Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.7 LOW
CVE-2026-79732 — Dell Secure Connect Gateway Improper Certificate Validation Vulnerability

Dell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentia…

Remote | Misconfiguration
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
3.7 LOW
CVE-2026-79729 — Dell Secure Connect Gateway Improper Certificate Validation Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker w…

Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
3.7 LOW
CVE-2026-79690 — Dell Secure Connect Gateway Improper Certificate Validation Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker w…

Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-79617 — Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Gr…

Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access C…

| Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.5 MEDIUM
CVE-2026-78482 — Dell Secure Connect Gateway OS Command Injection Vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Comma…

| Injection
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.6 HIGH
CVE-2026-26212 — Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE

Rara One Click Demo Import plugin for WordPress before 1.3.5 contains an arbitrary file upload vulnerability that allows authenticated attackers with Administrator privileges to upload arbitrary PHP …

Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.8 HIGH
CVE-2026-86775 — knowns before 0.30.0 Path Traversal via Document API

knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in internal/server/routes/docs.go normalizes the user-supplied document path with …

Remote | Path Traversal
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
6.3 MEDIUM
CVE-2026-86774 — Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy

Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-86773 — Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints

Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predef…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-86772 — Snipe-IT 8.6.3 Stored XSS via Department Names

Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedNameLink() where department names are rendered unescaped in the fallback branch for…

snipe-it | Remote | Cross-Site Scripting
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.3 HIGH
CVE-2026-86771 — Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num

Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() fu…

snipe-it | Remote | Server-Side Request Forgery
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.6 HIGH
CVE-2026-86770 — Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case var…

snipe-it | Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-86769 — Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout

Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API endpoint that records the checkout target user's id in the created_by column inst…

snipe-it | Remote | Misconfiguration
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.4 MEDIUM
CVE-2026-86768 — Snipe-IT before 8.7.0 Improper Input Validation via API Checkout

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can s…

snipe-it | Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.3 MEDIUM
CVE-2026-86767 — Snipe-IT before 8.7.0 Cross-Company Read via requested-assets

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.vi…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86766 — Snipe-IT 8.6.3 Race Condition via Consumable Checkout

Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout). The requested quantity is va…

snipe-it | Remote | Race Condition
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86765 — Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
7.1 HIGH
CVE-2026-86764 — Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
5.1 MEDIUM
CVE-2026-86763 — snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer

Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the…

snipe-it | Remote | Authorization
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
8.6 HIGH
CVE-2026-86762 — Snipe-IT before 8.7.0 Authentication Bypass via API Middleware

Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal ac…

snipe-it | Remote | Authentication
Sep 09, 2026 Sep 09, 2026
Sep 09, 2026
Sep 09, 2026
Showing 20 of 13994 Results