Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-75329 — Super-Diamond Server Unauthorized Configuration Access Vulnerability

The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (includi…

| Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-75328 — DocSys Arbitrary File Read Vulnerability

In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:

| Path Traversal
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
4.8 MEDIUM
CVE-2026-65930 — LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields

LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects L…

limesurvey | Remote | Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.7 HIGH
CVE-2026-65647 — Plesk Improper Symlink Resolution Arbitrary Code Execution

Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.

Remote | Path Traversal
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.7 HIGH
CVE-2026-65646 — Plesk Improper Neutralization of Special Elements Vulnerability

Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.

Remote | Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.6 HIGH
CVE-2026-65642 — Plesk Insecure Direct Object Reference Vulnerability

Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.

Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
9.3 CRITICAL
CVE-2026-65641 — Microsoft SMB Server NTLM Authentication Relay Vulnerability

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

one one | Remote | Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.5 HIGH
CVE-2026-64632 — Reporter Service NTLM Credential Exposure

A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.

one one | Remote | Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.4 HIGH
CVE-2026-63360 — LimeSurvey Community Edition 7.0.5 - Reflected XSS in user activation confirmation endpoi…

LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied int…

limesurvey | Remote | Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.7 HIGH
CVE-2026-61617 — Pterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk ex…

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfe…

wings | Remote | Denial of Service
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
6.8 MEDIUM
CVE-2026-58070 — VMware Guest OS Credential Exposure in Support Logs

A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.

Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.6 HIGH
CVE-2026-55182 — LibreNMS: Remote Code Execution by Signal Alert Transportation Module

LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an …

librenms | Remote | Injection
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
5.4 MEDIUM
CVE-2026-45694 — LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid parameters

LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vm…

librenms | Remote | Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NONE
CVE-2026-43621 — Simple Machines Forum < 2.1.7 Authorization Confusion via Profile::load()

Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gai…

simple_machines_forum smf | Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
4.4 MEDIUM
CVE-2026-21810 — HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference a…

HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the bina…

| Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
3.9 LOW
CVE-2026-21809 — HCL BigFix Quantum Risk Analyzer is affected by generating error messages with sensitive …

HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more effici…

| Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.2 HIGH
CVE-2026-16809 — LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering

LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own…

limesurvey | Remote | Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.9 HIGH
CVE-2026-79921 — amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Ove…

amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the nego…

Remote | Denial of Service
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
3.5 LOW
CVE-2026-77573 — Weblate: DNS rebinding in VCS operations allows server-side request forgery

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs can perform server-side…

weblate | Remote | Server-Side Request Forgery
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
5.3 MEDIUM
CVE-2026-77507 — Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the permission checks used el…

weblate | Remote | Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
Showing 20 of 12209 Results