Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.9 LOW
CVE-2026-21807 — HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflow

HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.

| Memory Corruption
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
3.7 LOW
CVE-2025-62341 — HCL Connections is vulnerable to server-side request forgery (SSRF)

HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to …

Remote | Server-Side Request Forgery
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.5 HIGH
CVE-2026-81202 — itsourcecode Payroll System CRUD Operation ajax.php delete missing authentication

A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a mani…

payroll_system | Remote | Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.1 HIGH
CVE-2026-77611 — SeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwriting a diff…

SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested object key can overwrite a different object…

seaweedfs | Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.6 HIGH
CVE-2026-77368 — SeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbitrary Write t…

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a …

seaweedfs | Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.1 HIGH
CVE-2026-77317 — SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwrite

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a …

seaweedfs | Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.7 HIGH
CVE-2026-77298 — SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy

SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external OIDC JWT sent directly in the Authorization header and maps it to an IAM ro…

seaweedfs | Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-75333 — YX Image Recognition Path Traversal

yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist val…

| Path Traversal
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-75331 — Tamguo Unrestricted File Upload and Stored Cross-Site Scripting

tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type valida…

| Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-75329 — Super-Diamond Server Unauthorized Configuration Access Vulnerability

The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (includi…

| Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
0.0 NA
CVE-2026-75328 — DocSys Arbitrary File Read Vulnerability

In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:

| Path Traversal
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
4.8 MEDIUM
CVE-2026-65930 — LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields

LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects L…

limesurvey | Remote | Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.7 HIGH
CVE-2026-65647 — Plesk Improper Symlink Resolution Arbitrary Code Execution

Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.

Remote | Path Traversal
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.7 HIGH
CVE-2026-65646 — Plesk Improper Neutralization of Special Elements Vulnerability

Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.

Remote | Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.6 HIGH
CVE-2026-65642 — Plesk Insecure Direct Object Reference Vulnerability

Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.

Remote | Authorization
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
9.3 CRITICAL
CVE-2026-65641 — Microsoft SMB Server NTLM Authentication Relay Vulnerability

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

one one | Remote | Authentication
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
8.5 HIGH
CVE-2026-64632 — Reporter Service NTLM Credential Exposure

A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.

one one | Remote | Information Disclosure
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.4 HIGH
CVE-2026-63360 — LimeSurvey Community Edition 7.0.5 - Reflected XSS in user activation confirmation endpoi…

LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied int…

limesurvey | Remote | Cross-Site Scripting
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
7.7 HIGH
CVE-2026-61617 — Pterodactyl Wings SFTP write path does not enforce disk quota, allowing node-wide disk ex…

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfe…

wings | Remote | Denial of Service
Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
6.8 MEDIUM
CVE-2026-58070 — VMware Guest OS Credential Exposure in Support Logs

A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.

Aug 26, 2026 Aug 26, 2026
Aug 26, 2026
Aug 26, 2026
Showing 20 of 12256 Results