| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-80491 | Hig | 0.56 | 8.6 | 0.00 | Sep 12, 2026 | The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks. | ||
| CVE-2026-78152 | Med | 0.34 | 5.3 | 0.00 | Sep 12, 2026 | The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content. | ||
| CVE-2026-77753 | Med | 0.36 | 5.5 | 0.00 | Sep 12, 2026 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working… | ||
| CVE-2026-77752 | Hig | 0.47 | 7.2 | 0.00 | Sep 12, 2026 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take… | ||
| CVE-2026-77705 | Hig | 0.47 | 7.2 | 0.00 | Sep 12, 2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management… | ||
| CVE-2026-77689 | Med | 0.34 | 5.3 | 0.00 | Sep 12, 2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never… | ||
| CVE-2026-77006 | Cri | 0.62 | 9.6 | 0.00 | Sep 12, 2026 | The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete… | ||
| CVE-2026-77005 | Cri | 0.62 | 9.6 | 0.00 | Sep 12, 2026 | The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on… | ||
| CVE-2026-75800 | Cri | 0.64 | 9.8 | 0.00 | Sep 12, 2026 | The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary… | ||
| CVE-2026-87719 | Cri | 0.64 | 9.9 | 0.01 | Sep 12, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and… | ||
| CVE-2026-85706 | Cri | 0.77 | 10.0 | 0.01 | KEV | Sep 12, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path… | |
| CVE-2026-90467 | Med | 0.19 | 4.0 | 0.00 | Sep 12, 2026 | aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like… | ||
| CVE-2026-89268 | Med | 0.28 | 5.4 | 0.00 | Sep 12, 2026 | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers,… | ||
| CVE-2026-89267 | Med | 0.21 | 4.3 | 0.00 | Sep 12, 2026 | starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to… | ||
| CVE-2026-89266 | Hig | 0.53 | 8.2 | 0.00 | Sep 12, 2026 | stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes,… | ||
| CVE-2026-90461 | Med | 0.41 | 6.3 | 0.00 | Sep 11, 2026 | OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication. | ||
| CVE-2026-90460 | Hig | 0.49 | — | 0.00 | Sep 11, 2026 | An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the… | ||
| CVE-2026-90457 | Med | 0.38 | — | 0.00 | Sep 11, 2026 | The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a… | ||
| CVE-2026-90456 | Cri | 0.53 | — | 0.00 | Sep 11, 2026 | An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials… | ||
| CVE-2026-90455 | Med | 0.34 | — | 0.00 | Sep 11, 2026 | A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a… | ||
| CVE-2026-90454 | Med | 0.27 | — | 0.00 | Sep 11, 2026 | A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise… | ||
| CVE-2026-90453 | Med | 0.26 | — | 0.00 | Sep 11, 2026 | A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's… | ||
| CVE-2026-90452 | Med | 0.32 | — | 0.00 | Sep 11, 2026 | Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could… | ||
| CVE-2026-90451 | Hig | 0.46 | — | 0.00 | Sep 11, 2026 | An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that… | ||
| CVE-2026-90450 | Med | 0.27 | — | 0.00 | Sep 11, 2026 | The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any… | ||
| CVE-2026-90449 | Med | 0.38 | — | 0.00 | Sep 11, 2026 | When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative… | ||
| CVE-2026-90448 | Hig | 0.39 | — | 0.00 | Sep 11, 2026 | A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an… | ||
| CVE-2026-90447 | Hig | 0.39 | — | 0.00 | Sep 11, 2026 | A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service… | ||
| CVE-2026-90446 | Med | 0.27 | — | 0.00 | Sep 11, 2026 | An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an… | ||
| CVE-2026-90445 | Hig | 0.39 | — | 0.00 | Sep 11, 2026 | An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries… | ||
| CVE-2026-90444 | Hig | 0.50 | — | 0.00 | Sep 11, 2026 | A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed… | ||
| CVE-2026-90443 | Med | 0.27 | — | 0.00 | Sep 11, 2026 | A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes… | ||
