CVE watch
Every disclosure pulled from the NVD feed, filterable by severity.
CVE-2025-63080 published: Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution. This vulnerability has been fixed in firmware version: 3.0...
View full advisory →CVE-2026-78245 published: A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upl...
View full advisory →CVE-2026-78337 published: Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application o...
View full advisory →CVE-2026-78244 published: A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in...
View full advisory →CVE-2026-76172 published: fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the re...
View full advisory →CVE-2026-59295 published: Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when as...
View full advisory →CVE-2026-10618 published: Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without es...
View full advisory →CVE-2026-10582 published: Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alo...
View full advisory →CVE-2026-75931 published: fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a sche...
View full advisory →CVE-2026-75975 published: fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so inval...
View full advisory →CVE-2026-78317 published: SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
View full advisory →CVE-2026-78314 published: SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
View full advisory →CVE-2026-78315 published: SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
View full advisory →CVE-2026-78316 published: SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
View full advisory →CVE-2026-66897 published: A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user laun...
View full advisory →CVE-2026-75899 published: fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a seco...
View full advisory →CVE-2026-16249 published: Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability i...
View full advisory →CVE-2026-78306 published: DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi...
View full advisory →CVE-2026-78321 published: The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access ...
View full advisory →CVE-2026-77993 published: Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a refle...
View full advisory →