Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2026-47837 — Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affec…

Remote | Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.2 HIGH
CVE-2026-47836 — Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cl…

| Misconfiguration
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
6.8 MEDIUM
CVE-2026-32639 — Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions an…

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type pe…

winter | Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
5.9 MEDIUM
CVE-2026-32593 — Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange …

winter | Remote | Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2025-56798 — Unraid OS Cross-Site Request Forgery Privilege Escalation

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's …

| Cross-Site Request Forgery
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2025-29419 — CTFd Man-in-the-Middle Vulnerability

CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.

| Cryptography
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2023-42179 — Bird Home Automation GmbH D1101V-F Incorrect Access Control

Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.

| Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.1 HIGH
CVE-2026-35445 — Winter: Authenticated backend users can bypass Users controller permission checks

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler P…

winter | Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.1 HIGH
CVE-2026-32258 — Winter: Stored XSS through Editor Settings custom styles

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can…

winter | Remote | Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.1 HIGH
CVE-2026-32257 — Winter: Stored XSS through Brand Settings custom styles

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with t…

winter | Remote | Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2020-15878 — LibreNMS SQL Injection Vulnerability

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address paramete…

| Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2020-15876 — LibreNMS SQL Injection Vulnerability

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter i…

| Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2020-15874 — LibreNMS Command Injection Vulnerability

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.

| Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.1 HIGH
CVE-2026-81036 — Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth …

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs re…

stalwart | Remote | Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.1 HIGH
CVE-2026-81035 — Midday Missing Owner Check on Team Deletion

Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the t…

Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.3 HIGH
CVE-2026-81034 — Netmaker through 1.6.0 Improper Certificate Validation in SMTP Client

Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp.go assigns a TLS configuration whose skip-verify field is set to true uncondit…

netmaker netmaker | Remote | Cryptography
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
5.3 MEDIUM
CVE-2026-81033 — Automatisch through 0.15.0 User Enumeration via Forgot-Password Response Discrepancy

Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js l…

Remote | Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
9.8 CRITICAL
CVE-2026-81032 — NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Configuration

NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all int…

Remote | Misconfiguration
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.2 HIGH
CVE-2026-81031 — IDURAR ERP CRM through 4.1.1 Account Takeover via Unverified Identifier on Password Update

IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserCon…

idurar | Remote | Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
6.5 MEDIUM
CVE-2026-81030 — Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpoint

Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in mage_ai/api/resources/BrowserItemResource.py passes a caller-supplied path to the…

mage-ai | Remote | Path Traversal
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
Showing 20 of 12192 Results