Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-36762 — JeeSite File Upload Path Traversal Vulnerability

An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary fi…

| Path Traversal
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.1 MEDIUM
CVE-2026-36761 — JeeSite Stored XSS Vulnerability

A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into th…

Remote | Cross-Site Scripting
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.5 HIGH
CVE-2026-33845 — Gnutls: gnutls: denial of service via dtls zero-length fragment

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This…

Remote | Memory Corruption
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
10.0 CRITICAL
CVE-2026-36767 — Shopizer Path Traversal File Write Vulnerability

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request.

Remote | Path Traversal
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
5.0 MEDIUM
CVE-2026-36764 — SpringBlade SSRF Vulnerability

A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request.

Remote | Server-Side Request Forgery
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
9.6 CRITICAL
CVE-2026-36760 — JeeSite File Upload Path Traversal Write Arbitrary Files

An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files w…

Remote | Path Traversal
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
4.3 MEDIUM
CVE-2026-36757 — Halo SSRF

A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Remote | Server-Side Request Forgery
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
9.8 CRITICAL
CVE-2025-71284 — Synway SMG Gateway Management Software OS Command Injection via radius_address

Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and in…

Remote | Injection
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
8.7 HIGH
CVE-2025-51846 — CryptPad unbounded WebSocket frame flood

CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.

cryptpad | Remote | Denial of Service
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
9.8 CRITICAL
CVE-2022-50993 — Weaver E-office < 10.0_20221201 Unauthenticated Arbitrary File Read via XmlRpcServlet

Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicio…

Remote | Authentication
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
8.7 HIGH
CVE-2022-50992 — Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet

Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers t…

e-cology | Remote | Path Traversal
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.7 HIGH
CVE-2026-5174 — Improper Access Control Vulnerability in Progress MOVEit Automation

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before …

Remote | Authorization
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
9.8 CRITICAL
CVE-2026-4670 — Improper Authentication vulnerability in Progress MOVEit Automation

Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from…

Remote | Authentication
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.1 MEDIUM
CVE-2026-38940 — RafyMrX TOKO-ONLINE-ROTI Cross-Site Scripting

Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php component

Remote | Cross-Site Scripting
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.1 MEDIUM
CVE-2026-38939 — Andrewtch88 MVC-Ecommerce Cross-Site Scripting Vulnerability

Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the product_catalogue.php component

Remote | Cross-Site Scripting
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
8.8 HIGH
CVE-2026-36960 — U-SPEED N300 Router CSRF Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF…

Remote | Cross-Site Request Forgery
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-36759 — Halo SSRF Vulnerability

A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Remote | Server-Side Request Forgery
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
4.3 MEDIUM
CVE-2026-36758 — Halo SSRF

A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Remote | Server-Side Request Forgery
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
5.4 MEDIUM
CVE-2026-36756 — Halo SSRF

A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Remote | Server-Side Request Forgery
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
8.1 HIGH
CVE-2026-36340 — Krayin CRM Remote Code Execution

An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function

Remote | Information Disclosure
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
Showing 20 of 5809 Results