Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability
Priority - CWE-287: Improper Authentication
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
LiquidJS is Vulnerable to Remote Code Execution
WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Link Factory - Backdoor
Unauthenticated Command Injection
Unauthenticated RCE
ERPNext: Possibility of server-side template injection due to missing validation
Dokploy: Remote Code Execution via volume-backup
Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers
Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`
Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts)
Dokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCE
Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke serviceaccounts bound to wildcard rbac (*/*/*)
Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE
Cross-project instance move bypasses all project restrictions allowing host command execution
LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
Project restriction bypass via instance migration config override
Root RCE via image backup.yaml symlink
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
IBM i is Affected By Remote Code Execution Vulnerability []
Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of CVE-2026-44966 fix)
Apache Allura: Git command injection
WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability
WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability
WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability
WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalation vulnerability
idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
ipv6: ioam: refresh hdr pointer before ioam6_event()
net: bcmgenet: keep RBUF EEE/PM disabled
net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover
WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability
vCenter directory-traversal vulnerability
WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434)
UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd
YesWiki: Unauthenticated SQL Injection
WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability
WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulnerability
WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability
WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication vulnerability
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
CVE-2026-18749
IBM i is Affected By Remote Code Execution Vulnerability in Line Printer Daemon []
IBM i is Affected By Multiple Vulnerabilities in the Debug Server
IBM Db2 Mirror for i is vulnerable to OS command injection []
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options
Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations.
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.
OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user without an ACI proxy grant
Dokploy: Command Injection via dockerImage in buildRemoteDocker
Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes another tenant's S3 credentials and backups
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redirecting traffic to attacker-controlled IPs) and DNS denial of service (NODATA responses). Exploitation requires a multi-pool deployment with AttributeFilter enabled in scheduler_filters, which is a non-default but documented and supported configuration for self-service tiering.
UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd
TypeBot vulnerable to CSV injection in result export
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names
Command Injection via Malicious OCPP Server
Vitest: Browser Mode provider commands bypass the file-access permission gate
Flowise before 3.1.3 Sandbox Escape via Puppeteer
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse
Authenticated Heap Overflow
SurrealDB before 2.2.2 SurrealQL Injection via export
Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build
Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build
WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
PeerTube: Cross-origin remote video takeover via Update activity
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header
Microsoft Office SharePoint Spoofing Vulnerability
CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal
WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability
WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability
WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability
WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injection vulnerability
WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Injection vulnerability
WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability
WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability
Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
Priority – CWE-306: Missing Authentication for Critical Function
Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID
Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability
WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability
Path Traversal in IBM Desktop App
Unauthenticated Buffer Overflow in PROFINET Service
Fooocus webui vulnerable to Remote Code Execution
SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget
rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0
rsync < 3.5.0 Command Injection via Multiple Code Paths
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
Priority – CWE-602: Client-Side Enforcement of Server-Side Security
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Microsoft SharePoint Server Security Feature Bypass Vulnerability
rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode
rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header
Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
gRPC-Go has an authorization bypass via missing leading slash in :path
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
Flowise before 3.1.3 Sandbox Escape to RCE
Flowise before 3.1.3 Remote Code Execution via Custom MCP
Flowise before 3.1.3 Prompt Injection RCE via CSV Agent
Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV
Flowise before 3.1.3 Remote Code Execution via Airtable Agent
Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image
SurrealDB before 1.1.1 Format String via Scripting Functions
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Electerm check folder size function may get attacked by unsafe folder name
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry
rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling
rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft SharePoint Elevation of Privilege Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Potential cache poisoning in JFrog Artifactory
Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Elevation of Privilege Vulnerability
fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
net: devmem: reject dma-buf bind with non-page-aligned size or SG length
Azure Entra ID Spoofing Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
Windows GDI+ Remote Code Execution Vulnerability
Windows SMBv3 Server Remote Code Execution Vulnerability
Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability
Windows SMBv3 Server Remote Code Execution Vulnerability
Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability
Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability
@cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation
Windows Active Directory Domain Services Remote Code Execution Vulnerability
Quarkus authorization bypass via semicolon path normalization inconsistency
Missing Authorization inAlanWeb SCADA
WordPress Booking Activities plugin <= 1.18.4 - PHP Object Injection vulnerability
WordPress Service Finder Booking plugin <= 6.2 - Privilege Escalation vulnerability
Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
PostgreSQL pg_dump heap buffer overflow executes arbitrary code
SMP security request
Bluetooth re-pairing with legitimate device can use lower security level
Bluetooth re-pairing can use a lower security level than previous
MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters
Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Driver
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
IBM i is Affected By A Privilege Escalation Vulnerability []
PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client
IBM i is Affected By Remote Code Execution Vulnerabilities [, ]
IBM i is Affected By Remote Code Execution Vulnerabilities [, ]
IBM i is Affected By Multiple Vulnerabilities in SQL
IBM i is Affected By Multiple Vulnerabilities in the Debug Server
IBM i is Affected By Multiple Vulnerabilities in Domain Name System
IBM i is Affected By Multiple Vulnerabilities in Domain Name System
PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code
PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code
forced re-pairing with already bonded device
PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound
PostgreSQL expression deparse allows SQL injection via EXTRACT argument
PostgreSQL type confusion via "internal" arguments
PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound
PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code
PostgreSQL refint plan cache type confusion executes arbitrary code
PostgreSQL plperl tied object heap buffer overflow executes arbitrary code
PostgreSQL to_char heap buffer overflow executes arbitrary code
PostgreSQL regexp heap buffer overflow executes arbitrary code
PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound
IBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code Execution
IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
Authentication Bypass
SQL Injection
Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
scsi: qla2xxx: Implement ref count for SRB
GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling
GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()
Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter
Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch
Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
PostGIS address_standardizer Out-of-Bounds Write via standardize_address()
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
Shescape: Quadratic-time denial of service in flag-protection
rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall
rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion
rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()
Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. While the vulnerability is in Oracle Service Fulfillment Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Fulfillment Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).
