Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-47754 — unauthenticated path traversal in Metacat 2.x

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archi…

Remote | Path Traversal
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.9 MEDIUM
CVE-2026-72761 — Webhook SSRF guard bypassed by IPv6 transition addresses (NAT64/6to4/Teredo pass is_globa…

The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transition addresses (NAT64 `64:ff9b::/96`, 6to4 `2002::…

Remote | Server-Side Request Forgery
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.3 MEDIUM
CVE-2026-72760 — cti-transmute Following List Exposes User Email Addresses to Authenticated Users

Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. When an authenticated user follows another account, get_following() includes the f…

Remote | Information Disclosure
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.9 MEDIUM
CVE-2026-72759 — cti-transmute Conversion History Authorization Bypass Leads to Sensitive Data Disclosure …

In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record references a deleted conversion, the associated c…

Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
8.6 HIGH
CVE-2026-19433 — Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vC…

Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated users of any company to blindly overwrite the contac…

prospero_flow_crm | Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
0.0 NA
CVE-2026-18412 — The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability

OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate that the extract…

| Path Traversal
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.1 MEDIUM
CVE-2026-72751 — Stored Cross-Site Scripting in CTI-Transmute Conversion Graph via Malicious STIX/MISP Con…

CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise converted MISP and STIX content. Attacker-controlled values originating from …

Remote | Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.8 MEDIUM
CVE-2026-71959 — Bitwarden Server < 2026.7.2 Audit Log Injection via POST /collect

Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrari…

server | Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
9.8 CRITICAL
CVE-2026-63106 — ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a My…

Remote | Injection
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.4 MEDIUM
CVE-2026-63105 — ReadyEcommerce < 4.5.2 Stored XSS via Chat and Support Ticket Systems

ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML payloads through the chat and support ticket messag…

Remote | Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
4.4 MEDIUM
CVE-2026-59112 — Signature validation vulnerability affecting DigiDoc applications

Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc …

| Cryptography
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
2.4 LOW
CVE-2026-18503 — Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()

Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().

cpython cpython | Denial of Service
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.1 MEDIUM
CVE-2026-18478 — Stored XSS in Magnolia CMS

Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed …

Remote | Cross-Site Scripting
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
6.7 MEDIUM
CVE-2026-16742 — systemd-homed: local privilege escalation via missing home-record signature verification …

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user

| Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
4.7 MEDIUM
CVE-2026-15060 — systemd-machined: unprivileged users can terminate arbitrary processes

When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session …

| Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
5.5 MEDIUM
CVE-2026-15059 — systemd-oomd: unprivileged users can terminate arbitrary processes

Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.

| Path Traversal
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.5 HIGH
CVE-2026-72692 — OpenSignLabs opensignserver - Missing Authorization

A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attr…

Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.5 HIGH
CVE-2026-72691 — OpenSignLabs opensignserver - Authentication Bypass

An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files …

Remote | Authentication
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.1 HIGH
CVE-2026-72690 — Attendize Attendize - Cross-Tenant Authorization Bypass

An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to inject persistent mandatory survey questions into another organizer's events via…

Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
7.5 HIGH
CVE-2026-72689 — OpenSignLabs opensignserver - Broken Object Level Authorization

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse c…

Remote | Authorization
Aug 10, 2026 Aug 10, 2026
Aug 10, 2026
Aug 10, 2026
Showing 20 of 9983 Results