|
CVE-2026-82466
|
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
High
|
Authentication Bypass
Cwe 287
Ruby
|
il y a 15 heures
|
|
CVE-2026-77652
|
|
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
|
High
|
C
Cwe 122
Buffer Overflow
|
il y a 3 jours
|
|
CVE-2021-23758
KEV
|
|
Remote Code Execution in AjaxNetProfessional
Remote Code Execution in AjaxNetProfessional
|
High
|
Cwe 502
Remote Code Execution
Insecure Deserialization
C#
+4
|
il y a 4 jours
|
|
CVE-2026-18328
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 5 jours
|
|
CVE-2026-18323
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 5 jours
|
|
CVE-2026-16601
|
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
High
|
JavaScript
WordPress
Remote Code Execution
Cwe 434
+1
|
il y a 5 jours
|
|
CVE-2026-78681
|
|
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
|
High
|
Denial of Service
Cwe 776
Python
|
il y a 5 jours
|
|
CVE-2026-78680
|
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
High
|
Cwe 426
Python
Remote Code Execution
|
il y a 5 jours
|
|
CVE-2026-78675
|
|
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
|
High
|
Cwe 73
Python
Path Traversal
|
il y a 5 jours
|
|
CVE-2026-75574
|
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
High
|
PHP
Cwe 1336
WordPress
Remote Code Execution
|
il y a 5 jours
|
|
CVE-2026-56707
|
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
High
|
Cwe 862
WordPress
PHP
Authentication Bypass
|
il y a 5 jours
|
|
CVE-2026-56702
|
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
High
|
PHP
Cwe 434
Remote Code Execution
|
il y a 5 jours
|
|
CVE-2026-34968
|
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
High
|
PHP
C
Cwe 22
Adminer
+1
|
il y a 5 jours
|
|
CVE-2026-76098
|
|
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens fr...
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can excee...
|
High
|
Python
Denial of Service
Cwe 674
Markdown
|
il y a 5 jours
|
|
CVE-2026-71504
|
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
|
High
|
Cwe 862
Cwe 915
PHP
|
il y a 5 jours
|
|
CVE-2026-40877
|
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
High
|
PHP
Remote Code Execution
Cwe 94
Cwe 502
|
il y a 5 jours
|
|
CVE-2026-78209
|
|
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
|
High
|
Cwe 1236
JavaScript
Remote Code Execution
|
il y a 6 jours
|
|
CVE-2026-78208
|
|
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
|
High
|
JavaScript
Path Traversal
Cwe 73
|
il y a 6 jours
|
|
CVE-2026-78206
|
|
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory...
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory...
|
High
|
Denial of Service
Cwe 409
JavaScript
|
il y a 6 jours
|
|
CVE-2026-78161
|
|
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
|
High
|
C
Cwe 119
Cwe 787
Buffer Overflow
|
il y a 6 jours
|
|
CVE-2026-9769
|
|
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
|
High
|
Denial of Service
Cwe 674
Python
|
il y a 6 jours
|
|
CVE-2026-4671
|
|
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
|
High
|
Cwe 400
Denial Of Service
JavaScript
|
il y a 6 jours
|
|
CVE-2026-30819
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.
|
High
|
PHP
Cross-Site Scripting
Cwe 79
|
il y a 1 semaine
|
|
CVE-2026-14279
|
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
High
|
WordPress
Privilege Escalation
Cwe 269
PHP
|
il y a 2 semaines
|
|
CVE-2026-73680
|
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
High
|
Cwe 78
Cockpit
PHP
Command Injection
|
il y a 2 semaines
|
|
CVE-2026-19826
|
|
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
|
High
|
Java
Insecure Deserialization
Cwe 20
Cwe 502
|
il y a 2 semaines
|
|
CVE-2026-19825
|
|
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
|
il y a 2 semaines
|
|
CVE-2026-19794
|
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 2 semaines
|
|
CVE-2026-19762
|
|
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
|
High
|
Java
Path Traversal
Cwe 22
|
il y a 2 semaines
|
|
CVE-2026-19764
|
|
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
+2
|
il y a 2 semaines
|
|
CVE-2026-19758
|
|
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
|
High
|
Java
Path Traversal
Cwe 22
|
il y a 2 semaines
|
|
CVE-2026-19757
|
|
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
|
High
|
Java
Path Traversal
Cwe 22
|
il y a 2 semaines
|
|
CVE-2026-18146
|
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 2 semaines
|
|
CVE-2026-73031
|
|
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
|
High
|
JavaScript
Vue.js
Cross-Site Scripting
Cwe 79
|
il y a 2 semaines
|
|
CVE-2026-73222
|
|
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
|
High
|
JavaScript
Cwe 78
Cwe 306
Cwe 352
+2
|
il y a 2 semaines
|
|
CVE-2026-15426
|
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
|
High
|
WordPress
Cwe 269
PHP
Authentication Bypass
|
il y a 2 semaines
|
|
CVE-2026-48026
|
|
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI render...
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write ac...
|
High
|
JavaScript
Cwe 79
Cross-Site Scripting
|
il y a 3 semaines
|
|
CVE-2026-18325
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 3 semaines
|
|
CVE-2026-16636
|
|
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 3 semaines
|
|
CVE-2026-15991
|
|
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
|
High
|
PHP
WordPress
Remote Code Execution
Cwe 862
+1
|
il y a 3 semaines
|
|
CVE-2026-71287
|
|
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
|
High
|
PHP
SQL Injection
Cwe 89
Cacti
|
il y a 3 semaines
|
|
CVE-2026-71270
|
|
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
|
High
|
Java
Server-Side Request Forgery
Cwe 918
|
il y a 3 semaines
|
|
CVE-2026-71271
|
|
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
|
High
|
Cwe 918
Remote Code Execution
Go
HTTP
|
il y a 3 semaines
|
|
CVE-2026-71272
|
|
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
|
High
|
Server-Side Request Forgery
Cwe 367
Go
DNS
|
il y a 3 semaines
|
|
CVE-2026-71259
|
|
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
|
High
|
Python
Cwe 184
Remote Code Execution
|
il y a 3 semaines
|
|
CVE-2026-7444
|
|
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
|
High
|
WordPress
Cwe 352
PHP
Cross-Site Request Forgery
|
il y a 3 semaines
|
|
CVE-2026-7520
|
|
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
|
High
|
WordPress
Cwe 862
PHP
Authentication Bypass
|
il y a 3 semaines
|
|
CVE-2026-71215
|
|
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
|
High
|
JavaScript
Cwe 22
Path Traversal
|
il y a 3 semaines
|
|
CVE-2026-71209
|
|
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
|
High
|
JavaScript
Express
Cwe 22
Path Traversal
|
il y a 3 semaines
|
|
CVE-2026-71206
|
|
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
|
High
|
Cwe 613
Go
Authentication Bypass
|
il y a 3 semaines
|