CVE watch

Every disclosure pulled from the NVD feed, filterable by severity.

All Critical High Medium Low Unknown
CVE-2026-28162 HIGH

CVE-2026-28162 published: Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.

View full advisory →
CVE-2026-28165 CRITICAL

CVE-2026-28165 published: Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

View full advisory →
CVE-2026-28166 HIGH

CVE-2026-28166 published: Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.

View full advisory →
CVE-2026-28167 HIGH

CVE-2026-28167 published: Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.

View full advisory →
CVE-2026-28171 HIGH

CVE-2026-28171 published: Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.

View full advisory →
CVE-2025-63080 UNKNOWN

CVE-2025-63080 published: Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.    This vulnerability has been fixed in firmware version: 3.0...

View full advisory →
CVE-2026-78245 HIGH

CVE-2026-78245 published: A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upl...

View full advisory →
CVE-2026-78337 UNKNOWN

CVE-2026-78337 published: Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application o...

View full advisory →
CVE-2026-78244 HIGH

CVE-2026-78244 published: A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in...

View full advisory →
CVE-2026-76172 HIGH

CVE-2026-76172 published: fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the re...

View full advisory →
CVE-2026-59295 MEDIUM

CVE-2026-59295 published: Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when as...

View full advisory →
CVE-2026-10618 MEDIUM

CVE-2026-10618 published: Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without es...

View full advisory →
CVE-2026-10582 HIGH

CVE-2026-10582 published: Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alo...

View full advisory →
CVE-2026-75931 HIGH

CVE-2026-75931 published: fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a sche...

View full advisory →
CVE-2026-75975 HIGH

CVE-2026-75975 published: fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so inval...

View full advisory →
CVE-2026-78317 HIGH

CVE-2026-78317 published: SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

View full advisory →
CVE-2026-78314 HIGH

CVE-2026-78314 published: SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

View full advisory →
CVE-2026-78315 HIGH

CVE-2026-78315 published: SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

View full advisory →
CVE-2026-78316 HIGH

CVE-2026-78316 published: SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

View full advisory →
CVE-2026-66897 CRITICAL

CVE-2026-66897 published: A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user laun...

View full advisory →