| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-68839 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-67643 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-67636 | Cri | 0.59 | 9.0 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-67631 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-67378 | Cri | 0.59 | 9.0 | 0.01 | Sep 8, 2026 | Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65669 | Cri | 0.62 | 9.6 | 0.01 | Sep 8, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-82533 | Cri | 0.55 | 9.6 | 0.01 | Sep 8, 2026 | DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the… | ||
| CVE-2026-79570 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | ||
| CVE-2026-79569 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | ||
| CVE-2026-78997 | Cri | 0.60 | 9.3 | 0.00 | Sep 8, 2026 | UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain… | ||
| CVE-2026-75156 | Cri | 0.52 | 9.1 | 0.00 | Sep 8, 2026 | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are… | ||
| CVE-2026-26084 | Cri | 0.64 | 9.9 | 0.00 | Sep 8, 2026 | A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests. | ||
| CVE-2026-86840 | Cri | 0.59 | 9.1 | 0.00 | Sep 8, 2026 | The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on… | ||
| CVE-2026-79574 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message. | ||
| CVE-2026-79577 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request. | ||
| CVE-2026-79576 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password. | ||
| CVE-2026-79571 | Cri | 0.59 | 9.1 | 0.00 | Sep 8, 2026 | Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without… | ||
| CVE-2026-61516 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session.… | ||
| CVE-2026-12745 | Cri | 0.64 | 9.8 | 0.02 | Sep 8, 2026 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-12744 | Cri | 0.64 | 9.8 | 0.02 | Sep 8, 2026 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-12650 | Cri | 0.64 | 9.9 | 0.01 | Sep 8, 2026 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-12647 | Cri | 0.64 | 9.9 | 0.01 | Sep 8, 2026 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-12646 | Cri | 0.64 | 9.9 | 0.01 | Sep 8, 2026 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-12645 | Cri | 0.64 | 9.9 | 0.01 | Sep 8, 2026 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. | ||
| CVE-2026-77098 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server. | ||
| CVE-2026-77092 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor. | ||
| CVE-2026-77089 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center. | ||
| CVE-2026-78234 | Cri | 0.64 | 9.9 | 0.00 | Sep 8, 2026 | A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource.… | ||
| CVE-2026-71377 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from… | ||
| CVE-2026-71376 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20… | ||
| CVE-2026-62645 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized… | ||
| CVE-2026-50093 | Cri | 0.59 | 9.0 | 0.00 | Sep 8, 2026 | A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A… | ||
| CVE-2026-71374 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through… | ||
| CVE-2026-86510 | Cri | 0.64 | 9.9 | 0.00 | Sep 8, 2026 | A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and… | ||
| CVE-2026-86509 | Cri | 0.62 | 9.6 | 0.00 | Sep 8, 2026 | A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit… | ||
| CVE-2026-76969 | Cri | 0.61 | 9.4 | 0.00 | Sep 8, 2026 | @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or… | ||
| CVE-2026-66768 | Cri | 0.59 | 9.0 | 0.00 | Sep 8, 2026 | SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow… | ||
| CVE-2026-58240 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component… | ||
| CVE-2026-44756 | Cri | 0.65 | 10.0 | 0.00 | Sep 8, 2026 | A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and… | ||
| CVE-2026-86543 | Cri | 0.57 | 9.8 | 0.00 | Sep 7, 2026 | knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish… | ||
| CVE-2026-86542 | Cri | 0.52 | 9.1 | 0.00 | Sep 7, 2026 | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files… | ||
| CVE-2026-75650 | Cri | 0.77 | 10.0 | 0.02 | KEV | Sep 7, 2026 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code.… | |
| CVE-2026-86480 | Cri | 0.64 | 9.8 | 0.00 | Sep 7, 2026 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges | ||
| CVE-2026-86478 | Cri | 0.64 | 9.8 | 0.00 | Sep 7, 2026 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | ||
| CVE-2026-7861 | Cri | 0.64 | 9.8 | 0.00 | Sep 7, 2026 | Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3. | ||
| CVE-2026-18922 | Cri | 0.57 | 9.8 | 0.01 | Sep 7, 2026 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL… | ||
| CVE-2026-86426 | Cri | 0.57 | 9.8 | 0.02 | Sep 7, 2026 | LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion by sending small integers like… | ||
| CVE-2026-86419 | Cri | 0.52 | 9.1 | 0.00 | Sep 7, 2026 | Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme or destination. The original request… | ||
| CVE-2026-80238 | Cri | 0.60 | 9.3 | 0.00 | Sep 7, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to… | ||
| CVE-2026-76578 | Cri | 0.57 | 9.8 | 0.00 | Sep 7, 2026 | A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory… |
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.59cvss 9.0epss 0.01
Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.59cvss 9.0epss 0.01
Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.62cvss 9.6epss 0.01
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
- risk 0.55cvss 9.6epss 0.01
DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the…
- risk 0.64cvss 9.8epss 0.00
mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
- risk 0.64cvss 9.8epss 0.00
Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
- risk 0.60cvss 9.3epss 0.00
UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain…
- risk 0.52cvss 9.1epss 0.00
Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are…
- risk 0.64cvss 9.9epss 0.00
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
- risk 0.59cvss 9.1epss 0.00
The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on…
- risk 0.64cvss 9.8epss 0.00
An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.
- risk 0.64cvss 9.8epss 0.00
An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.
- risk 0.64cvss 9.8epss 0.00
An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.
- risk 0.59cvss 9.1epss 0.00
Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without…
- risk 0.64cvss 9.8epss 0.00
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session.…
- risk 0.64cvss 9.8epss 0.02
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.8epss 0.02
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.9epss 0.01
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.9epss 0.01
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.9epss 0.01
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.9epss 0.01
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
- risk 0.64cvss 9.8epss 0.00
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
- risk 0.64cvss 9.8epss 0.00
Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
- risk 0.64cvss 9.8epss 0.00
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
- risk 0.64cvss 9.9epss 0.00
A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource.…
- risk 0.64cvss 9.8epss 0.00
Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from…
- risk 0.64cvss 9.8epss 0.01
OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20…
- risk 0.64cvss 9.8epss 0.00
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized…
- risk 0.59cvss 9.0epss 0.00
A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A…
- risk 0.64cvss 9.8epss 0.00
Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through…
- risk 0.64cvss 9.9epss 0.00
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and…
- risk 0.62cvss 9.6epss 0.00
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit…
- risk 0.61cvss 9.4epss 0.00
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or…
- risk 0.59cvss 9.0epss 0.00
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow…
- risk 0.64cvss 9.8epss 0.00
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component…
- risk 0.65cvss 10.0epss 0.00
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and…
- risk 0.57cvss 9.8epss 0.00
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish…
- risk 0.52cvss 9.1epss 0.00
knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files…
- risk 0.77cvss 10.0epss 0.02
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code.…
- risk 0.64cvss 9.8epss 0.00
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
- risk 0.64cvss 9.8epss 0.00
In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address
- risk 0.64cvss 9.8epss 0.00
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.
- risk 0.57cvss 9.8epss 0.01
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL…
- risk 0.57cvss 9.8epss 0.02
LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion by sending small integers like…
- risk 0.52cvss 9.1epss 0.00
Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme or destination. The original request…
- risk 0.60cvss 9.3epss 0.00
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to…
- risk 0.57cvss 9.8epss 0.00
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory…