Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-108730 — Raven 2.0.0 through 3.0.0 Missing Authorization via Legacy Message and File APIs

Raven 2.0.0 through 3.0.0 contains a missing authorization vulnerability in legacy methods in raven/api/raven_message.py that skip the workspace membership check. Authenticated non-members can call g…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.2 HIGH
CVE-2026-108729 — Corteza through 2024.9.10 Unauthenticated Attachment Access via Compose Attachment Endpoi…

Corteza through 2024.9.10 contains an incorrect authorization vulnerability in compose attachment endpoints that allows unauthenticated attackers to download private attachments by setting the URL ki…

corteza | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-108728 — Flyte 2.0.1 through 2.0.51 Cleartext Secret Exposure via Admission Webhook

Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The embedded sec…

Remote | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108727 — EdgeEver through 1.108.0 Missing Authorization via Memo-Template API Routes

EdgeEver through 1.108.0 contains a missing authorization vulnerability in the Hono API memo-template routes that allows holders of scoped API tokens to bypass token scope restrictions because templa…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108726 — GLPI through 12.0.0 Missing Authorization via ajax/map.php

GLPI through 12.0.0 contains a missing authorization vulnerability in ajax/map.php that allows authenticated low-privileged users to search itemtypes they cannot view by omitting the canView() check.…

glpi | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108725 — Cheshire Cat AI core through 2.0.23 Stored XSS via uploads plugin

Cheshire Cat AI core through 2.0.23 contains a stored cross-site scripting vulnerability in the uploads plugin that allows authenticated users to upload HTML files via POST /uploads without type rest…

Remote | Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.9 MEDIUM
CVE-2026-108724 — Sylius through 2.3.0 Authorization Bypass via Shop API Product-Review Endpoint

Sylius through 2.3.0 contains an authorization bypass vulnerability that allows unauthenticated attackers to read unmoderated and rejected product reviews because the AcceptedExtension filter is not …

sylius | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
2.5 LOW
CVE-2026-108723 — answer-me-with-html through 0.5.0 Symlink Following in Code Block src Embedding

answer-me-with-html through 0.5.0 contains a link following vulnerability in the am CLI code block src= embedding, where localPath() checks only path text without resolving symlinks. Attackers can sh…

| Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
4.2 MEDIUM
CVE-2026-108722 — open-computer-use through commit 610bac8 Stored XSS via log.html Session Log

open-computer-use through commit 610bac8 contains a stored cross-site scripting vulnerability in Logger.write_log_file in os_computer_use/logging.py, which writes transcript text into log.html withou…

Remote | Cross-Site Scripting
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.8 MEDIUM
CVE-2026-108721 — Open Computer Use through 1.0.0 Denylist Bypass via Case-Variant Bundle ID

Open Computer Use through 1.0.0 on macOS contains an improper case sensitivity handling vulnerability that allows local MCP callers to bypass the password-manager denylist using case-variant bundle i…

| Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108720 — phpIPAM through 1.8.3 Missing Authorization in Customers, Locations and NAT Pages

phpIPAM through 1.8.3 contains a missing authorization vulnerability that allows authenticated low-privilege users to view restricted subnets and addresses because customer, location and NAT pages sk…

phpipam | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108719 — LLMGateway through 1.20.0 Blind SSRF via Video-Generation callback_url

LLMGateway through 1.20.0 contains a blind server-side request forgery vulnerability that allows API key holders to reach internal hosts via the video-generation callback_url extension. Attackers can…

Remote | Server-Side Request Forgery
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.6 HIGH
CVE-2026-108718 — Rill 0.77.0 through 0.90.5 OAuth Missing Authorization via Dynamic Client Registration

Rill 0.77.0 through 0.90.5 contains a missing authorization vulnerability in the admin OAuth server that issues authorization codes to dynamically registered clients without user consent. Attackers c…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.3 MEDIUM
CVE-2026-108717 — Combodo iTop 3.1.0 through 3.3.0 Missing Authorization via LinkSetController

Combodo iTop 3.1.0 through 3.3.0 contains a missing authorization vulnerability in LinkSetController.php that allows authenticated console users to bypass profile grants by supplying arbitrary class …

itop | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.0 MEDIUM
CVE-2026-108716 — mcp-remote 0.8.0 through 0.14.3 Cleartext Credential Transmission via --device-code OAuth…

mcp-remote 0.8.0 through 0.14.3 contains a cleartext transmission vulnerability in authorizeWithDeviceCode that sends client secrets and receives tokens without enforcing HTTPS endpoints. When discov…

Remote | Cryptography
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108715 — LibreNMS through 26.9.1.1 Authorization Bypass via Smokeping Graph auth.inc.php

LibreNMS through 26.9.1.1 contains an authorization bypass vulnerability in includes/html/graphs/smokeping/auth.inc.php that checks the src probe device instead of the rendered target device. Restric…

librenms | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.7 HIGH
CVE-2026-108714 — MCP Kotlin SDK through 0.15.0 Memory Exhaustion via Application.mcpWebSocket

MCP Kotlin SDK through 0.15.0 contains an uncontrolled memory allocation vulnerability that allows remote clients to exhaust server memory because Application.mcpWebSocket installs Ktor WebSockets wi…

Remote | Memory Corruption
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108713 — SuiteCRM through 7.15.2 and 8.10.2 Missing Authorization via setCampaignMarketingAndTempl…

SuiteCRM through 7.15.2 and 8.x through 8.10.2 contains a missing authorization vulnerability that allows authenticated users to create and modify EmailMarketing records via the setCampaignMarketingA…

suitecrm | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108712 — SuiteCRM through 7.15.2 and 8.10.2 Missing Authorization via DetailUserRole Entry Point

SuiteCRM through 7.15.2 and 8.10.2 contains a missing authorization vulnerability in the DetailUserRole entry point that allows authenticated non-admin users to view other users' ACL data. Attackers …

suitecrm | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108711 — Plastic Labs Honcho through 3.3.0 Incorrect Authorization via POST /v3/workspaces

Plastic Labs Honcho through 3.3.0 contains an incorrect authorization vulnerability that allows peer- or session-scoped API key holders to read workspace data because get_or_create_workspace checks o…

Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 13681 Results