Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.0 MEDIUM
CVE-2026-34244 — Weblate: SSRF via Project-Level Machinery Configuration

Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation servi…

weblate | Remote | Server-Side Request Forgery
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
7.7 HIGH
CVE-2026-34242 — Weblate: Arbitrary File Read via Symlink

Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has be…

weblate | Remote | Path Traversal
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
7.4 HIGH
CVE-2026-33667 — OpenProject: 2FA OTP Verification Missing Rate Limiting

OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_factor_authentication module has no rate limiting,…

openproject | Remote | Authentication
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
5.0 MEDIUM
CVE-2026-33440 — Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot UR…

Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. This issue has…

weblate | Remote | Misconfiguration
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
8.0 HIGH
CVE-2026-33435 — Weblate: Remote code execution during backup restoration

Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain cir…

weblate | Remote | Misconfiguration
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
6.8 MEDIUM
CVE-2026-33220 — Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the …

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been f…

weblate | Remote | Authorization
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
8.0 HIGH
CVE-2026-6290 — Velociraptor Query() Plugin Misapplies Permissions To Orgs

Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with acces…

velociraptor | Remote | Authorization
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
6.5 MEDIUM
CVE-2026-5758 — Mafintosh's protocol-buffers-schema is vulnerable to prototype pollution

JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve…

Remote | Misconfiguration
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
4.3 MEDIUM
CVE-2026-33214 — Weblate has improper access control for the translation memory API

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been f…

weblate | Remote | Authorization
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
3.1 LOW
CVE-2026-33212 — Weblate: Improper access control for pending tasks in API

Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't hav…

weblate | Remote | Authorization
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
7.4 HIGH
CVE-2026-32631 — Git for Windows: `git clone` from manipulated repositories can leak NTLM hashes to arbitr…

Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by trick…

git_for_windows | Remote | Information Disclosure
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
9.8 CRITICAL
CVE-2026-30993 — Slah CMS Remote Code Execution (RCE)

Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.

Remote | Injection
Apr 15, 2026 Apr 16, 2026
Apr 15, 2026
Apr 16, 2026
7.5 HIGH
CVE-2026-6372 — WordPress Accept Cryptocurrencies with Plisio plugin <= 2.0.5 - Payment Bypass vulnerabil…

Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accept Cryptocurrencies wi…

Remote | Authorization
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
5.9 MEDIUM
CVE-2026-6370 — WordPress Mini Ajax Cart for WooCommerce plugin <= 1.3.4 - Cross Site Scripting (XSS) vul…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Ajax Cart for WooCommerce allows Stored XSS.This issue affects Mini Ajax Cart for…

Remote | Cross-Site Scripting
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
7.5 HIGH
CVE-2026-30996 — SAC-NFe Directory Traversal Vulnerability

An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a directory traversal and read arbitrary files from the system via a crafted GET reque…

Remote | Path Traversal
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
8.6 HIGH
CVE-2026-30995 — Slah CMS SQL Injection Vulnerability

Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_ver.php endpoint.

Remote | Injection
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
7.5 HIGH
CVE-2026-30994 — Slah Config.php Information Disclosure Vulnerability

Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, including active session credentials.

Remote | Authorization
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
9.9 CRITICAL
CVE-2026-20186 — Cisco Identity Services Engine Multiple Authenticated Remote Code Execution Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploi…

identity_services_engine | Remote | Injection
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
9.8 CRITICAL
CVE-2026-20184 — Cisco Webex Meetings Certificate Validation Vulnerability

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. …

webex | Remote | Authentication
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
9.9 CRITICAL
CVE-2026-20180 — Cisco Identity Services Engine Multiple Remote Code Execution Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploi…

identity_services_engine | Remote | Injection
Apr 15, 2026 Apr 15, 2026
Apr 15, 2026
Apr 15, 2026
Showing 20 of 6510 Results