showing 20 of 12602 Results