|
CVE-2026-82475
|
|
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
|
High
|
Cwe 862
Authentication Bypass
|
il y a 13 heures
|
|
CVE-2026-82472
|
|
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
|
High
|
Cwe 306
Remote Code Execution
|
il y a 13 heures
|
|
CVE-2026-82466
|
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
High
|
Authentication Bypass
Cwe 287
Ruby
|
il y a 13 heures
|
|
CVE-2026-81421
|
|
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
|
High
|
Cwe 918
Server-Side Request Forgery
|
il y a 3 jours
|
|
CVE-2026-77652
|
|
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
|
High
|
C
Cwe 122
Buffer Overflow
|
il y a 3 jours
|
|
CVE-2026-68861
|
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
|
High
|
Cwe 78
Os
Command Injection
Dell
+1
|
il y a 3 jours
|
|
CVE-2026-68863
|
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
|
High
|
Denial of Service
Cwe 121
Buffer Overflow
Denial Of Service
+2
|
il y a 3 jours
|
|
CVE-2021-23758
KEV
|
|
Remote Code Execution in AjaxNetProfessional
Remote Code Execution in AjaxNetProfessional
|
High
|
Cwe 502
Remote Code Execution
Insecure Deserialization
C#
+4
|
il y a 4 jours
|
|
CVE-2026-18323
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 4 jours
|
|
CVE-2026-16601
|
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
High
|
JavaScript
WordPress
Remote Code Execution
Cwe 434
+1
|
il y a 4 jours
|
|
CVE-2026-18328
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 4 jours
|
|
CVE-2026-68960
|
|
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
|
High
|
Cwe 121
Buffer Overflow
Windows
|
il y a 4 jours
|
|
CVE-2026-78680
|
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
High
|
Cwe 426
Python
Remote Code Execution
|
il y a 5 jours
|
|
CVE-2026-75574
|
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
High
|
PHP
Cwe 1336
WordPress
Remote Code Execution
|
il y a 5 jours
|
|
CVE-2026-78675
|
|
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
|
High
|
Cwe 73
Python
Path Traversal
|
il y a 5 jours
|
|
CVE-2026-72695
|
|
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
|
High
|
Path Traversal
Cwe 22
|
il y a 5 jours
|
|
CVE-2026-56707
|
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
High
|
Cwe 862
WordPress
PHP
Authentication Bypass
|
il y a 5 jours
|
|
CVE-2026-56702
|
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
High
|
PHP
Cwe 434
Remote Code Execution
|
il y a 5 jours
|
|
CVE-2026-34968
|
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
High
|
PHP
C
Cwe 22
Adminer
+1
|
il y a 5 jours
|
|
CVE-2026-71504
|
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
|
High
|
Cwe 862
Cwe 915
PHP
|
il y a 5 jours
|
|
CVE-2026-71506
|
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
|
High
|
Cwe 863
Remote Code Execution
Enterprise Saas
|
il y a 5 jours
|
|
CVE-2026-40877
|
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
High
|
PHP
Remote Code Execution
Cwe 94
Cwe 502
|
il y a 5 jours
|
|
CVE-2026-30864
|
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in v...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 5 jours
|
|
CVE-2026-78208
|
|
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
|
High
|
JavaScript
Path Traversal
Cwe 73
|
il y a 6 jours
|
|
CVE-2026-78161
|
|
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
|
High
|
C
Cwe 119
Cwe 787
Buffer Overflow
|
il y a 6 jours
|
|
CVE-2026-4671
|
|
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
|
High
|
Cwe 400
Denial Of Service
JavaScript
|
il y a 6 jours
|
|
CVE-2026-30866
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
|
High
|
Cwe 200
Cwe 306
Web Application
Authentication Bypass
|
il y a 1 semaine
|
|
CVE-2026-27490
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue ha...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
|
High
|
Cwe 330
Cwe 331
Web Application
Authentication Bypass
|
il y a 1 semaine
|
|
CVE-2026-30819
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.
|
High
|
PHP
Cross-Site Scripting
Cwe 79
|
il y a 1 semaine
|
|
CVE-2026-54682
|
|
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and Format...
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it w...
|
High
|
Cwe 79
Cross-Site Scripting
|
il y a 1 semaine
|
|
CVE-2026-73197
|
|
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
|
High
|
Denial of Service
Cwe 770
Redhat
Enterprise Linux
+1
|
il y a 1 semaine
|
|
CVE-2026-19905
|
|
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
|
High
|
SQL Injection
Cwe 74
Cwe 89
Sql Injection
|
il y a 2 semaines
|
|
CVE-2026-14279
|
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
High
|
WordPress
Privilege Escalation
Cwe 269
PHP
|
il y a 2 semaines
|
|
CVE-2026-73680
|
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
High
|
Cwe 78
Cockpit
PHP
Command Injection
|
il y a 2 semaines
|
|
CVE-2026-19825
|
|
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
|
il y a 2 semaines
|
|
CVE-2026-19826
|
|
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
|
High
|
Java
Insecure Deserialization
Cwe 20
Cwe 502
|
il y a 2 semaines
|
|
CVE-2026-19794
|
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 2 semaines
|
|
CVE-2026-19764
|
|
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
+2
|
il y a 2 semaines
|
|
CVE-2026-19762
|
|
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
|
High
|
Java
Path Traversal
Cwe 22
|
il y a 2 semaines
|
|
CVE-2026-19758
|
|
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
|
High
|
Java
Path Traversal
Cwe 22
|
il y a 2 semaines
|
|
CVE-2026-19757
|
|
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
|
High
|
Java
Path Traversal
Cwe 22
|
il y a 2 semaines
|
|
CVE-2026-73654
|
|
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
|
High
|
Denial of Service
Cwe 1321
Remote Code Execution
npm
+1
|
il y a 2 semaines
|
|
CVE-2026-72777
|
|
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
|
High
|
Cwe 918
Server-Side Request Forgery
|
il y a 2 semaines
|
|
CVE-2026-18146
|
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 2 semaines
|
|
CVE-2026-73031
|
|
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
|
High
|
JavaScript
Vue.js
Cross-Site Scripting
Cwe 79
|
il y a 2 semaines
|
|
CVE-2026-73222
|
|
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
|
High
|
JavaScript
Cwe 78
Cwe 306
Cwe 352
+2
|
il y a 2 semaines
|
|
CVE-2026-15426
|
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
|
High
|
WordPress
Cwe 269
PHP
Authentication Bypass
|
il y a 2 semaines
|
|
CVE-2026-67620
|
|
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
|
High
|
Server-Side Request Forgery
Cwe 918
|
il y a 3 semaines
|
|
CVE-2026-48026
|
|
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI render...
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write ac...
|
High
|
JavaScript
Cwe 79
Cross-Site Scripting
|
il y a 3 semaines
|
|
CVE-2026-18325
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 3 semaines
|