Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-50894 — EasyAdmin Unrestricted File Upload Vulnerability

easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and ga…

| Misconfiguration
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2025-67066 — Oasys Sysoa SQL Injection

SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path

| Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2022-26961 — Italtel NetMatch-S Stored Cross-Site Scripting

Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious u…

| Cross-Site Scripting
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.7 HIGH
CVE-2026-85786 — Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-ja…

Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitra…

Remote | Denial of Service
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.8 MEDIUM
CVE-2026-85643 — code-projects Online Shopping System adduser.php mysqli_query sql injection

A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql…

online_shopping_system | Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-79391 — Trueview MQTT Broker Authentication Bypass

No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with networ…

| Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-79390 — Trueview TI8161 MQTT Information Disclosure

Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker with access to the same ne…

| Information Disclosure
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-79389 — Trueview MQTT Command Injection Vulnerability

Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, including security-related nonce,…

| Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-71626 — Invoice Ninja Information Disclosure Vulnerability

An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components

| Information Disclosure
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-71625 — ThinkSNS+ Privilege Escalation

An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component

| Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-71624 — esoTalk Remote Code Execution Vulnerability

An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php …

| Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
0.0 NA
CVE-2026-71622 — APiAdmin SQL Injection

SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component

| Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.7 HIGH
CVE-2026-63464 — Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_priv…

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webh…

Remote | Server-Side Request Forgery
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.1 HIGH
CVE-2026-61699 — nebula-mesh: Certificate revocation is never enforced at the mesh

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. …

Remote | Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.4 MEDIUM
CVE-2026-55513 — nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-ho…

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_tok…

Remote | Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
5.3 MEDIUM
CVE-2026-55512 — nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entr…

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable without authentication and is r…

Remote | Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
8.0 HIGH
CVE-2026-53932 — wnx/laravel-backup-restore: Improper Neutralization of Special Elements used in an OS Com…

laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue…

Remote | Injection
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.1 HIGH
CVE-2026-53604 — nebula-mesh: CA private key not zeroized on web mobile-bundle error paths

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into mobilebundle.Build. Insi…

Remote | Information Disclosure
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
7.1 HIGH
CVE-2026-53603 — nebula-mesh: Operator session tokens stored in plaintext in the database

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the P…

Remote | Authentication
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
6.9 MEDIUM
CVE-2026-53602 — nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid…

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula c…

Remote | Authorization
Sep 04, 2026 Sep 04, 2026
Sep 04, 2026
Sep 04, 2026
Showing 20 of 12816 Results