Zalktis: SQL injection via partner-controlled fields in imported e-invoices
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
Netty has Insufficient Bailiwick Validation for NS Records
Pathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLs
iskorotkov/avro: CPU Exhaustion in Avro Decoder
iskorotkov/avro: Integer Overflow in Avro Decoder
Meeting Room Booking System has server-side request forgery in import functionality
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
SpdyStream: DOS on CRI
SQL Injection in AlanWeb SCADA
Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable
cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding
ColdFusion | Improper Input Validation (CWE-20)
SQL Query Validation Bypass in OpenSearch Direct Query
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
FileRun 2026.2.0 RCE via Thumbnail Generation Command Injection
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree
SurrealDB before 1.1.0 Denial of Service via HTTP Headers
ASP-CMS SQL Injection via commentList.asp id Parameter
CMS Admin SQL Injection via db_data.php table_name Parameter
File Browser before v2.63.22 Authorization Bypass via Recursive Operations
Flowise before 3.1.3 Sandbox Escape via Pandas Methods
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
Rainbond 6.9.7 Region API Cross-Enterprise IDOR via Tenant Access
rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
Priority - CWE-284: Improper Access Control
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync
Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Lightroom Classic | Deserialization of Untrusted Data (CWE-502)
Next.js: Server-side request forgery in applications using WebSocket upgrades
Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking
Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin
Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin
Open Recovery Mode
Access to Bootloader
Potential code smuggling via doc comments in cmd/cgo
Vim: Heap Buffer Overflow when Loading a Spell File
Acm-search-v2-rhel9: search-v2-operator: addonfactory.getvaluesfromaddonannotation enables arbitrary helm-values override per spoke
WordPress Reviewer plugin <= 3.14.2 - SQL Injection vulnerability
WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - SQL Injection vulnerability
During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
rsync < 3.5.0 Symlink Following Arbitrary File Overwrite
WordPress Form Maker by 10Web plugin <= 1.15.44 - SQL Injection vulnerability
WordPress CubeWP plugin <= 1.1.30 - SQL Injection vulnerability
WordPress Do Lasso plugin <= 358 - SQL Injection vulnerability
WordPress Booktics plugin 1.0.22 - SQL Injection vulnerability
Authorization Bypass Through User-Controlled Key in GitLab
IBM i is Affected By Multiple Vulnerabilities in SQL
Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster
Arbitrary file read+write on host via templates/ symlink in malicious image
Incorrect Authorization in GitLab
Serendipity before 2.6.0 SSRF via hex IPv4 and IPv6 addresses
amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.
KVM: x86: hyper-v: Bound the bank index when querying sparse banks
qed: fix double free in qed_cxt_tables_alloc()
rsync < 3.5.0 Arbitrary File Read via Symlink Following
rsync < 3.5.0 Path Traversal via Symlink Module Root
ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)
MongoDB BI Connector ODBC driver may write outside an allocated buffer when the setup dialog opens a data source with oversized path settings
IBM® Db2® is vulnerable to buffer overflow in the IXF IMPORT parser
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high privilege.
FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`)
rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()
Windows Network Address Translation (NAT) Spoofing Vulnerability
Zoom Clients - Use After Free
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
SVGO: removeScripts plugin leaves some executable scripts intact
AutoGPT: Webhook provider path confusion bypasses generic webhook secret verification
Velociraptor collect_client() Permissions Bypass
KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
Priority – CWE-284: Improper Access Control
rsync < 3.5.0 Symlink Race Condition Directory Traversal
ishankportfolio: Stored Contact Form Submission Exposure via Public Client-Side Database Configuration
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
Apache Thrift: Swift Range crash in skip()
Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
ColdFusion | Improper Input Validation (CWE-20)
WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation
IBM i is Affected By Multiple Vulnerabilities in Host Servers
PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory
tarfile opened in streaming mode mishandles EOF
IBM® Db2® is vulnerable to privilege escalation with a specially crafted query
bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
Rhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kubernetes client certificate renewal validation
electerm's RDP clipboard file download may parse unsafe file name
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here>
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.
