Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-72593 — dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access

A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager functionality including reading, writing, deleting, an…

phpfilemanager | Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72592 — dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload

An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships with an empty up…

phpfilemanager | Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
7.7 HIGH
CVE-2026-72591 — Koito - Authenticated Server-Side Request Forgery via Album Image URL Parameter

A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP requests to arbitrary internal or external hosts by supp…

| Server-Side Request Forgery
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72590 — alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter

An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job entries by sending a crafted GET request to /cron…

| Injection
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72589 — alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database ho…

An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system commands by importing a crafted crontab database f…

| Injection
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.3 MEDIUM
CVE-2026-72588 — bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password Rec…

A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/rec…

checkmate | Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
6.1 MEDIUM
CVE-2026-72587 — Instatic - Cache Poisoning via Unauthenticated Server Island Endpoint

A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison the shared process-wide render cache by manipulating the u query parameter of …

| Misconfiguration
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-72586 — frangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event Handler

A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEna…

fuxa | Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
7.4 HIGH
CVE-2026-72584 — fastschema - TOCTOU Race Condition Bypasses OTP Attempt Limit in Account Recovery

A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attacker to bypass the OTP attempt limit on the account recovery flow, enabling brut…

| Race Condition
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-72583 — fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Upload

A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated user to upload an SVG file containing malicious JavaScript by bypassing the MIME …

| Cross-Site Scripting
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-72582 — fastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery Endpoint

A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a single HTTP request. The sendOTPEmail function in p…

| Denial of Service
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
8.6 HIGH
CVE-2026-72581 — duhow xiaoai-patch - Server-Side Request Forgery in /auth Endpoint

A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to arbitrary internal o…

| Server-Side Request Forgery
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72580 — duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints

An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on Xiaomi smart speakers running the patch. The /mute …

| Injection
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
7.5 HIGH
CVE-2026-72579 — NASA HyperCP - OS Command Injection via Malicious HTTP Response from Data Server

An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from oceandata.sci.gsfc.nasa.gov to execute arbitrary syste…

| Injection
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-72578 — FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher

A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.

| Cross-Site Request Forgery
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.8 CRITICAL
CVE-2026-72577 — NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE an…

Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to conn…

| Authentication
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
5.4 MEDIUM
CVE-2026-72576 — Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload

A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Author role) to inject arbitrary JavaScript by uploading a crafted SVG file as the s…

bludit | Cross-Site Scripting
Aug 10, 2026 Aug 28, 2026
Aug 10, 2026
Aug 28, 2026
9.1 CRITICAL
CVE-2026-72575 — daptin - Authentication Bypass via Null Owner Permission Check on usergroup Objects

An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, create, update, and delete usergroup records. The permission check functions (CanRe…

| Authorization
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
6.1 MEDIUM
CVE-2026-72574 — picocms Pico - Host Header Injection Enables Script Source Hijacking

A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control the origin of JavaScript and CSS assets loaded by the default theme. When base…

| Misconfiguration
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-72573 — 4xmen pm2panel - Authenticated OS Command Injection via id Query Parameter

An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execute arbitrary system commands on the host. The pm2panel.js handler at line 188 pa…

| Injection
Aug 10, 2026 Sep 03, 2026
Aug 10, 2026
Sep 03, 2026
Showing 20 of 13880 Results