| CVE-2026-54258 | Med | 0.35 | 6.5 | 0.00 | Sep 11, 2026 | ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging… | ||
| CVE-2026-54248 | — | Med | 0.35 | 6.5 | 0.00 | Sep 11, 2026 | Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy… | |
| CVE-2026-54241 | Hig | 0.41 | 7.4 | 0.00 | Sep 11, 2026 | libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer… | ||
| CVE-2026-54240 | Hig | 0.41 | 7.4 | 0.00 | Sep 11, 2026 | libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflow and cause out-of-bounds heap reads or… | ||
| CVE-2026-50018 | Med | 0.35 | 6.5 | 0.00 | Sep 11, 2026 | Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP connection but never responds), each… | ||
| CVE-2026-50013 | Hig | 0.42 | 7.5 | 0.00 | Sep 11, 2026 | Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the… | ||
| CVE-2026-49992 | Med | 0.34 | — | 0.00 | Sep 11, 2026 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly… | ||
| CVE-2026-49846 | Hig | 0.42 | 7.5 | 0.00 | Sep 11, 2026 | libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes… | ||
| CVE-2026-48496 | Med | 0.33 | 6.2 | 0.00 | Sep 11, 2026 | OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to open a nonregular mapping file, such as a… | ||
| CVE-2026-45056 | Med | 0.38 | — | 0.00 | Sep 11, 2026 | matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted… | ||
| CVE-2026-44715 | Hig | 0.57 | — | 0.00 | Sep 11, 2026 | OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level… | ||
| CVE-2026-61534 | cri | 0.52 | — | — | Sep 11, 2026 | # Summary `Store`/`LegacyStore` key internal lookup tables by the `type`, `id`, and relationship names from a JSON:API document. Because these were plain objects, a document with `type: "__proto__"` writes onto `Object.prototype`, polluting every object in the process. #… | ||
| CVE-2026-59973 | hig | 0.38 | — | — | Sep 11, 2026 | ## Summary The published fix for GHSA-v6ph-xcq9-qxxj / CVE-2026-39885 added a direct hostname denylist for OpenAPI external `$ref` dereferencing, but the latest patched dependency `mcp-from-openapi` 2.3.0 still makes backend-origin requests to loopback when the target is… | ||
| CVE-2026-56825 | hig | 0.38 | — | — | Sep 11, 2026 | ## Title Missing authorization on product removal actions in CollectionProducts component ## Description A lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside `packages/admin/src/Livewire/Components/Collection/Col… | ||
| CVE-2026-56830 | 0.00 | — | — | Sep 11, 2026 | ## Title Missing authorization on Media sub-form store action allows unpermissioned product media update ## Description A lack of authorization control on the `store()` method was found in `packages/admin/src/Livewire/Components/Products/Form/Media.php`. The security fix… | |||
| CVE-2026-56829 | hig | 0.38 | — | — | Sep 11, 2026 | ## Title Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component ## Description A lack of authorization control was discovered in the `stockAction()` method in `packages/admin/src/Livewire/Components/Products/VariantStock.php`. The… | ||
| CVE-2026-56828 | hig | 0.38 | — | — | Sep 11, 2026 | ## Summary Three Livewire admin components in `shopper/framework` (latest master at commit `fcd0c59`, released as v2.8.0) gate state-mutating actions on the read-only `view_users` permission. This is the same class as the issue Shopper fixed in v2.8.0 / PR #511 /… | ||
| CVE-2026-56826 | 0.00 | — | — | Sep 11, 2026 | ## Summary Four Livewire components in the Settings area expose destructive Filament actions (`delete` / `edit`) that perform **no server-side authorization**. Any authenticated user who can reach the Settings pages — i.e. holding only the coarse `access_setting` permission,… |
- risk 0.56cvss 8.6epss 0.00
The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.
- risk 0.34cvss 5.3epss 0.00
The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.