Potential package cache integrity issue in JFrog Artifactory
WordPress Biagiotti Core plugin <= 2.1.1 - Local File Inclusion vulnerability
WordPress Foton Core plugin <= 1.1.1 - Local File Inclusion vulnerability
WordPress Barista theme <= 2.5.1 - Local File Inclusion vulnerability
WordPress Geo Mashup plugin <= 1.13.18 - Local File Inclusion vulnerability
wifi: iwlwifi: mvm: fix driver-set TX rates on old devices
Microsoft SharePoint Server Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
RPC Runtime Library Remote Code Execution Vulnerability
WordPress SAML SP Single Sign On plugin <= 5.4.3 - Privilege Escalation vulnerability
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
ColdFusion | Heap-based Buffer Overflow (CWE-122)
Next.js: Middleware / Proxy bypass through dynamic route parameter injection
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
WordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerability
WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision
IBM WebSphere Application Server Liberty is affected by a privilege escalation
IBM i is Affected By Multiple Vulnerabilities in Host Servers
IBM i is Affected By improper privilege management in Navigator for i
Openjdk-orb: unauthed class loading via iiop in eap
PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands
WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI
Microsoft Exchange Server Elevation of Privilege Vulnerability
React Router vulnerable to XSS via Open Redirects
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later
Oh My Posh: Arbitrary command execution via template injection in the path segment
FreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute in PropertyFileIncluded::Restore()
Faker: helpers.fake exploitable into arbritary code execution
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
i2c: core: fix adapter deregistration race
Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
Input: goodix - clamp the device-reported contact count
Input: iforce - bound the device-reported force-feedback effect index
Input: mms114 - fix touch indexing for MMS134S and MMS136
Input: touchwin - reset the packet index on every complete packet
Input: mms114 - reject an oversized device packet size
fpga: region: fix use-after-free in child_regions_with_firmware()
power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
usb: gadget: net2280: Fix double free in probe error path
mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()
sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
smb: client: require net admin for CIFS SWN netlink
ALSA: pcm: Don't setup bogus iov_iter for silencing
ALSA: asihpi: Fix potential OOB array access at reading cache
net: hsr: defer node table free until after RCU readers
Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Word Remote Code Execution Vulnerability
Microsoft Office Word Remote Code Execution Vulnerability
Microsoft Office Graphics Component Remote Code Execution Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Windows NTFS Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
Windows HTTP.sys Elevation of Privilege Vulnerability
Windows SMB Client Elevation of Privilege Vulnerability
Windows NTFS Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Schannel Elevation of Privilege Vulnerability
Windows License Manager Elevation of Privilege Vulnerability
Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Shell Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows DHCP Client Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Windows Device Association Service Elevation of Privilege Vulnerability
Windows HTTP.sys Elevation of Privilege Vulnerability
Windows HTTP.sys Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows DHCP Client Elevation of Privilege Vulnerability
Windows HTTP.sys Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Windows Bind Filter Driver Elevation of Privilege Vulnerability
Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability
Windows Message Queuing Elevation of Privilege Vulnerability
Windows Message Queuing Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Windows Device Association Service Elevation of Privilege Vulnerability
Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
Windows Telephony Service Elevation of Privilege Vulnerability
Windows NTFS Elevation of Privilege Vulnerability
Microsoft Digest Authentication Elevation of Privilege Vulnerability
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
Windows Storage Elevation of Privilege Vulnerability
Windows Remote Desktop Services Elevation of Privilege Vulnerability
Windows MIDI Service Module Elevation of Privileges Vulnerability
Windows HTTP.sys Elevation of Privilege Vulnerability
Windows Bind Filter Driver Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows USB Driver Elevation of Privilege Vulnerability
Windows Display Enhancement Service Elevation of Privilege Vulnerability
Windows Remote Desktop Services Elevation of Privilege Vulnerability
Windows Remote Desktop Services Elevation of Privilege Vulnerability
Windows Remote Desktop Services Elevation of Privilege Vulnerability
Windows Storage Elevation of Privilege Vulnerability
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability
Application Information Services Elevation of Privilege Vulnerability
Windows Remote Desktop Services Elevation of Privilege Vulnerability
Windows Sensor Data Service Elevation of Privilege Vulnerability
Windows Telephony Service Elevation of Privilege Vulnerability
Windows Work Folder Service Elevation of Privilege Vulnerability
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump directories
accel/ivpu: Fix signed integer truncation in IPC receive
Lightroom Classic | Out-of-bounds Write (CWE-787)
Lightroom Classic | Out-of-bounds Write (CWE-787)
Lightroom Classic | Out-of-bounds Write (CWE-787)
Lightroom Classic | Out-of-bounds Write (CWE-787)
Lightroom Classic | Out-of-bounds Write (CWE-787)
Lightroom Classic | Out-of-bounds Write (CWE-787)
Lightroom Classic | Out-of-bounds Write (CWE-787)
Lightroom Classic | Integer Overflow or Wraparound (CWE-190)
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
ColdFusion | Incorrect Authorization (CWE-863)
IBM i is Affected By An Improper Management Vulnerability in HTTP Server []
Incorrect Permission Assignment in Autodesk Installer Named Pipes
tarfile extraction filter bypass allows escaping the destination directory
Linux-pam: linux-pam directory traversal
block, bfq: don't move oom_bfqq
bfq: fix use-after-free in bfq_dispatch_request
f2fs: fix to do sanity check on curseg->alloc_type
mt76: mt7921: fix crash when startup fails.
dm integrity: fix memory corruption when tag_size is less than digest size
drm/amd/display: fix array index out of bound error in DCN32 DML
peci: cpu: Fix use-after-free in adev_release()
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
GitPython before 3.1.54 Remote Code Execution via --template
MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_attachment
Cursor: Sandbox escape via launching privileged containers
Next AI Draw.io 0.4.16 SSRF via DNS Rebinding in parse-url
Multicloud-operators-subscription: multicloud-operators-subscription: fetchchannelreferences honours channel.spec.secretref.namespace enabling cross-namespace secret exfiltration
WordPress Directories Pro plugin <= 2.0.5 - Privilege Escalation vulnerability
WordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerability
Lightroom Classic | Incorrect Authorization (CWE-863)
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
IBM i is Affected By Out-of-Bounds Read Vulnerability []
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read
WatchGuard Firebox admd Out of Bounds Write Vulnerability
File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
WordPress MailChimp For WooCommerce plugin < 6.2 - SQL Injection vulnerability
Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading
rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode
Bypassing passkey entry in legacy pairing
Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode
Adobe Commerce | Incorrect Authorization (CWE-863)
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
IBM i is Affected By Multiple Vulnerabilities in the Debug Server
js-yaml: Exponential parsing time in the flow collections leads to denial of service
py-libp2p: yamux connection DoS via oversized data frame
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
http4s-blaze-server: Unbounded WebSocket message aggregation
NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials
WordPress KiviCare plugin <= 4.5.1 - Sensitive Data Exposure vulnerability
Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.
Filter expression injection via forged keyset pagination cursor in Ash
WordPress Arvow AI SEO Writer plugin <= 1.5.3 - Broken Access Control vulnerability
WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin <= 2.1.1 - Broken Access Control vulnerability
WordPress iCARRY plugin <= 2.9 - Sensitive Data Exposure vulnerability
WordPress WooCommerce Appointments plugin <= 5.3.8 - Sensitive Data Exposure vulnerability
WordPress SMEPay: UPI Gateway for WooCommerce plugin <= 1.0.5 - Payment Bypass vulnerability
WordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerability
WordPress MultiVendorX plugin <= 5.0.10 - Broken Access Control vulnerability
WordPress WPJAM Basic plugin <= 7.0.2.1 - Sensitive Data Exposure vulnerability
WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugin <= 1.0.7 - Broken Access Control vulnerability
ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65.
svcrdma: wake sq waiters when the transport closes
wifi: iwlwifi: mld: stop TX during firmware restart
HAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of service
WordPress WPMobile.App plugin <= 11.77 - Broken Access Control vulnerability
WordPress OMGF Pro plugin <= 5.2.7 - Arbitrary File Download vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
Gstreamer: gstreamer: dtls certificate subject dn stack buffer overflow in openssl_verify_callback
Remote Desktop Client Remote Code Execution Vulnerability
Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
python-socketio: Binary attachment accumulation can cause denial of service
python-engineio has unbound thread allocation that can cause denial of service
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic
Adobe Commerce | Incorrect Authorization (CWE-863)
ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)
FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
Next.js: Denial of Service via connection exhaustion in applications using Cache Components
Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Next.js: Middleware / Proxy bypass in Pages Router applications using i18n
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
Axios: Allocation of Resources Without Limits or Throttling in axios
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
Quadratic string concatenation in consumePhrase in net/mail
Prometheus: remote read endpoint allows denial of service via crafted snappy payload
Prometheus Azure AD remote write OAuth client secret exposed via config API
Anonymous user token generation exposure in JFrog Artifactory
Micrometer HTTP server instrumentations DoS vulnerability
Micrometer gRPC server instrumentation DoS vulnerability
Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
Quadratic string concatentation in consumeComment in net/mail
Go JOSE affect by a panic in JWE decryption
Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
Crash when handling long CNAME response in net
Denial of service in github.com/jackc/pgproto3/v2
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
Unexpected work during chain building in crypto/x509
WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability
WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability
WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.3 - Broken Access Control vulnerability
Incorrect enforcement of email constraints in crypto/x509
Incorrect parsing of IPv6 host literals in net/url
Axios affected by Denial of Service via __proto__ Key in mergeConfig
Tempo query limit results in unbounded memory allocation
Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of service
CVE-2026-17613
IBM i is Affected By Multiple Vulnerabilities in the Debug Server
Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard
IBM i is Affected By A Denial of Service Vulnerability []
Jboss-remoting: jboss-remoting: integer overflow in messagereader leads to pre-authentication denial of service
Unbounded Memory Growth in QUIC Server Incoming Channel Queue
fast-uri vulnerable to host confusion via failed IDN canonicalization
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
Memory exhaustion in query parameter parsing in net/url
In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.
WordPress DeBounce Email Validator plugin <= 5.7 - Local File Inclusion Vulnerability
Smallrye-fault-tolerance: smallrye fault tolerance
Rsync: info leak via uninitialized stack contents
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
WordPress Participants Database plugin <= 2.7.8.4 - Arbitrary File Deletion vulnerability
Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dos
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Bluetooth: MGMT: validate Add Extended Advertising Data length
Microsoft Exchange Server Spoofing Vulnerability
A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.
Netty: HttpClientCodec response desynchronization
Apache Thrift: Swift Compact Protocol integer overflow
OpenTelemetry-Go has an incomplete fix for CVE-2026-24051: BSD kenv command not using absolute path enables PATH hijacking
WordPress Hydra Booking plugin <= 1.2.2 - Broken Access Control vulnerability
During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.
Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image
Code execution in IBM Desktop App
A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.
GitPython before 3.1.54 Arbitrary File Overwrite via diff
GitPython before 3.1.57 Arbitrary File Overwrite and Read
filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink
PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer
phpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php
Project Resource Managers may escalate privileges in JFrog Artifactory
WordPress Gutenverse Companion plugin <= 2.5.1 - Server Side Request Forgery (SSRF) vulnerability
Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
rsync < 3.5.0 Symlink Race Condition via ACL/xattr Application
rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest
Azure Monitor Agent Elevation of Privilege Vulnerability
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
WordPress Car Rental Manager plugin <= 1.3.9 - PHP Object Injection vulnerability
Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
PostgreSQL logical decoding can dlopen arbitrary file
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
GitPython before 3.1.57 Arbitrary File Read via Repo.archive()
Budibase before 3.40.0 NoSQL Injection via MongoDB datasource
OpenRemote Notification Delete Cross-Realm Insecure Direct Object Reference
Flowise before 3.1.3 Credential Exposure via API
Seerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETag
Clusterclaims-controller: clusterclaims-controller: tenant-controlled clusterclaim labels propagated to managedcluster enabling cross-tenant managedclusterset join
The coturn server can end in a state where it does not accept more requests with "even-port" enabled.
Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset
rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT
NetBox 4.5.8 ORM Injection via WritableNestedSerializer
WordPress Smart Online Order for Clover plugin <= 1.6.1 - Cross Site Scripting (XSS) vulnerability
WordPress SureDash plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability
WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.10.0 - Cross Site Scripting (XSS) vulnerability
WordPress MultiParcels Shipping For WooCommerce plugin <= 1.30.36 - Reflected Cross Site Scripting (XSS) vulnerability
WordPress Local Delivery Drivers for WooCommerce plugin <= 3.0.0 - Cross Site Scripting (XSS) vulnerability
WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerability
WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - Cross Site Scripting (XSS) vulnerability
WordPress WP-Stats plugin <= 2.56 - Cross Site Scripting (XSS) vulnerability
Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers
BT122 plaintext pause encryption request causes DOS
WordPress Agrion theme <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits
KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)
net: ifb: report ethtool stats over num_tx_queues
WordPress Mang Board WP plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability
WordPress GeekyBot plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability
WordPress WP Full Stripe Free plugin <= 8.5.0 - Cross Site Scripting (XSS) vulnerability
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Installed Base accessible data as well as unauthorized update, insert or delete access to some of Oracle Installed Base accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Gstreamer: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebuffer
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block
rsync < 3.5.0 Arbitrary File Deletion via Malicious File List
TypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and modify arbitrary typebots
OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
WordPress Knowledge Base for Documentation, FAQs with AI Assistance plugin <= 17.211.0 - Cross Site Scripting (XSS) vulnerability
WordPress Visitors Traffic Real Time Statistics plugin <= 8.11 - Cross Site Scripting (XSS) vulnerability
WordPress WP Event SOlution plugin <= 4.1.19 - Arbitrary Content Deletion vulnerability
WordPress Blog Floating Button plugin <= 1.4.20 - Cross Site Scripting (XSS) vulnerability
WordPress Do Lasso plugin <= 358 - Cross Site Scripting (XSS) vulnerability
WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) vulnerability
WordPress Business Directory plugin <= 6.4.25 - Cross Site Scripting (XSS) vulnerability
WordPress Maspik – Spam blacklist plugin <= 2.9.1 - Cross Site Scripting (XSS) vulnerability
WordPress Welcart e-Commerce plugin <= 2.11.31 - Cross Site Scripting (XSS) vulnerability
WordPress MailChimp Subscribe Forms plugin <= 4.3.3 - Cross Site Scripting (XSS) vulnerability
WordPress Solace Extra plugin <= 1.6.0 - Broken Access Control vulnerability
MongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as character data
IBM i is Affected By Multiple Vulnerabilities in the Debug Server
Missing Authorization in GitLab
Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications
SurrealDB before 2.2.2 CPU Exhaustion via nested FOR loops
SurrealDB before 2.2.2 Denial of Service via /sql endpoint
SurrealDB before 1.1.1 Denial of Service via Global Parameters
SurrealDB before 2.0.4 Improper Authorization via SELECT Permissions
Windows Autopilot Elevation of Privilege Vulnerability
Windows Autopilot Elevation of Privilege Vulnerability
Windows Autopilot Elevation of Privilege Vulnerability
Windows Autopilot Elevation of Privilege Vulnerability
Windows Autopilot Elevation of Privilege Vulnerability
Windows Autopilot Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
KVM: guest_memfd: Treat memslot binding offset+size as unsigned values
During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Graphics Kernel Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
Windows HTTP.sys Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Bind Filter Driver Elevation of Privilege Vulnerability
Windows MIDI Service Module Elevation of Privileges Vulnerability
Windows Push Notifications Elevation of Privilege Vulnerability
Winlogon Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Bind Filter Driver Elevation of Privilege Vulnerability
Windows Network Connection Broker Elevation of Privilege Vulnerability
Windows DHCP Client Remote Code Execution Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
Abrt: chownproblemdir succeeds during active post-create event processing due to inadequate locking
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
webbrowser.open() allows leading dashes in URLs
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.
SiYuan before v3.7.4 Information Disclosure via Local Storage
SiYuan before v3.7.4 Information Disclosure via getBookmarkLabels
SiYuan before v3.7.4 Information Disclosure via getOutlineStorage
SiYuan before v3.7.4 Information Disclosure via getRefIDs
SiYuan before v3.7.4 Path Traversal via getUniqueFilename
Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet
rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry
CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport
During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure Access server is still able to accept connections and is still able to issue a failover to connected clients. https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping
rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error
rsync < 3.5.0 Newline Injection via name-converter uid/gid mapping
rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive
rsync < 3.5.0 Path Traversal Write Escape via --relative Mode
Meeting Room Booking System has an unauthenticated open redirect
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets
Local privilege escalation via improper input sanitization in execl() call
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
Insertion of Sesitive Information into Log File in AlanWeb SCADA
Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions
NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.
WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.
Windows Graphics Kernel Denial of Service Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability
Insufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLI
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
Sensitive Data Exposure in Atlas Software's k12net
net: usb: aqc111: Fix out-of-bounds accesses in RX fixup
Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter
Windows DNS Elevation of Privilege Vulnerability
OpenZeppelin Confidential Contracts ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds.
Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr
Potential insecure deserialization in JFrog Artifactory
baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.
