5.3
CVE-2026-24096 - Insufficient permission validation on multiple REST API Quick Setup endpoints
Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged users to perform unauthorized actions or obtain sensitive information
6.9
CVE-2026-0932 -
Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs.
5.3
CVE-2026-1879 - Harvard University IQSS Dataverse Theme Customization ThemeAndWidgets.xhtml unrestricted upload
A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a manipulation of the argument uploadLogo results in unrestricted upload. Remote exploitation of the atta…
5.3
CVE-2024-53828 - Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulner…
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.
6.9
CVE-2026-21630 - Joomla! Core - [20260302] - SQL injection in com_content articles webservice endpoint
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.