Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.0 HIGH
CVE-2026-16923 — Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.

aix aix powervm_vios | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.0 HIGH
CVE-2026-16922 — Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) race condition.

aix aix powervm_vios | Race Condition
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
0.0 NA
CVE-2026-44725 — EMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code execu…

EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, the plugin-install REST API and dashboard uplo…

| Authentication
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
0.0 NA
CVE-2026-61898 — accountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu lan…

The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as t…

accountsservice | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
0.0 NA
CVE-2026-61897 — accountsservice: incomplete privilege drop when running Ubuntu-specific language helper s…

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but l…

accountsservice | Authentication
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
0.0 NA
CVE-2026-73220 — CVAT: Stored XSS via annotation guides in audio tasks

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the audio-task annotation guide renderer in cvat-ui/src/audio/components/annotation-p…

| Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
0.0 NA
CVE-2026-76993 — GreyDGL PentestGPT Web-Page Crawling injection

A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the argument Traceback can le…

| Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
0.0 NA
CVE-2026-55558 — aiosmtplib: STARTTLS response injection

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake wi…

| Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-76990 — code-projects Simple Inventory System delete.php sql injection

A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads t…

Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.4 HIGH
CVE-2026-76833 — @cgauge/yaml npm Package Arbitrary Code Execution via eval() YAML Tag

@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditi…

| Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-76635 — baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.php

baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values direc…

Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.1 HIGH
CVE-2026-76634 — WeGIA < 3.9.2 Insecure Direct Object Reference via profile_funcionario.php

WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-76633 — WeGIA < 3.9.2 Authorization Bypass Password Change via alterarSenha

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credential…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.4 HIGH
CVE-2026-70383 — Arbitrary file overwrite vulnerability in DigiDoc4 client

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client. This issue affects DigiDoc4: from 4.0.0 b…

| Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
4.8 MEDIUM
CVE-2026-64972 — Reflected XSS in ATutor

ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double quote into the popup parameter, break out of the attribute value, and append a …

Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
4.8 MEDIUM
CVE-2026-64971 — Reflected XSS in ATutor

ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. P…

Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.1 MEDIUM
CVE-2026-64970 — Stored XSS in ATutor

ATutor is vulnerable to Stored Cross Site Scripting in registration functionality.  An attacker can register a new account and enter a JavaScript payload in the phone field during registration. When …

Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.3 MEDIUM
CVE-2026-64969 — Insecure Direct Object Reference in ATutor

ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authenticated user, including a student, can supply another user's member_id in a POST…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.1 MEDIUM
CVE-2026-64968 — Server-Side Request Forgery in ATutor

ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, o…

Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.9 MEDIUM
CVE-2026-64967 — Path Traversal in ATutor

A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access arbitrary files outside the intended logs directory. This can lead to unauthori…

Remote | Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
Showing 20 of 12718 Results