Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2025-15627 — Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication

A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and m…

| Cryptography
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.9 MEDIUM
CVE-2025-15544 — Weak Credential Protection During TP-Link Omada Device Adoption

A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that …

| Cryptography
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.6 HIGH
CVE-2026-61524 — WebsiteBaker CMS < 2.13.10 File Upload RCE via Module Installation

WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uplo…

Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.6 HIGH
CVE-2026-61523 — WebsiteBaker CMS < 2.13.10 Code Injection via Droplets Editor

WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content th…

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.6 MEDIUM
CVE-2026-40717 — Dell Monitor Driver Improper Link Resolution Elevation of Privilege Vulnerability

Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit t…

| Path Traversal
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
10.0 HIGH
CVE-2026-18613 — GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection

A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulati…

gl-mt3000 | Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
10.0 HIGH
CVE-2026-18612 — GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection

A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Nat…

gl-mt3000 | Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.7 HIGH
CVE-2025-9291 — Improper Certificate Validation in TP-Link Omada Cloud Communications

A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certi…

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.3 MEDIUM
CVE-2026-69153 — PostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads ar…

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousM…

Remote | Path Traversal
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 miti…

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alt…

brace-expansion | Remote | Denial of Service
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.6 HIGH
CVE-2026-69151 — Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pi…

Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.6 HIGH
CVE-2026-69149 — Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scri…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS)…

Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.8 HIGH
CVE-2026-68945 — Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse…

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-join…

Remote | Misconfiguration
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
6.5 MEDIUM
CVE-2026-68930 — Russh: Channel-scoped server callbacks can be reached without an open channel

Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encry…

Remote | Authorization
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
4.8 MEDIUM
CVE-2026-67612 — OpenEMR 8.2.0 Stored XSS via import_template.php Template Management

OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript by st…

Remote | Cross-Site Scripting
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.6 HIGH
CVE-2026-67611 — OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password …

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.1 HIGH
CVE-2026-67610 — OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with sy…

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
7.5 HIGH
CVE-2026-61372 — Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to up…

jena_fuseki | Remote | Path Traversal
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
8.8 HIGH
CVE-2026-41453 — Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter

Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulati…

Remote | Injection
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
9.8 CRITICAL
CVE-2026-41452 — Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a c…

Remote | Authentication
Aug 03, 2026 Aug 03, 2026
Aug 03, 2026
Aug 03, 2026
Showing 20 of 9339 Results