Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-54768 — WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user ex…

WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-cl…

wpgraphql | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.8 MEDIUM
CVE-2026-53573 — core-geonetwork has an Open Redirect Bypass

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and Keycloak…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.5 MEDIUM
CVE-2026-45377 — Decidim: Private exports can be downloaded through reusable links

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged…

decidim | Remote | Authorization
Jul 31, 2026 Aug 01, 2026
Jul 31, 2026
Aug 01, 2026
5.5 MEDIUM
CVE-2026-45376 — Decidim: Admin user search allows SQL injection through similarity-based sorting

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] in…

decidim | Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.9 MEDIUM
CVE-2026-45330 — Decidim: Verification admins can access supplied IDs from other organisations

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Auth…

decidim | Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.8 HIGH
CVE-2026-34641 — Premiere Pro | Out-of-bounds Write (CWE-787)

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction…

premiere | Memory Corruption
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.8 CRITICAL
CVE-2026-68771 — ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted p…

Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-52371 — XXL-Job Server-Side Request Forgery

A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.

| Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-52232 — FS Inc S3150-8T2F Switch Reflected Cross-Site Scripting

A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the …

| Cross-Site Scripting
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-52134 — libiec61850 Authentication Bypass Vulnerability

An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.

| Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-51953 — FeehiCMS Privilege Escalation Vulnerability

An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication logic, logout handler components

| Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.4 MEDIUM
CVE-2026-45086 — Decidim: Forms admin question editor lacks authorization

Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach t…

decidim | Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
9.8 CRITICAL
CVE-2026-68770 — sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_c…

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within se…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.1 HIGH
CVE-2026-65981 — Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN alloca…

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does n…

coturn | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-51785 — Hiawatha Remote Code Execution

An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-50986 — PrestaShop Totadministrativemandate Module Cross-Site Request Forgery

PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awai…

| Cross-Site Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-38713 — TOTOLINK Command Injection Vulnerability

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulner…

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-38710 — TR-Series System Command Injection Vulnerability

TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock interface. This vulnerability allows attackers to execute arbitrary commands as r…

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-38708 — TOTOLINK Router Command Injection Vulnerability

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulner…

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2025-69948 — Modern Loan Management System SQL Injection

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.

| Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
Showing 20 of 9406 Results