|
CVE-2026-82475
|
|
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
|
High
|
Cwe 862
Authentication Bypass
|
18 hours ago
|
|
CVE-2026-82472
|
|
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
|
High
|
Cwe 306
Remote Code Execution
|
18 hours ago
|
|
CVE-2026-82466
|
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
High
|
Authentication Bypass
Cwe 287
Ruby
|
18 hours ago
|
|
CVE-2026-81421
|
|
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
|
High
|
Cwe 918
Server-Side Request Forgery
|
3 days ago
|
|
CVE-2026-77652
|
|
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
|
High
|
C
Cwe 122
Buffer Overflow
|
3 days ago
|
|
CVE-2026-68861
|
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
|
High
|
Cwe 78
Os
Command Injection
Dell
+1
|
3 days ago
|
|
CVE-2026-68863
|
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
|
High
|
Denial of Service
Cwe 121
Buffer Overflow
Denial Of Service
+2
|
3 days ago
|
|
CVE-2021-23758
KEV
|
|
Remote Code Execution in AjaxNetProfessional
Remote Code Execution in AjaxNetProfessional
|
High
|
Cwe 502
Remote Code Execution
Insecure Deserialization
C#
+4
|
4 days ago
|
|
CVE-2026-18328
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
5 days ago
|
|
CVE-2026-16601
|
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
High
|
JavaScript
WordPress
Remote Code Execution
Cwe 434
+1
|
5 days ago
|
|
CVE-2026-18323
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
5 days ago
|
|
CVE-2026-68960
|
|
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
|
High
|
Cwe 121
Buffer Overflow
Windows
|
5 days ago
|
|
CVE-2026-78680
|
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
High
|
Cwe 426
Python
Remote Code Execution
|
5 days ago
|
|
CVE-2026-75574
|
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
High
|
PHP
Cwe 1336
WordPress
Remote Code Execution
|
5 days ago
|
|
CVE-2026-78675
|
|
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
|
High
|
Cwe 73
Python
Path Traversal
|
5 days ago
|
|
CVE-2026-72695
|
|
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
|
High
|
Path Traversal
Cwe 22
|
5 days ago
|
|
CVE-2026-56707
|
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
High
|
Cwe 862
WordPress
PHP
Authentication Bypass
|
5 days ago
|
|
CVE-2026-56702
|
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
High
|
PHP
Cwe 434
Remote Code Execution
|
5 days ago
|
|
CVE-2026-34968
|
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
High
|
PHP
C
Cwe 22
Adminer
+1
|
5 days ago
|
|
CVE-2026-71506
|
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
|
High
|
Cwe 863
Remote Code Execution
Enterprise Saas
|
5 days ago
|
|
CVE-2026-71504
|
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
|
High
|
Cwe 862
Cwe 915
PHP
|
5 days ago
|
|
CVE-2026-40877
|
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
High
|
PHP
Remote Code Execution
Cwe 94
Cwe 502
|
5 days ago
|
|
CVE-2026-30864
|
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in v...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
|
High
|
Cross-Site Scripting
Cwe 79
|
5 days ago
|
|
CVE-2026-78208
|
|
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
|
High
|
JavaScript
Path Traversal
Cwe 73
|
6 days ago
|
|
CVE-2026-78161
|
|
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
|
High
|
C
Cwe 119
Cwe 787
Buffer Overflow
|
6 days ago
|
|
CVE-2026-4671
|
|
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
|
High
|
Cwe 400
Denial Of Service
JavaScript
|
6 days ago
|
|
CVE-2026-30866
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
|
High
|
Cwe 200
Cwe 306
Web Application
Authentication Bypass
|
1 week ago
|
|
CVE-2026-27490
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue ha...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
|
High
|
Cwe 330
Cwe 331
Web Application
Authentication Bypass
|
1 week ago
|
|
CVE-2026-30819
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.
|
High
|
PHP
Cross-Site Scripting
Cwe 79
|
1 week ago
|
|
CVE-2026-54682
|
|
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and Format...
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it w...
|
High
|
Cwe 79
Cross-Site Scripting
|
1 week ago
|
|
CVE-2026-73197
|
|
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
|
High
|
Denial of Service
Cwe 770
Redhat
Enterprise Linux
+1
|
1 week ago
|
|
CVE-2026-19905
|
|
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
|
High
|
SQL Injection
Cwe 74
Cwe 89
Sql Injection
|
2 weeks ago
|
|
CVE-2026-14279
|
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
High
|
WordPress
Privilege Escalation
Cwe 269
PHP
|
2 weeks ago
|
|
CVE-2026-73680
|
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
High
|
Cwe 78
Cockpit
PHP
Command Injection
|
2 weeks ago
|
|
CVE-2026-19826
|
|
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
|
High
|
Java
Insecure Deserialization
Cwe 20
Cwe 502
|
2 weeks ago
|
|
CVE-2026-19825
|
|
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
|
2 weeks ago
|
|
CVE-2026-19794
|
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
2 weeks ago
|
|
CVE-2026-19764
|
|
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
+2
|
2 weeks ago
|
|
CVE-2026-19762
|
|
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
|
High
|
Java
Path Traversal
Cwe 22
|
2 weeks ago
|
|
CVE-2026-19758
|
|
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
|
High
|
Java
Path Traversal
Cwe 22
|
2 weeks ago
|
|
CVE-2026-19757
|
|
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
|
High
|
Java
Path Traversal
Cwe 22
|
2 weeks ago
|
|
CVE-2026-73654
|
|
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
|
High
|
Denial of Service
Cwe 1321
Remote Code Execution
npm
+1
|
2 weeks ago
|
|
CVE-2026-72777
|
|
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
|
High
|
Cwe 918
Server-Side Request Forgery
|
2 weeks ago
|
|
CVE-2026-18146
|
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
2 weeks ago
|
|
CVE-2026-73031
|
|
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
|
High
|
JavaScript
Vue.js
Cross-Site Scripting
Cwe 79
|
2 weeks ago
|
|
CVE-2026-73222
|
|
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
|
High
|
JavaScript
Cwe 78
Cwe 306
Cwe 352
+2
|
2 weeks ago
|
|
CVE-2026-15426
|
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
|
High
|
WordPress
Cwe 269
PHP
Authentication Bypass
|
2 weeks ago
|
|
CVE-2026-67620
|
|
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
|
High
|
Server-Side Request Forgery
Cwe 918
|
3 weeks ago
|
|
CVE-2026-48026
|
|
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI render...
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write ac...
|
High
|
JavaScript
Cwe 79
Cross-Site Scripting
|
3 weeks ago
|
|
CVE-2026-18325
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
3 weeks ago
|