Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-81728 — Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies onl…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
6.8 MEDIUM
CVE-2026-81530 — KMS master key exposure via unredacted credential serialization in driver settings string

A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced verbatim in th…

c_driver | Cryptography
Aug 27, 2026 Aug 28, 2026
Aug 27, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-81529 — Connection-option injection via unescaped settings in the canonical MongoDB URL builder

Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connectio…

c_driver | Remote | Injection
Aug 27, 2026 Aug 28, 2026
Aug 27, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-81528 — NoSQL injection via array replacement bypassing update shape validation in driver write p…

A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a value supplied as a replacement is forwarded to the server witho…

c_driver | Remote | Injection
Aug 27, 2026 Aug 28, 2026
Aug 27, 2026
Aug 28, 2026
6.9 MEDIUM
CVE-2026-81527 — NoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translation

A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When application…

c_driver | Remote | Injection
Aug 27, 2026 Aug 28, 2026
Aug 27, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-81526 — Cross-database write redirection via unvalidated dotted database name in bulk write names…

The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. An actor able to influence that identi…

rust_driver | Remote | Injection
Aug 27, 2026 Aug 28, 2026
Aug 27, 2026
Aug 28, 2026
8.6 HIGH
CVE-2026-81525 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP D…

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database opera…

php_driver | Remote | Injection
Aug 27, 2026 Aug 28, 2026
Aug 27, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-81524 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Dri…

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an…

c_driver | Remote | Injection
Aug 27, 2026 Aug 28, 2026
Aug 27, 2026
Aug 28, 2026
4.4 MEDIUM
CVE-2026-81523 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in libmongoc…

A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact i…

libmongocrypt | Injection
Aug 27, 2026 Aug 28, 2026
Aug 27, 2026
Aug 28, 2026
8.6 HIGH
CVE-2026-81522 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ D…

A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier fro…

c_driver | Remote | Authorization
Aug 27, 2026 Aug 28, 2026
Aug 27, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-81521 — Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite…

The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the…

go_driver | Remote | Injection
Aug 27, 2026 Aug 28, 2026
Aug 27, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-77438 — Trilium unauthenticated share-search discloses password-protected and hidden shared notes

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHidde…

Remote | Information Disclosure
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.5 HIGH
CVE-2026-76640 — Unitree G1 EDU 1.5.2 BLE GATT RCE via WiFi Provisioning Stack

Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code …

| Memory Corruption
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.8 HIGH
CVE-2026-76639 — Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path Traversal

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three we…

| Authentication
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
7.7 HIGH
CVE-2026-75889 — CVE-2026-75889 CVE Record

Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerT…

alloy | Remote | Information Disclosure
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
10.0 CRITICAL
CVE-2026-74820 — Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause

ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to exe…

Remote | Injection
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.7 HIGH
CVE-2026-6876 — Sandbox Escape in Now Platform

ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the Now Pla…

Remote | Authentication
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.3 MEDIUM
CVE-2026-66353 — Doggo vulnerable to cross-site scripting via unescaped date field values

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woylie doggo allows Reflected XSS. Doggo.normalize_value/2 in lib/doggo.ex returned date field v…

Remote | Cross-Site Scripting
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
5.1 MEDIUM
CVE-2026-65931 — LimeSurvey Community Edition 7.0.5 - Improper authorization in survey menu entry creation…

LimeSurvey Community Edition 7.0.5 contains an authenticated improper authorization vulnerability in the survey menu entry creation endpoint. An authenticated user with only the global settings:re…

Remote | Authorization
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
8.2 HIGH
CVE-2026-59324 — fluxTransform shared RequestMessageHolder causes cross-message header leakage under async…

When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply he…

Remote | Race Condition
Aug 27, 2026 Aug 27, 2026
Aug 27, 2026
Aug 27, 2026
Showing 20 of 12395 Results