Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-18640 — Velociraptor directory traversal via the NewNotebook API

The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The…

velociraptor | Remote | Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.1 MEDIUM
CVE-2026-73210 — Server-Side Request Forgery via Favicon Retrieval in Lookyloo PlaywrightCapture

A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled. PlaywrightCapture implements this option to prevent capture…

Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-51584 — Memos SSO Authentication Bypass Account Takeover

An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is …

| Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
0.0 NA
CVE-2026-51583 — usememos Server-Side Request Forgery

An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by sett…

| Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
10.0 CRITICAL
CVE-2026-48056 — Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, all…

Remote | Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.3 CRITICAL
CVE-2026-48046 — Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Han…

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised rende…

Remote | Misconfiguration
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
9.8 CRITICAL
CVE-2026-46670 — YesWiki: Unauthenticated SQL Injection

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a defa…

Remote | Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.6 HIGH
CVE-2026-19539 — IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletion

Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title,…

prospero_flow_crm | Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.1 MEDIUM
CVE-2026-19434 — Stored Cross-site Scripting in Pentestify finding severity field

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a findin…

pentestify | Remote | Cross-Site Scripting
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.3 MEDIUM
CVE-2026-72785 — Craft CMS before 5.10.6 Authorization Bypass via structures/move-element

Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can…

Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.4 MEDIUM
CVE-2026-72784 — Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-s…

Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.2 MEDIUM
CVE-2026-72783 — Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContained function of the Local file system class. The or…

| Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-72782 — Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates befo…

Remote | Information Disclosure
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.8 HIGH
CVE-2026-72781 — Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape

Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as s…

Remote | Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
6.5 MEDIUM
CVE-2026-72780 — Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey

Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing r…

Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.5 MEDIUM
CVE-2026-72779 — Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject

Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that doe…

Remote | Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
8.8 HIGH
CVE-2026-72778 — Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. C…

Remote | Authentication
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.8 MEDIUM
CVE-2026-72775 — n8n before 1.123.67 SQL Injection via PostgresTrigger Node

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifier parameters (channel, function, and trigger name…

Remote | Injection
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
7.1 HIGH
CVE-2026-72774 — n8n before 1.123.67 Authentication Bypass via HTTP Request Node

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's…

Remote | Authorization
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
4.9 MEDIUM
CVE-2026-72773 — n8n before 2.32.1 Path Traversal via computer-use search_files

n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory confineme…

Remote | Path Traversal
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
Showing 20 of 10275 Results