Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.6 MEDIUM
CVE-2026-90706 — D-Link DWR-M921 formWsc os command injection

A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. T…

Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.6 MEDIUM
CVE-2026-90705 — D-Link DWR-M921 Boa Dispatch Table formsysCmd os command injection

A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argu…

Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.1 HIGH
CVE-2026-8821 — Playbooks run owner channel membership permission bypass

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authentic…

Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.7 HIGH
CVE-2026-89180 — Thinking Software Technology|EFence - SQL Injection

EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-87802 — Apache Syncope: SRA OAuth2 JWT signature verification bypass

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impers…

syncope | Cryptography
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-87785 — Apache Syncope: JWT subject spoofing

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoo…

syncope | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-87779 — Apache Syncope: AES Secret Key disclosure via log output

Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with r…

syncope | Information Disclosure
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-86460 — Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence

Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.…

syncope | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
0.0 NA
CVE-2026-82232 — Apache Syncope: SQL injection via sort parameter in Task search

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary…

syncope | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
5.1 MEDIUM
CVE-2026-81566 — Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Pa…

Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() me…

Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.9 MEDIUM
CVE-2026-81565 — Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP P…

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based dest…

Remote | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
7.0 HIGH
CVE-2026-81564 — Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowin…

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neithe…

Remote | Path Traversal
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.9 MEDIUM
CVE-2026-79700 — Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled…

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the …

Remote | Authentication
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.6 HIGH
CVE-2026-78375 — Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content…

Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read j…

Remote | Injection
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.5 MEDIUM
CVE-2026-5132 — Unbounded zlib decompression in Calls SDP WebSocket messages

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service o…

Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
8.5 HIGH
CVE-2026-20773 — Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint

A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capab…

pingfederate pingfederate | Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
6.5 MEDIUM
CVE-2026-15814 — Uploading a crafted image causes excessive memory allocation in the Mattermost Server

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authentic…

Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
4.3 MEDIUM
CVE-2026-14344 — Inconsistent authorization checks in Mattermost Boards endpoints

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create b…

Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
4.3 MEDIUM
CVE-2026-14259 — Board archive import bypasses team board creation permissions

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non…

Remote | Authorization
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
4.3 MEDIUM
CVE-2026-13417 — Boards plugin denial of service via unvalidated block fields.properties

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user wit…

Remote | Denial of Service
Sep 14, 2026 Sep 14, 2026
Sep 14, 2026
Sep 14, 2026
Showing 20 of 12469 Results