|
CVE-2026-72777
|
|
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
|
High
|
Cwe 918
Server-Side Request Forgery
|
il y a 2 semaines
|
|
CVE-2026-18146
|
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 2 semaines
|
|
CVE-2026-73031
|
|
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
|
High
|
JavaScript
Vue.js
Cross-Site Scripting
Cwe 79
|
il y a 2 semaines
|
|
CVE-2026-73222
|
|
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
|
High
|
JavaScript
Cwe 78
Cwe 306
Cwe 352
+2
|
il y a 2 semaines
|
|
CVE-2026-15426
|
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
|
High
|
WordPress
Cwe 269
PHP
Authentication Bypass
|
il y a 2 semaines
|
|
CVE-2026-67620
|
|
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
|
High
|
Server-Side Request Forgery
Cwe 918
|
il y a 3 semaines
|
|
CVE-2026-48026
|
|
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI render...
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write ac...
|
High
|
JavaScript
Cwe 79
Cross-Site Scripting
|
il y a 3 semaines
|
|
CVE-2026-18325
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 3 semaines
|
|
CVE-2026-16636
|
|
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
il y a 3 semaines
|
|
CVE-2026-15991
|
|
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
|
High
|
PHP
WordPress
Remote Code Execution
Cwe 862
+1
|
il y a 3 semaines
|
|
CVE-2026-67623
|
|
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
|
High
|
Remote Code Execution
Cwe 829
Git
|
il y a 3 semaines
|
|
CVE-2026-71288
|
|
Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
|
High
|
SQL Injection
Cwe 89
Remote Code Execution
Sql
+1
|
il y a 3 semaines
|
|
CVE-2026-71287
|
|
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
|
High
|
PHP
SQL Injection
Cwe 89
Cacti
|
il y a 3 semaines
|
|
CVE-2026-71280
|
|
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
|
High
|
Cwe 918
Server-Side Request Forgery
Golang
|
il y a 3 semaines
|
|
CVE-2026-71272
|
|
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
|
High
|
Server-Side Request Forgery
Cwe 367
Go
DNS
|
il y a 3 semaines
|
|
CVE-2026-71271
|
|
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
|
High
|
Cwe 918
Remote Code Execution
Go
HTTP
|
il y a 3 semaines
|
|
CVE-2026-71270
|
|
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
|
High
|
Java
Server-Side Request Forgery
Cwe 918
|
il y a 3 semaines
|
|
CVE-2026-71259
|
|
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
|
High
|
Python
Cwe 184
Remote Code Execution
|
il y a 3 semaines
|
|
CVE-2026-7520
|
|
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
|
High
|
WordPress
Cwe 862
PHP
Authentication Bypass
|
il y a 3 semaines
|
|
CVE-2026-7444
|
|
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
|
High
|
WordPress
Cwe 352
PHP
Cross-Site Request Forgery
|
il y a 3 semaines
|
|
CVE-2026-71215
|
|
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
|
High
|
JavaScript
Cwe 22
Path Traversal
|
il y a 3 semaines
|
|
CVE-2026-71209
|
|
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
|
High
|
JavaScript
Express
Cwe 22
Path Traversal
|
il y a 3 semaines
|
|
CVE-2026-71206
|
|
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
|
High
|
Cwe 613
Go
Authentication Bypass
|
il y a 3 semaines
|
|
CVE-2026-6627
|
|
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
|
High
|
PHP
WordPress
Cwe 862
Authentication Bypass
|
il y a 3 semaines
|
|
CVE-2026-6147
|
|
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
|
High
|
WordPress
Remote Code Execution
Cwe 434
PHP
|
il y a 3 semaines
|
|
CVE-2026-55739
|
|
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce...
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce...
|
High
|
Cwe 639
Remote Code Execution
|
il y a 3 semaines
|
|
CVE-2026-54418
|
|
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
|
High
|
Cwe 862
Remote Code Execution
|
il y a 3 semaines
|
|
CVE-2026-18859
|
|
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of...
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of...
|
High
|
SQL Injection
Cwe 74
Cwe 89
Sql Injection
+1
|
il y a 3 semaines
|
|
CVE-2026-17347
|
|
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an...
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an...
|
High
|
Cwe 78
Cwe 88
Pgadmin4
Remote Code Execution
+2
|
il y a 4 semaines
|
|
CVE-2026-17346
|
|
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON /...
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON /...
|
High
|
Cwe 89
PostgreSQL
Sql Injection
Pgadmin
+1
|
il y a 4 semaines
|
|
CVE-2026-44098
|
|
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
|
High
|
Cwe 78
Command Injection
Firewall Bypass
|
il y a 4 semaines
|
|
CVE-2026-44097
|
|
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
|
High
|
Cwe 434
Remote Code Execution
Denial of Service
|
il y a 4 semaines
|
|
CVE-2026-6267
|
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5,...
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5,...
|
High
|
Cwe 201
Gitlab
Authentication Bypass
Access Control
|
il y a 1 mois
|
|
CVE-2026-5490
|
|
DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote...
DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote...
|
High
|
SQL Injection
Privilege Escalation
Cwe 89
Sql Injection
|
il y a 1 mois
|
|
CVE-2026-67428
|
|
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
|
High
|
C
Server-Side Request Forgery
Cwe 918
Python
+1
|
il y a 1 mois
|
|
CVE-2026-67424
|
|
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
|
High
|
Cwe 918
Remote File Inclusion
Python
|
il y a 1 mois
|
|
CVE-2026-67201
|
|
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass...
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass...
|
High
|
Server-Side Request Forgery
Cwe 436
|
il y a 1 mois
|
|
CVE-2026-66473
|
|
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
|
High
|
Cwe 862
WordPress
PHP
Authentication Bypass
|
il y a 1 mois
|
|
CVE-2026-65447
|
|
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-65446
|
|
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-65443
|
|
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-65442
|
|
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
|
High
|
Server-Side Request Forgery
Cwe 918
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-65441
|
|
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
|
il y a 1 mois
|
|
CVE-2026-65437
|
|
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <=...
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <=...
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-61957
|
|
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-61953
|
|
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
|
High
|
Server-Side Request Forgery
Cwe 918
WordPress
PHP
|
il y a 1 mois
|
|
CVE-2026-66040
|
|
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
|
High
|
Cwe 122
Ffmpeg
Remote Code Execution
|
il y a 1 mois
|
|
CVE-2026-15074
|
|
@fastify/static vulnerable to route guard bypass via path traversal
@fastify/static vulnerable to route guard bypass via path traversal
|
High
|
Cwe 22
Fastify
Nodejs
Path Traversal
+1
|
il y a 1 mois
|
|
CVE-2026-9323
|
|
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
|
High
|
Python
Cwe 338
Remote Code Execution
|
il y a 1 mois
|
|
CVE-2026-11826
|
|
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
|
High
|
C++
Denial of Service
Cwe 122
Buffer Overflow
+4
|
il y a 1 mois
|