CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2026-32587

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP EasyPay: from n/a through <= 4.2.11.

    Published: 16 Mar 2026
    5.3
    Medium

    CVE-2026-32583

    Last Modified: 22 Apr 2026

    Missing Authorization vulnerability in Webnus Inc. Modern Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Modern Events Calendar: from n/a through 7.29.0.

    Published: 16 Mar 2026
    1.1
    Low

    CVE-2026-4243

    Last Modified: 22 Apr 2026

    A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/app/lanacion/clublanacion/BuildConfig.java of the component app.lanacion.activity. Executing a manipulation of the argument API_KEY_WEBSOCKET_CV can lead to unprotected storage of credentials. The attack can only be executed locally. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    4.3
    Medium

    CVE-2026-24692

    Last Modified: 24 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554

    Published: 16 Mar 2026
    3.1
    Low

    CVE-2026-22545

    Last Modified: 24 Mar 2026

    Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type switch which allows an authenticated attacker to change account password without confirmation via falsely claiming a different auth provider.. Mattermost Advisory ID: MMSA-2026-00583

    Published: 16 Mar 2026
    4.3
    Medium

    CVE-2026-2455

    Last Modified: 24 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation which allows an attacker to perform SSRF attacks against internal services via IPv4-mapped IPv6 literals (e.g., [::ffff:127.0.0.1]).. Mattermost Advisory ID: MMSA-2026-00585

    Published: 16 Mar 2026
    4.3
    Medium

    CVE-2026-21386

    Last Modified: 24 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID: MMSA-2026-00588

    Published: 16 Mar 2026
    4.8
    Medium

    CVE-2025-2274

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web Security through 8.5.6.

    Published: 16 Mar 2026
    3.3
    Low

    CVE-2025-52642

    Last Modified: 24 Mar 2026

    HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information disclosure.

    Published: 16 Mar 2026
    2.2
    Low

    CVE-2025-52646

    Last Modified: 24 Mar 2026

    HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information exposure under specific conditions.

    Published: 16 Mar 2026
    1.9
    Low

    CVE-2025-52645

    Last Modified: 25 Apr 2026

    HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or unintended behaviour.

    Published: 16 Mar 2026
    1.8
    Low

    CVE-2025-52649

    Last Modified: 25 Apr 2026

    HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infer or guess system-generated values, potentially leading to limited information disclosure or unintended access under specific conditions.

    Published: 16 Mar 2026
    1.1
    Low

    CVE-2026-4242

    Last Modified: 22 Apr 2026

    A security flaw has been discovered in BabyChakra Pregnancy & Parenting App up to 5.4.3.0 on Android. This affects an unknown function of the file file app/babychakra/babychakra/Configuration.java of the component app.babychakra.babychakra. Performing a manipulation of the argument SEGMENT_WRITE_KEY results in unprotected storage of credentials. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    5.8
    Medium

    CVE-2025-52644

    Last Modified: 24 Mar 2026

    HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation processes.

    Published: 16 Mar 2026
    4.7
    Medium

    CVE-2025-52643

    Last Modified: 25 Apr 2026

    HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or integrity impact when processing specially crafted files.

    Published: 16 Mar 2026
    1.8
    Low

    CVE-2025-52636

    Last Modified: 25 Apr 2026

    HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, which could potentially lead to service degradation or denial-of-service conditions under certain scenarios.

    Published: 16 Mar 2026
    7.1
    High

    CVE-2026-25369

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Reflected XSS.This issue affects Flexmls® IDX: from n/a through <= 3.15.9.

    Published: 16 Mar 2026
    2.1
    Low

    CVE-2026-4241

    Last Modified: 22 Apr 2026

    A vulnerability was identified in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/time-table.php. Such manipulation of the argument course_code leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

    Published: 16 Mar 2026
    5.5
    Medium

    CVE-2026-4240

    Last Modified: 24 Mar 2026

    A vulnerability was determined in Open5GS up to 2.7.6. The affected element is the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6b_aaa_cb/smf_s6b_sta_cb of the component CCA Handler. This manipulation causes denial of service. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.7.7 is sufficient to fix this issue. Patch name: 80eb484a6ab32968e755e628b70d1a9c64f012ec. Upgrading the affected component is recommended.

    Published: 16 Mar 2026
    5.3
    Medium

    CVE-2025-10461

    Last Modified: 27 Mar 2026

    Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access. This issue affects smartLink SW-HT: through 1.42 smartLink SW-PN: through 1.03.

    Published: 16 Mar 2026
    7.7
    High

    CVE-2025-10685

    Last Modified: 27 Mar 2026

    Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42

    Published: 16 Mar 2026
    2
    Low

    CVE-2026-4239

    Last Modified: 22 Apr 2026

    A vulnerability was found in Lagom WHMCS Template up to 2.3.7. Impacted is an unknown function of the component Datatables. The manipulation results in improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Mar 2026
    4.3
    Medium

    CVE-2026-25780

    Last Modified: 24 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing DOC files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted DOC file.. Mattermost Advisory ID: MMSA-2026-00581

    Published: 16 Mar 2026
    4.8
    Medium

    CVE-2025-52648

    Last Modified: 30 Mar 2026

    HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system

    Published: 16 Mar 2026
    5.6
    Medium

    CVE-2025-52638

    Last Modified: 30 Mar 2026

    HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Running containers with root privileges may increase the potential security risk, as it grants elevated permissions within the container environment. Aligning container configurations with security best practices requires minimizing privileges and avoiding root-level execution wherever possible.

