Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-28814 — Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to …

jspwiki | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-28813 — Apache JSPWiki: JSPWiki vulnerable to JSON hijacking

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

jspwiki | Cross-Site Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-28812 — Apache JSPWiki: UserManager does not sanity-check user database at startup

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixe…

jspwiki | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-28811 — Apache JSPWiki: Error Handling - Reveals Error Details

Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

jspwiki | Information Disclosure
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
9.8 CRITICAL
CVE-2026-28323 — SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

web_help_desk | Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.3 MEDIUM
CVE-2026-23985 — Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within th…

superset | Remote | Denial of Service
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
5.3 MEDIUM
CVE-2026-23981 — Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification

An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updating a chart's proper…

superset | Remote | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-15658 — foreUP customer REST API allows unauthenticated endpoint access

A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns t…

| Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
0.0 NA
CVE-2026-15657 — foreUP customer REST API allows authenticated users to read cleartext payment-processor m…

A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.

| Information Disclosure
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.5 HIGH
CVE-2026-10842 — IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by…

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constra…

Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
7.9 HIGH
CVE-2026-6540 — L7 policy bypass via unnormalized HTTP path matching

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments,…

calico_enterprise calico_cloud calico | Remote | Path Traversal
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.7 HIGH
CVE-2026-67349 — OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass

OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMidd…

Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.6 HIGH
CVE-2026-67348 — Julep Insecure Direct Object Reference via GET /executions/{execution_id}

Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply …

Remote | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.8 MEDIUM
CVE-2026-67347 — Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset Update

Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-location.service.ts and asset.service.ts update methods that allows channel-scoped…

Remote | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.6 HIGH
CVE-2026-67346 — Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass

Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing atta…

Remote | Server-Side Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.5 HIGH
CVE-2026-67345 — MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft

MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.…

Remote | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
8.3 HIGH
CVE-2026-65635 — Boruta dynamic client registration allows creation of over-privileged OAuth clients

Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through t…

Remote | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.9 MEDIUM
CVE-2026-54885 — Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching

Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/OpenID authorization server to issue outbound HTTP requests to attacker-chos…

Remote | Server-Side Request Forgery
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
9.1 CRITICAL
CVE-2026-53431 — Boruta accepts expired JWT client assertions due to missing exp claim validation

Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion to authenticate as the issuing OAuth client after…

Remote | Authentication
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
6.2 MEDIUM
CVE-2026-41187 — Calico Tier Authorization Bypass via DeleteCollection

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is…

calico_enterprise calico_cloud calico | Remote | Authorization
Jul 30, 2026 Jul 30, 2026
Jul 30, 2026
Jul 30, 2026
Showing 20 of 10052 Results