Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-55986 — Email Management API Bypasses ManageCredentials Feature Restrictions

Email Management API Bypasses ManageCredentials Feature Restrictions

| Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-55984 — Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

| Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-55982 — OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

| Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-54481 — Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-2…

Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

| Misconfiguration
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-50105 — RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix o…

RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

| Authentication
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-42931 — Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

| Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-23603 — Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim

| Server-Side Request Forgery
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.8 HIGH
CVE-2026-59109 — Zalktis: SQL injection via partner-controlled fields in imported e-invoices

SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce expor…

Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-73266 — Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels…

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the te…

multicluster_engine_for_kubernetes | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-13051 — Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attac…

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_…

| Information Disclosure
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2026-13048 — Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalo…

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catal…

| Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
0.0 NA
CVE-2022-4993 — HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispat…

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data…

| Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.1 MEDIUM
CVE-2026-73671 — Saurus CMS Unauthenticated Open Redirect via logout url parameter

Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed di…

Remote | Misconfiguration
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
8.6 HIGH
CVE-2026-73670 — CMS Admin SQL Injection via db_data.php table_name Parameter

A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsaniti…

Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.3 MEDIUM
CVE-2026-73576 — Zimbra Collaboration OnlyOffice Integration Weak Cryptographic Key Generation Vulnerabili…

In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure r…

collaboration | Remote | Cryptography
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
3.1 LOW
CVE-2026-73575 — Zimbra Collaboration Cross-Site Request Forgery Vulnerability

In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient va…

collaboration | Remote | Cross-Site Request Forgery
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
3.1 LOW
CVE-2026-73574 — Zimbra Collaboration Local File Inclusion Vulnerability

In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated a…

collaboration | Remote | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
3.1 LOW
CVE-2026-73573 — Zimbra Collaboration Path Traversal Vulnerability

In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An aut…

collaboration | Remote | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.1 MEDIUM
CVE-2026-73572 — Zimbra Collaboration Stored Cross-Site Scripting Vulnerability

In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content…

collaboration | Remote | Cross-Site Scripting
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
3.1 LOW
CVE-2026-73571 — Zimbra Collaboration Authorization Bypass

An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker …

collaboration | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
Showing 20 of 11267 Results