    Published: 16 Mar 2026
    2
    Low

    CVE-2026-4238

    Last Modified: 22 Apr 2026

    A vulnerability has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/courses.php. The manipulation of the argument course_code leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Mar 2026
    4.5
    Medium

    CVE-2025-52637

    Last Modified: 30 Mar 2026

    HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information exposure under specific conditions.

    Published: 16 Mar 2026
    4.3
    Medium

    CVE-2026-4265

    Last Modified: 30 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permission via uploading files in a team where they have permission and reusing the file metadata in a POST request to a different team. Mattermost Advisory ID: MMSA-2025-00553

    Published: 16 Mar 2026
    4.3
    Medium

    CVE-2026-25783

    Last Modified: 30 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advisory ID: MMSA-2026-00586

    Published: 16 Mar 2026
    7.5
    High

    CVE-2026-24458

    Last Modified: 30 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with multi-megabyte passwords. Mattermost Advisory ID: MMSA-2026-00587

    Published: 16 Mar 2026
    5.5
    Medium

    CVE-2026-4237

    Last Modified: 22 Apr 2026

    A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod_reports/index.php. Executing a manipulation of the argument Home can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

    Published: 16 Mar 2026
    6.6
    Medium

    CVE-2026-2462

    Last Modified: 30 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528

    Published: 16 Mar 2026
    4.3
    Medium

    CVE-2026-2578

    Last Modified: 30 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579

    Published: 16 Mar 2026
    6.9
    Medium

    CVE-2025-69246

    Last Modified: 30 Mar 2026

    Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throttling, or step-up challenges. This issue was fixed in version 1.4.6.

    Published: 16 Mar 2026
    5.1
    Medium

    CVE-2025-69245

    Last Modified: 30 Mar 2026

    Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malicious URL which, when opened by the authenticated victim, results in arbitrary JavaScript execution in the victim’s browser. This issue was fixed in 1.4.6.

    Published: 16 Mar 2026
    6.9
    Medium

    CVE-2025-69243

    Last Modified: 30 Mar 2026

    Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an attacker to determine if the login is valid or not, enabling a brute force attack with valid logins. This issue was fixed in version 1.5.0.

    Published: 16 Mar 2026
    5.1
    Medium

    CVE-2025-69242

    Last Modified: 30 Mar 2026

    Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the victim’s browser. This issue was fixed in version 1.4.6.

    Published: 16 Mar 2026
    5.3
    Medium

    CVE-2025-69241

    Last Modified: 30 Mar 2026

    Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authenticated attacker can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. This issue was fixed in version 1.4.6.

    Published: 16 Mar 2026
    7.5
    High

    CVE-2025-69240

    Last Modified: 30 Mar 2026

    Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker (who knows the victim's email address) can force the server to send an email with password reset link pointing to the domain from spoofed header. When victim clicks the link, browser sends request to the attacker’s domain with the token in the path allowing the attacker to capture the token. This allows the attacker to reset victim's password and take over the victim's account. This issue was fixed in version 1.4.6.

    Published: 16 Mar 2026
    5.1
    Medium

    CVE-2025-69239

    Last Modified: 30 Mar 2026

    Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. It allows an attacker with high privileges to provide the URL for redirecting server-side HTTP request. This issue was fixed in version 1.4.6.

    Published: 16 Mar 2026
    6.9
    Medium

    CVE-2025-69238

    Last Modified: 30 Mar 2026

    Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, which when visited by the authenticated victim, will automatically send POST request to the endpoint (e. x. deletion of the data) without enforcing token verification.  This issue was fixed in version 1.4.6.

    Published: 16 Mar 2026
    5.1
    Medium

    CVE-2025-69237

    Last Modified: 30 Mar 2026

    Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated attacker with permissions to create content can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. This issue was fixed in version 1.4.6.

    Published: 16 Mar 2026
    5.1
    Medium

    CVE-2025-69236

    Last Modified: 30 Mar 2026

    Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. Authenticated attacker with permissions to edit posts can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. This issue was fixed in version 1.4.6.

    Published: 16 Mar 2026
    8.6
    High

    CVE-2025-15540

    Last Modified: 30 Mar 2026

    "Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack of sandboxing or access restrictions, JavaScript code executed through Raytha’s “functions” feature can instantiate .NET components and perform arbitrary operations within the application’s hosting environment. This issue was fixed in version 1.4.6.

    Published: 16 Mar 2026
    7.8
    High

    CVE-2026-3476

    Last Modified: 8 Jun 2026

    A Code Injection vulnerability affecting SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code on the user's machine while opening a specially crafted file.

    Published: 16 Mar 2026
    4.3
    Medium

    CVE-2026-26246

    Last Modified: 30 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted PSD file. Mattermost Advisory ID: MMSA-2026-00572

    Published: 16 Mar 2026
    5.5
    Medium

    CVE-2026-4236

    Last Modified: 22 Apr 2026

    A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=add. Such manipulation of the argument txtsearch/deptname/name leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

    Published: 16 Mar 2026
    4.3
    Medium

    CVE-2026-2458

    Last Modified: 30 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all public channels within a private team via the channel search API endpoint.. Mattermost Advisory ID: MMSA-2025-00568

    Published: 16 Mar 2026
    4.3
    Medium

    CVE-2026-2457

    Last Modified: 30 Mar 2026

    Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post update API endpoint.. Mattermost Advisory ID: MMSA-2025-00569

    Published: 16 Mar 2026
    4.3
    Medium

    CVE-2026-2461

    Last Modified: 30 Mar 2026

    Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermost Advisory ID: MMSA-2025-00559

    Published: 16 Mar 2026