Out-of-bounds Write in Wireshark
Submariner-operator: rbac permissions can allow for the spread of node compromises
Mongoose: Prototype pollution in the update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
vLLM: Completion prompt lists fan out into unbounded engine requests
WordPress GiveWP plugin < 4.16.6 - Cross Site Scripting (XSS) vulnerability
WordPress Featured Image from URL plugin <= 5.3.3 - Cross Site Scripting (XSS) vulnerability
RustFS: Version-specific object reads authorize the non-version action
Apache Allura: Missing permission checks IDOR
ERPNext: Broken Access Control on certain endpoint
Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints
Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext
WordPress Motors plugin <= 1.4.113 - Broken Access Control vulnerability
WordPress WpBookingly plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability
WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.5.1 - Broken Access Control vulnerability
WordPress Accordion plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability
WordPress FluentCommunity plugin <= 2.7.5 - Cross Site Scripting (XSS) vulnerability
WordPress Internal Link Optimiser plugin <= 5.2.7 - Broken Access Control vulnerability
WordPress AfterShip Tracking plugin <= 1.18.1 - Cross Site Scripting (XSS) vulnerability
WordPress AI for SEO plugin <= 2.4.2 - Broken Access Control vulnerability
WordPress Profile Extra Fields by BestWebSoft plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability
WordPress WP Social Avatar plugin <= 1.5 - Broken Access Control vulnerability
WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposure vulnerability
Windows SMB Client Information Disclosure Vulnerability
Windows DHCP Client Denial of Service Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)
Microsoft Exchange Server Denial of Service Vulnerability
.NET Information Disclosure Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
Windows SMB Client Information Disclosure Vulnerability
Windows HTTP Protocol Stack Tampering Vulnerability
WordPress Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin <= 1.0.32 - Broken Access Control vulnerability
Windows Remote Desktop Client Information Disclosure Vulnerability
Windows Remote Desktop Client Information Disclosure Vulnerability
Windows Remote Desktop Client Information Disclosure Vulnerability
Microsoft Remote Registry Service Denial of Service Vulnerability
Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Draft List - Contributor Stored Cross-Site Scripting via Draft Title in Custom Drafts Template Attributes
Adobe Commerce | Incorrect Authorization (CWE-863)
ColdFusion | Incorrect Authorization (CWE-863)
Admidio: Any logged-in user can delete inventory fields via `mode=field_delete` — incomplete fix of #2024
Ghostfolio has a Stripe subscription bypass
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
Apache Thrift: C++ JSON OOB read
Microsoft Dynamics Business Central Information Disclosure Vulnerability
WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Cross Site Scripting (XSS) vulnerability
WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability
WordPress WP Event SOlution plugin <= 4.1.18 - Sensitive Data Exposure vulnerability
WordPress Service Finder Booking plugin <= 6.2 - Broken Access Control vulnerability
WordPress Do Lasso plugin <= 358 - Insecure Direct Object References (IDOR) vulnerability
WordPress Tourfic plugin <= 2.23.1 - Broken Access Control vulnerability
WordPress Popup by Supsystic plugin <= 1.11.2 - Cross Site Scripting (XSS) vulnerability
Inefficient candidate hostname parsing in crypto/x509
CVE-2026-18744
Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing
Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing
Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing
IBM i is Affected By Multiple Vulnerabilities in SQL
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext
Denial of service via resource exhaustion in Mattermost
Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero data length
Golang-fips: golang fips zeroed buffer
Windows Kernel Elevation of Privilege Vulnerability
PPWP – Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Flowise before 3.1.4 Credential Abuse via Text-to-Speech
Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack
Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
Shescape: Path disclosure on Unix with Zsh
Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0
WordPress Anti Spam and list cleaner – AcyChecker plugin <= 2.0.0 - Broken Access Control vulnerability
NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Resource and Creation of Temporary File in Directory with Insecure Permissions
Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
Insufficient OIDC endpoint validation could invoke unintended local protocol handlers
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
IBM i is Affected By Multiple Vulnerabilities in SQL
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
Potential DoS via quadratic complexity in unicodedata.normalize()
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
Gitea SSH Key Parser Denial of Service
In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing
EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
Nagios Core / XI CSRF Protection Bypass via Double-Submit Cookie
PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for
Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties
Assisted-service: assisted-service: authenticated users can gain administrative access to openshift clusters via credential disclosure
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.
JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass
Flowise before 3.1.3 IDOR via customer-default-source endpoint
WordPress Vehica Core plugin <= 1.0.104 - Server Side Request Forgery (SSRF) vulnerability
WordPress ReactPress plugin <= 3.4.0 - Broken Access Control vulnerability
CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service.
Out-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platforms
Out-of-bounds write in the Base64 decoder in Amazon aws-sdk-cpp
Kong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identity
Heap buffer overflow in Modbusgwd
Stack overflow parsing XML with deeply nested DTD content models
Incomplete control character validation in http.cookies
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
Prisma Access Agent: Local Privilege Escalation
SurrealDB before 2.2.2 Memory Exhaustion via Nested Functions
WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability
Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secrets
ToolJet: Cross-tenant Broken Access Control in ToolJet Database (tooljet-db): any authenticated user can read and write another organization's tables
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS
Next.js: Denial of Service in the Image Optimization API
389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext() via critical session tracking control
Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto
Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto
Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
GlobalProtect App: Local Privilege Escalation Vulnerabilities
Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF)
rsync < 3.5.0 TOCTOU Race Condition via Destination Directory Handling
Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured
SurrealDB before 2.3.6 deny-net Bypass via DNS Resolution
TypeORM: migration:generate template-literal code injection
Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory
rsync < 3.5.0 Symlink Race Condition via --remove-source-files
rsync < 3.5.0 Symlink Race Condition Information Disclosure
ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash.
Docker Sandboxes ICMP egress restriction bypass after daemon restart
Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution
SourcelessFileLoader does not use io.open_code()
HTTP client proxy tunnel headers not validated for CR/LF
Quasar Framework: Prototype pollution in Quasar extend() utility
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.
Prisma Access Agent: Anti-Tamper Protection Bypass on Windows
HCL AION is affected by multiple security vulnerabilities.
Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
Microsoft Office Graphics Component Information Disclosure Vulnerability
Windows NTFS Information Disclosure Vulnerability
iommufd: Set upper bounds on cache invalidation entry_num and entry_len
KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB
KVM: SEV: Pin source page for write when adding CPUID data for SNP guest
i2c: imx-lpi2c: mark I2C adapter when hardware is powered down
Input: elan_i2c - prevent division by zero and arithmetic underflow
MIPS: smp: report dying CPU to RCU in stop_this_cpu()
gpio: rockchip: teardown bugs and resource leaks
media: rc: igorplugusb: fix control request setup packet
gpio: shared: fix deadlock on shared proxy's parent removal
x86/mm: Disable broadcast TLB flush when PCID is disabled
net: ethtool: phy: avoid NULL deref when PHY driver is unbound
ACPI: driver: Check ACPI_COMPANION() against NULL during probe
phonet/pep: disable BH around forwarded sk_receive_skb()
wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
tracing: Do not call map->ops->elt_free() if elt_alloc() fails
i2c: tegra: fix pm_runtime leak on mutex_lock failure
spi: qup: fix error pointer deref after DMA setup failure
spi: ep93xx: fix error pointer deref after DMA setup failure
spi: sprd: fix error pointer deref after DMA setup failure
kho: skip KHO for crash kernel
firmware: arm_ffa: Check for NULL FF-A ID table while driver registration
ARM: integrator: Fix early initialization
btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()
test_kprobes: clear kprobes between test runs
net: ti: icssm-prueth: fix eth_ports_node leak in probe
netfs, afs: Fix write skipping in dir/link writepages
hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
mm/memory: fix spurious warning when unmapping device-private/exclusive pages
mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free
mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page
Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer
net: ethtool: fix NULL pointer dereference in phy_reply_size
l2tp: use list_del_rcu in l2tp_session_unhash
Microsoft Office Graphics Component Information Disclosure Vulnerability
Windows NTFS Information Disclosure Vulnerability
Microsoft Office Graphics Component Information Disclosure Vulnerability
Win32k Information Disclosure Vulnerability
Windows NTFS Information Disclosure Vulnerability
Windows NTFS Information Disclosure Vulnerability
Win32k Information Disclosure Vulnerability
Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability
Win32k Information Disclosure Vulnerability
Win32k Information Disclosure Vulnerability
Windows Imaging Component Information Disclosure Vulnerability
Windows Management Instrumentation Information Disclosure Vulnerability
Windows Wired AutoConfig Service Information Disclosure Vulnerability
Windows GDI+ Information Disclosure Vulnerability
Windows DWM Core Library Information Disclosure Vulnerability
Windows Defender Firewall Service Security Feature Bypass Vulnerability
Windows DWM Core Library Information Disclosure Vulnerability
Windows Hello Tampering Vulnerability
Windows GDI Information Disclosure Vulnerability
Windows Event Logging Service Information Disclosure Vulnerability
Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
SourceCodester Simple Student Information System view_department.php sql injection
Kong Mesh: kumactl connects to the control plane without verifying the TLS certificate when no CA is configured
Open5GS CER init.c diam_log_func assertion
drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback()
ceph: fix possible deadlock when holding Fwb to get inline_data
drm/amd/display: Check if modulo is 0 before dividing.
f2fs: use spin_lock to avoid hang
drm/amd/amdgpu/amdgpu_cs: fix refcount leak of a dma_fence obj
drm/amd/display: Fix memory leak
drm/amdkfd: svm range restore work deadlock when process exit
ath11k: pci: fix crash on suspend if board file is not found
ath11k: mhi: use mhi_sync_power_up()
scsi: mpi3mr: Fix memory leaks
ath11k: Fix frames flush failure caused by deadlock
scsi: hisi_sas: Free irq vectors in order for v3 HW
mt76: fix monitor mode crash with sdio driver
ceph: fix inode reference leakage in ceph_get_snapdir()
ceph: fix memory leak in ceph_readdir when note_last_dentry returns error
staging: wfx: fix an error handling in wfx_init_common()
staging: vchiq_core: handle NULL result of find_service_by_handle
habanalabs: fix possible memory leak in MMU DR fini
drm/amd/display: Fix by adding FPU protection for dcn30_internal_validate_bw
scsi: qedf: Add stag_work to all the vports
scsi: qedf: Fix refcount issue when LOGO is received during TMF
drm/gma500: Fix WARN_ON(lock->magic != lock) error
Material for MkDocs: DOM XSS in search suggestions via query parameter
RustFS: FTPS MKD bypasses IAM CreateBucket authorization
Notepad++: Install-time PowerShell command injection through installation path
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services.
Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creation
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Execution, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Execution accessible data as well as unauthorized read access to a subset of Oracle Transportation Execution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler
ColdFusion | Improper Encoding or Escaping of Output (CWE-116)
Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation
OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes
ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication
Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action
Serendipity 2.3.5 Reflected XSS via search clean-URL route
GitPython before 3.1.56 Arbitrary File Truncation via Commit.count
@hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket handshake
vLLM: Cross-User Data Leak Vulnerability
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of CVE-2026-55574
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
phpList < 3.7.0-RC5 Cross-Site Request Forgery via Bounce Rules
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
WordPress User Registration plugin <= 5.2.6 - Broken Access Control vulnerability
WordPress InstaWP Connect plugin <= 0.1.3.7 - Broken Access Control vulnerability
WordPress Revolut Gateway for WooCommerce plugin < 4.22.10 - Broken Access Control vulnerability
WordPress GiveWP plugin < 4.16.6 - Broken Access Control vulnerability
Budibase: Account Enumeration via Login Lockout Response Differential
kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
NodeBB < 4.15.0 Stored XSS via ActivityPub emoji tag.icon.url and tag.name
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>
Anonymous users may access restricted Artifactory repository information
RS9116W/SiWx917 malformed packet with increased length field causes memory leak
BT122 malformed packet with increased length field causes memory leak
BT122 stops advertising
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
Windows Schannel Security Feature Bypass Vulnerability
Priority - CWE-203: Observable Discrepancy
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens
Apache Thrift: c_glib dispatch stack overflow
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass
CVE-2026-18750
Kong Mesh: control plane denial of service via a malformed dataplane token with a non-string JWT kid
Kong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authentication
Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering
Referer Validation Bypass in TL-WR820N Web Management Interface
PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle
CPython >3.11 Insecure Input Validation resulting in privilege escalation
Allocation of Resources Without Limits or Throttling in GitLab
Prevent Direct Access – Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File Access
GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake
Saurus CMS Unauthenticated Open Redirect via logout url parameter
rails-html-sanitizer: Possible XSS vulnerability with certain configurations
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
Next AI Draw.io 0.2.1 - 0.4.16 Reflected XSS via unsanitized mcp query parameter
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.
