Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-17347 — pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substituti…

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by…

Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.8 HIGH
CVE-2026-17346 — pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/s…

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_…

Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-16504 — VPS.org one-click Zulip template deployment instance contains multiple vulnerabilities

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

| Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-16503 — VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Dock…

| Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.8 MEDIUM
CVE-2026-10686 — Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS)…

Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branches of ipv6_route_packet() (subsys/net/ip) were affected: the explicit-rou…

zephyr zephyr | Remote | Denial of Service
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.3 MEDIUM
CVE-2025-62347 — HCL iControl Improper Input Validation Vulnerability

HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an a…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.3 MEDIUM
CVE-2026-67350 — Serendipity < 2.6.1 Open Redirect via exit.php

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encode…

serendipity | Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-18446 — fast-uri vulnerable to host confusion via backslash authority introducer

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash…

| Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.6 HIGH
CVE-2026-10685 — Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called par…

zephyr zephyr | Memory Corruption
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
2.1 LOW
CVE-2026-65636 — YAML injection via unescaped newlines in ymlr document comments

Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inject arbitrary content into generated YAML documents through document comments. …

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-28145 — WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability

Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.

masterstudy_lms | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.3 MEDIUM
CVE-2026-28144 — WordPress WP Maps plugin <= 4.9.6 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6.

Remote | Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-18358 — Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection thro…

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection th…

Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.8 CRITICAL
CVE-2026-17561 — Unauthenticated RCE in Innotim Software's Logsign SIEM

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects L…

Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-15227 — Missing Authorization Allows Editing of Foreign Reports

Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users.

checkmk | Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.1 MEDIUM
CVE-2026-46594 — Reflected XSS in PHP Poll Script

A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arb…

php_poll_script | Remote | Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.6 HIGH
CVE-2026-46593 — Authenticated SQL Injection in PHP Poll Script

A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticat…

php_poll_script | Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.9 MEDIUM
CVE-2025-67651 — CSRF in PHP Jabbers scripts

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthoriz…

Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.6 HIGH
CVE-2025-67650 — Authenticated SQL Injection in PHP Jabbers scripts

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for so…

Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.3 CRITICAL
CVE-2025-67649 — Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script

A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an un…

car_rental_script car_rental_script | Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
Showing 20 of 9461 Results