Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-94592 — Armatura LLC Armatura One Use of Hard-coded Credentials

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. …

| Authentication
Oct 02, 2026 Oct 03, 2026
Oct 02, 2026
Oct 03, 2026
8.6 HIGH
CVE-2026-94591 — Armatura LLC Armatura One Use of Hard-coded Cryptographic Key

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization v…

| Cryptography
Oct 02, 2026 Oct 03, 2026
Oct 02, 2026
Oct 03, 2026
6.9 MEDIUM
CVE-2026-93474 — Monta monta.app Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Remote | Information Disclosure
Oct 02, 2026 Oct 03, 2026
Oct 02, 2026
Oct 03, 2026
4.3 MEDIUM
CVE-2026-105046 — Kentico Xperience Improper Authorization Vulnerability

Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.

xperience | Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
3.6 LOW
CVE-2026-105043 — MathWorks Simulink Arbitrary Code Execution Vulnerability

MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution.

| Misconfiguration
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.1 HIGH
CVE-2026-82045 — UTMStack < 11.2.16 JPQL Injection via searchPropertyValues

UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which bui…

Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.7 HIGH
CVE-2026-82044 — UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated ur…

Remote | Server-Side Request Forgery
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.9 MEDIUM
CVE-2026-82043 — UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint

UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.8 CRITICAL
CVE-2026-82042 — UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the …

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.9 CRITICAL
CVE-2026-82041 — UTMStack < 11.2.16 Missing Authorization via Command WebSocket

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role …

Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.4 CRITICAL
CVE-2026-75937 — OS Command Injection in Digi Accelerated Linux (DAL OS)

A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device…

| Authentication
Oct 02, 2026 Oct 03, 2026
Oct 02, 2026
Oct 03, 2026
5.3 MEDIUM
CVE-2026-104874 — Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction

Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and …

Remote | Denial of Service
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-104055 — Monitoring-user password logged in cleartext by postgres_exporter in postgresql VM charm

The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the mo…

Remote | Information Disclosure
Oct 02, 2026 Oct 03, 2026
Oct 02, 2026
Oct 03, 2026
5.3 MEDIUM
CVE-2026-82040 — UTMStack < 11.2.16 SSRF via IdentityProviderService

UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl() that allows authenticated attackers to make the server send requests to a…

Remote | Server-Side Request Forgery
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.8 HIGH
CVE-2026-82039 — UTMStack < 11.2.16 SQL Injection via searchGroupsByFilter

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetTyp…

Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.8 HIGH
CVE-2026-39718 — WordPress Wallstreet theme <= 2.8.6 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.

Remote | Cross-Site Request Forgery
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.3 MEDIUM
CVE-2026-12392 — RPC secret disclosure via vendor data endpoint in Canonical MAAS

An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the ve…

maas | Remote | Information Disclosure
Oct 02, 2026 Oct 03, 2026
Oct 02, 2026
Oct 03, 2026
2.5 LOW
CVE-2026-104994 — Trivy Directory Traversal Vulnerability

Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input …

trivy | Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.1 HIGH
CVE-2026-104991 — Phproject < 1.8.7 Missing Authorization via Issues REST API

Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API ke…

phproject | Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.1 HIGH
CVE-2026-104988 — Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allows certifica…

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certific…

Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 14703 Results