Stored Cross-site Scripting in Pentestify Markdown renderer via unescaped quotes
Stored Cross-site Scripting in Pentestify user account deletion via unescaped username
Kong Mesh: default control plane config leaks the admin token cross-origin via a CORS wildcard and localhost admin
Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path
Windows Hyper-V Information Disclosure Vulnerability
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Installed Base accessible data as well as unauthorized read access to a subset of Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).
ColdFusion | Improper Input Validation (CWE-20)
Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Allows Unauthorized Access
Discourse: Stored XSS in the moderation review queue
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758.
Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass in `@backstage/plugin-auth-backend`
Loofah: SVG `href` attribute bypasses local-reference restriction
KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier
Probo has an open redirect bypass via path normalization
Stack-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark
Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid
HCL AION is affected by multiple security vulnerabilities.
tpm: use try_get_ops() in tpm-space.c
Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
Windows NTFS Information Disclosure Vulnerability
Unauthorized Access to Admin Functionality via Forced Browsing
ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)
GlobalProtect App: Improper Certificate Validation Bypass Vulnerability
Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape
Discourse: Templates endpoint exposes hidden tag names
Discourse: Duplicate lookup reveals restricted topic titles through canonicalized URLs
Potential unauthorized metadata exposure in JFrog Artifactory
Authenticated users may view private Puppet module metadata
Authenticated users may access private NuGet metadata
Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization
HCL AION is affected by multiple security vulnerabilities.
Claircore: claircore: denial of service via unchecked type assertion in rpm header parser
OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge alarms as any user and bypass read-only
Incorrect Authorization in GitLab
Missing Authorization in GitLab
IBM i is Affected By Multiple Vulnerabilities in Navigator for i
PostgreSQL ascii() function reads past end of buffer
IBM i is Affected By Multiple Vulnerabilities in SQL
IBM i is Affected By Multiple Vulnerabilities in SQL
Salon Booking System – Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclosure
IBM® Db2® is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.
WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Update Modification via IDOR
PostgreSQL pg_trgm picksplit reads past end of buffer
KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR
Eventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR
Incorrect Authorization in GitLab
Missing Authorization in GitLab
PostgreSQL fails to check type USAGE privilege
Missing Authorization in GitLab
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
CORS Misconfiguration in DevOps Loop
Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives
PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL
PostgreSQL row security caching disregards role modifications
IBM DataPower Gateway affected by HTTP request header leakage in XML-Firewall
Configuration Injection via Carriage Return (\r) in write() method
GlobalProtect App: Local Privilege Escalation via Race Condition on macOS
Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header
A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
PostgreSQL ECPG integer underflow can crash the client
PostgreSQL amcheck does not clear untrusted search path
PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
Missing HTTP Security Headers in DevOps Loop
Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR
HCL AION is affected by multiple security vulnerabilities.
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Work in Process accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Work in Process. CVSS 3.1 Base Score 3.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).
HCL AION is affected by multiple security vulnerabilities.
IBM® Db2® could allow a local attacker to cause a denial of service due to a memory leak
Incorrect Privilege Assignment in GitLab
In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.
An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.
Insufficient Input Validation in DevOps Loop
IBM i is Affected By security restrictions bypass in Navigator for i
Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
Webhook Authorization Header Returned in Plaintext via API
Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
SurrealDB before 2.2.2 Denial of Service via JavaScript Scripting
SurrealDB before 2.2.2 Local File Read via DEFINE ANALYZER
Trix: XSS via JSON deserialization bypass in drag-and-drop (Level0InputController)
Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows
Sigstore Java has a vulnerability with bundle verification of integratedTime
Quadratic Behavior in xml.etree.ElementPath Index Predicates
Tarfile.extract() doesn't fully respect filter parameter
tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).
PAN-OS: Information Disclosure Vulnerability in URL Filtering
Prisma Access Agent: Authenticated Limited File Deletion on Linux
Prisma Browser: Sensitive Information Disclosure Vulnerability
Prisma Browser: Inappropriate Implementation in Account Protection
JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager
KVM: s390: pci: Fix handling of AIF enable without AISB
s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
s390/zcrypt: Validate length for CCA AES cipher key requests
s390/zcrypt: Validate length for CCA ECC private key requests
drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()
drm/amdgpu/vce: fix integer overflow in image size
drm/amdgpu/vcn4: avoid rereading IB param length
drm/amdgpu: fix division by zero with invalid uvd dimensions
drm/amdgpu: Fix kernel panic during driver load failure
drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
drm/amdgpu: reject mapping a reserved doorbell to a new queue
ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
ksmbd: bound DACL dedup walk to copied ACEs
ksmbd: validate ACE size against SID sub-authorities
usb: gadget: function: rndis: add length check to response query
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Private Repository Existence Disclosure via go-get Meta Endpoint
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
Public-only repository tokens can update private PR head branches
Repository migration SSRF via multi-answer DNS allow-list bypass
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Repository Visibility Manipulation via Git Push Options
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
Gitea LFS Deploy-Key Privilege Escalation
Private Repository Metadata Remains Accessible After Access Revocation
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
Public-only API token restriction is not enforced on team API routes
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Local File Inclusion via file:// URI in Migration Restore
REST API exposes organization membership of private organizations to public
Two SSRF findings in Gitea 1.26.2
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
Cross-repository issue/comment attachment re-linking can expose private attachment content
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Privilege Escalation via Access Token Scope Escalation in API
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
Email Management API Bypasses ManageCredentials Feature Restrictions
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Gitea runner registration-token GET endpoint performs a write under a read-only token scope
Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification
Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template