|
CVE-2026-82475
|
|
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
|
High
|
Cwe 862
Authentication Bypass
|
il y a 14 heures
|
|
CVE-2026-82472
|
|
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
|
High
|
Cwe 306
Remote Code Execution
|
il y a 14 heures
|
|
CVE-2026-82466
|
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
High
|
Authentication Bypass
Cwe 287
Ruby
|
il y a 14 heures
|
|
CVE-2026-81421
|
|
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
|
High
|
Cwe 918
Server-Side Request Forgery
|
il y a 3 jours
|
|
CVE-2026-77652
|
|
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
|
High
|
C
Cwe 122
Buffer Overflow
|
il y a 3 jours
|
|
CVE-2026-68863
|
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
|
High
|
Denial of Service
Cwe 121
Buffer Overflow
Denial Of Service
+2
|
il y a 3 jours
|
|
CVE-2026-68861
|
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
|
High
|
Cwe 78
Os
Command Injection
Dell
+1
|
il y a 3 jours
|
|
CVE-2021-23758
KEV
|
|
Remote Code Execution in AjaxNetProfessional
Remote Code Execution in AjaxNetProfessional
|
High
|
Cwe 502
Remote Code Execution
Insecure Deserialization
C#
+4
|
il y a 4 jours
|
|
CVE-2026-18328
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 4 jours
|
|
CVE-2026-18323
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 4 jours
|
|
CVE-2026-16601
|
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
High
|
JavaScript
WordPress
Remote Code Execution
Cwe 434
+1
|
il y a 4 jours
|
|
CVE-2026-68960
|
|
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
|
High
|
Cwe 121
Buffer Overflow
Windows
|
il y a 5 jours
|
|
CVE-2026-78681
|
|
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
|
High
|
Denial of Service
Cwe 776
Python
|
il y a 5 jours
|
|
CVE-2026-78680
|
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
High
|
Cwe 426
Python
Remote Code Execution
|
il y a 5 jours
|
|
CVE-2026-78675
|
|
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
|
High
|
Cwe 73
Python
Path Traversal
|
il y a 5 jours
|
|
CVE-2026-75574
|
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
High
|
PHP
Cwe 1336
WordPress
Remote Code Execution
|
il y a 5 jours
|
|
CVE-2026-72695
|
|
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
|
High
|
Path Traversal
Cwe 22
|
il y a 5 jours
|
|
CVE-2026-56707
|
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
High
|
Cwe 862
WordPress
PHP
Authentication Bypass
|
il y a 5 jours
|
|
CVE-2026-56702
|
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
High
|
PHP
Cwe 434
Remote Code Execution
|
il y a 5 jours
|
|
CVE-2026-34968
|
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
High
|
PHP
C
Cwe 22
Adminer
+1
|
il y a 5 jours
|
|
CVE-2026-76098
|
|
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens fr...
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can excee...
|
High
|
Python
Denial of Service
Cwe 674
Markdown
|
il y a 5 jours
|
|
CVE-2026-71506
|
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
|
High
|
Cwe 863
Remote Code Execution
Enterprise Saas
|
il y a 5 jours
|
|
CVE-2026-71505
|
|
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
|
High
|
Cwe 639
Dolibarr
Remote Code Execution
Rest Api
+1
|
il y a 5 jours
|
|
CVE-2026-71504
|
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
|
High
|
Cwe 862
Cwe 915
PHP
|
il y a 5 jours
|
|
CVE-2026-40877
|
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
High
|
PHP
Remote Code Execution
Cwe 94
Cwe 502
|
il y a 5 jours
|
|
CVE-2026-30864
|
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in v...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
|
High
|
Cross-Site Scripting
Cwe 79
|
il y a 5 jours
|
|
CVE-2026-78208
|
|
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
|
High
|
JavaScript
Path Traversal
Cwe 73
|
il y a 6 jours
|
|
CVE-2026-78209
|
|
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
|
High
|
Cwe 1236
JavaScript
Remote Code Execution
|
il y a 6 jours
|
|
CVE-2026-78206
|
|
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory...
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory...
|
High
|
Denial of Service
Cwe 409
JavaScript
|
il y a 6 jours
|
|
CVE-2026-78203
|
|
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap...
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap...
|
High
|
Cwe 639
Ghostwriter
Unauthorized Access
Information Disclosure
|
il y a 6 jours
|
|
CVE-2026-78161
|
|
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
|
High
|
C
Cwe 119
Cwe 787
Buffer Overflow
|
il y a 6 jours
|
|
CVE-2026-9769
|
|
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
|
High
|
Denial of Service
Cwe 674
Python
|
il y a 6 jours
|
|
CVE-2026-4671
|
|
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
|
High
|
Cwe 400
Denial Of Service
JavaScript
|
il y a 6 jours
|
|
CVE-2026-30866
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
|
High
|
Cwe 200
Cwe 306
Web Application
Authentication Bypass
|
il y a 1 semaine
|
|
CVE-2026-30819
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.
|
High
|
PHP
Cross-Site Scripting
Cwe 79
|
il y a 1 semaine
|
|
CVE-2026-27490
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue ha...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
|
High
|
Cwe 330
Cwe 331
Web Application
Authentication Bypass
|
il y a 1 semaine
|
|
CVE-2026-27462
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, lead...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.
|
High
|
Cwe 204
Remote Code Execution
|
il y a 1 semaine
|
|
CVE-2026-54682
|
|
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and Format...
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it w...
|
High
|
Cwe 79
Cross-Site Scripting
|
il y a 1 semaine
|
|
CVE-2026-73197
|
|
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
|
High
|
Denial of Service
Cwe 770
Redhat
Enterprise Linux
+1
|
il y a 1 semaine
|
|
CVE-2026-19905
|
|
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
|
High
|
SQL Injection
Cwe 74
Cwe 89
Sql Injection
|
il y a 2 semaines
|
|
CVE-2026-14279
|
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
High
|
WordPress
Privilege Escalation
Cwe 269
PHP
|
il y a 2 semaines
|
|
CVE-2026-73680
|
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
High
|
Cwe 78
Cockpit
PHP
Command Injection
|
il y a 2 semaines
|
|
CVE-2026-19826
|
|
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
|
High
|
Java
Insecure Deserialization
Cwe 20
Cwe 502
|
il y a 2 semaines
|
|
CVE-2026-19825
|
|
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
|
il y a 2 semaines
|
|
CVE-2026-19794
|
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 2 semaines
|
|
CVE-2026-19764
|
|
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
|
High
|
PHP
SQL Injection
Cwe 74
Cwe 89
+2
|
il y a 2 semaines
|
|
CVE-2026-19762
|
|
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
|
High
|
Java
Path Traversal
Cwe 22
|
il y a 2 semaines
|
|
CVE-2026-19758
|
|
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
|
High
|
Java
Path Traversal
Cwe 22
|
il y a 2 semaines
|
|
CVE-2026-19757
|
|
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
|
High
|
Java
Path Traversal
Cwe 22
|
il y a 2 semaines
|
|
CVE-2026-73654
|
|
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
|
High
|
Denial of Service
Cwe 1321
Remote Code Execution
npm
+1
|
il y a 2 semaines
|