- risk 0.36cvss 5.5epss 0.00
The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working…
- risk 0.47cvss 7.2epss 0.00
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take…
- risk 0.47cvss 7.2epss 0.00
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management…
- risk 0.34cvss 5.3epss 0.00
The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never…
- risk 0.62cvss 9.6epss 0.00
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete…
- risk 0.62cvss 9.6epss 0.00
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on…
- risk 0.64cvss 9.8epss 0.00
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary…
- risk 0.64cvss 9.9epss 0.01
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and…
- risk 0.77cvss 10.0epss 0.01
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path…
- risk 0.19cvss 4.0epss 0.00
aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like…
- risk 0.28cvss 5.4epss 0.00
QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers,…
- risk 0.21cvss 4.3epss 0.00
starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to…
- risk 0.53cvss 8.2epss 0.00
stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes,…
- risk 0.41cvss 6.3epss 0.00
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
- risk 0.49cvss —epss 0.00
An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the…
- risk 0.38cvss —epss 0.00
The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a…
- risk 0.53cvss —epss 0.00
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials…
- risk 0.34cvss —epss 0.00
A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a…
- risk 0.27cvss —epss 0.00
A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise…
- risk 0.26cvss —epss 0.00
A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's…
- risk 0.32cvss —epss 0.00
Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could…
- risk 0.46cvss —epss 0.00
An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that…
- risk 0.27cvss —epss 0.00
The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any…
- risk 0.38cvss —epss 0.00
When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative…
- risk 0.39cvss —epss 0.00
A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an…
- risk 0.39cvss —epss 0.00
A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service…
- risk 0.27cvss —epss 0.00
An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an…
- risk 0.39cvss —epss 0.00
An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries…
- risk 0.50cvss —epss 0.00
A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed…
- risk 0.27cvss —epss 0.00
A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes…
- risk 0.35cvss 6.5epss 0.00
ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging…
- risk 0.35cvss 6.5epss 0.00
Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy…
- risk 0.41cvss 7.4epss 0.00
libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer…
- risk 0.41cvss 7.4epss 0.00
libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflow and cause out-of-bounds heap reads or…
- risk 0.35cvss 6.5epss 0.00
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP connection but never responds), each…
- risk 0.42cvss 7.5epss 0.00
Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the…
- risk 0.34cvss —epss 0.00
Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly…
- risk 0.42cvss 7.5epss 0.00
libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes…
- risk 0.33cvss 6.2epss 0.00
OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to open a nonregular mapping file, such as a…
- risk 0.38cvss —epss 0.00
matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted…
- risk 0.57cvss —epss 0.00
OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level…
- risk 0.52cvss —epss —
# Summary `Store`/`LegacyStore` key internal lookup tables by the `type`, `id`, and relationship names from a JSON:API document. Because these were plain objects, a document with `type: "__proto__"` writes onto `Object.prototype`, polluting every object in the process. #…
- risk 0.38cvss —epss —
## Summary The published fix for GHSA-v6ph-xcq9-qxxj / CVE-2026-39885 added a direct hostname denylist for OpenAPI external `$ref` dereferencing, but the latest patched dependency `mcp-from-openapi` 2.3.0 still makes backend-origin requests to loopback when the target is…
- risk 0.38cvss —epss —
## Title Missing authorization on product removal actions in CollectionProducts component ## Description A lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside `packages/admin/src/Livewire/Components/Collection/Col…
- CVE-2026-56830Sep 11, 2026risk 0.00cvss —epss —
## Title Missing authorization on Media sub-form store action allows unpermissioned product media update ## Description A lack of authorization control on the `store()` method was found in `packages/admin/src/Livewire/Components/Products/Form/Media.php`. The security fix…
- risk 0.38cvss —epss —
## Title Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component ## Description A lack of authorization control was discovered in the `stockAction()` method in `packages/admin/src/Livewire/Components/Products/VariantStock.php`. The…
- risk 0.38cvss —epss —
## Summary Three Livewire admin components in `shopper/framework` (latest master at commit `fcd0c59`, released as v2.8.0) gate state-mutating actions on the read-only `view_users` permission. This is the same class as the issue Shopper fixed in v2.8.0 / PR #511 /…
- CVE-2026-56826Sep 11, 2026risk 0.00cvss —epss —
## Summary Four Livewire components in the Settings area expose destructive Filament actions (`delete` / `edit`) that perform **no server-side authorization**. Any authenticated user who can reach the Settings pages — i.e. holding only the coarse `access_setting` permission,…