| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-21807 | Low | 0.25 | 3.9 | 0.00 | Aug 26, 2026 | HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow. | ||
| CVE-2026-18823 | — | 0.00 | — | — | Aug 26, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||
| CVE-2025-62341 | Low | 0.24 | 3.7 | 0.00 | Aug 26, 2026 | HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass. | ||
| CVE-2026-81202 | Hig | 0.47 | 7.3 | 0.01 | Aug 26, 2026 | A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack… | ||
| CVE-2026-77611 | Hig | 0.39 | 7.1 | 0.00 | Aug 26, 2026 | SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested object key can overwrite a different object outside that scope by calling PutObjectAcl on the key it is allowed to access.… | ||
| CVE-2026-77368 | Hig | 0.42 | 7.6 | 0.00 | Aug 26, 2026 | SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upload session to write content to… | ||
| CVE-2026-77317 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose… | ||
| CVE-2026-77298 | Hig | 0.50 | — | 0.00 | Aug 26, 2026 | SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external OIDC JWT sent directly in the Authorization header and maps it to an IAM role without enforcing that role's trust policy, so a federated user can assume a… | ||
| CVE-2026-75333 | Hig | 0.49 | 7.5 | 0.01 | Aug 26, 2026 | yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation. | ||
| CVE-2026-75331 | Med | 0.30 | 4.6 | 0.00 | Aug 26, 2026 | tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type validation. Attackers can upload arbitrary HTML/JavaScript files to the server. | ||
| CVE-2026-75329 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2026 | The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any… | ||
| CVE-2026-75328 | Hig | 0.49 | 7.5 | 0.01 | Aug 26, 2026 | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability: | ||
| CVE-2026-65930 | Med | 0.31 | — | 0.00 | Aug 26, 2026 | LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5. | ||
| CVE-2026-65647 | Hig | 0.57 | — | 0.01 | Aug 26, 2026 | Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. | ||
| CVE-2026-65646 | Cri | 0.64 | 9.9 | 0.01 | Aug 26, 2026 | Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges. | ||
| CVE-2026-65642 | Hig | 0.56 | — | 0.00 | Aug 26, 2026 | Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases. | ||
| CVE-2026-65641 | Cri | 0.60 | — | 0.01 | Aug 26, 2026 | A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account. | ||
| CVE-2026-64632 | Hig | 0.55 | — | 0.00 | Aug 26, 2026 | A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account. | ||
| CVE-2026-63360 | Hig | 0.48 | — | 0.00 | Aug 26, 2026 | LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML… | ||
| CVE-2026-61617 | Hig | 0.43 | 7.7 | 0.00 | Aug 26, 2026 | Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the… | ||
| CVE-2026-58070 | Med | 0.44 | — | 0.00 | Aug 26, 2026 | A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials. | ||
| CVE-2026-55182 | Hig | 0.49 | — | 0.02 | Aug 26, 2026 | LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an alert transport entry are insufficiently escaped before being passed to an exec… | ||
| CVE-2026-45694 | Med | 0.28 | 5.4 | 0.00 | Aug 26, 2026 | LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected into the page title without adequate… | ||
| CVE-2026-43621 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter.… | ||
| CVE-2026-21810 | Med | 0.29 | 4.4 | 0.00 | Aug 26, 2026 | HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary. | ||
| CVE-2026-21809 | Low | 0.25 | 3.9 | 0.00 | Aug 26, 2026 | HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input. | ||
| CVE-2026-16809 | Hig | 0.47 | — | 0.00 | Aug 26, 2026 | LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message. This issue affects… | ||
| CVE-2026-79921 | Hig | 0.51 | — | 0.01 | Aug 26, 2026 | amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or… | ||
| CVE-2026-77573 | Low | 0.16 | 3.5 | 0.00 | Aug 26, 2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs can perform server-side request forgery against internal services through DNS rebinding during VCS… | ||
| CVE-2026-77507 | Med | 0.27 | 5.3 | 0.00 | Aug 26, 2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the permission checks used elsewhere, allowing unauthorized users to read change-history metadata from… | ||
| CVE-2026-75415 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing attackers to forge any user identity credential information, thereby… | ||
| CVE-2026-75414 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2026 | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. | ||
| CVE-2026-75413 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath. | ||
| CVE-2026-75411 | Cri | 0.57 | 9.8 | 0.01 | Aug 26, 2026 | JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this… | ||
| CVE-2026-75364 | Med | 0.44 | 6.8 | 0.00 | Aug 26, 2026 | Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitize the display_name parameter. User-controlled input is concatenated via sprintf() into the unquoted shell command `/etc/rrd/graphinterface… | ||
| CVE-2026-75363 | Med | 0.44 | 6.8 | 0.00 | Aug 26, 2026 | An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n. | ||
| CVE-2026-62326 | Med | 0.35 | 6.5 | 0.00 | Aug 26, 2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role can store a malicious regular expression in a source string's flags that is executed without any timeout,… | ||
| CVE-2026-62249 | Med | 0.21 | 4.3 | 0.00 | Aug 26, 2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project can retrieve the change history of restricted components in that project through nested API change endpoints,… | ||
| CVE-2026-61792 | Hig | 0.43 | 7.7 | 0.01 | Aug 26, 2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths… | ||
| CVE-2026-61790 | Med | 0.22 | 4.4 | 0.00 | Aug 26, 2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure two-factor authentication before receiving the team's permissions, but this requirement is not enforced for… | ||
| CVE-2026-55228 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the… | ||
| CVE-2026-55227 | Med | 0.21 | 4.3 | 0.00 | Aug 26, 2026 | Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user… | ||
| CVE-2026-52473 | Med | 0.21 | 4.3 | 0.00 | Aug 26, 2026 | An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder. | ||
| CVE-2026-52103 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2026 | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message. | ||
| CVE-2026-39275 | Med | 0.33 | 6.1 | 0.00 | Aug 26, 2026 | Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components | ||
| CVE-2026-15973 | Hig | 0.55 | — | 0.00 | Aug 26, 2026 | LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey menu entry containing attacker-controlled data. The value is… | ||
| CVE-2025-61480 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers. | ||
| CVE-2025-61479 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session. | ||
| CVE-2025-61478 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets. | ||
| CVE-2025-51679 | Cri | 0.59 | 9.1 | 0.00 | Aug 26, 2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior. |
- risk 0.25cvss 3.9epss 0.00
HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
- CVE-2026-18823Aug 26, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- risk 0.24cvss 3.7epss 0.00
HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass.
- risk 0.47cvss 7.3epss 0.01
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack…
- risk 0.39cvss 7.1epss 0.00
SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested object key can overwrite a different object outside that scope by calling PutObjectAcl on the key it is allowed to access.…
- risk 0.42cvss 7.6epss 0.00
SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upload session to write content to…
- risk 0.46cvss 8.1epss 0.00
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose…
- risk 0.50cvss —epss 0.00
SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external OIDC JWT sent directly in the Authorization header and maps it to an IAM role without enforcing that role's trust policy, so a federated user can assume a…
- risk 0.49cvss 7.5epss 0.01
yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.
- risk 0.30cvss 4.6epss 0.00
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type validation. Attackers can upload arbitrary HTML/JavaScript files to the server.
- risk 0.64cvss 9.8epss 0.01
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any…
- risk 0.49cvss 7.5epss 0.01
In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:
- risk 0.31cvss —epss 0.00
LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5.
- risk 0.57cvss —epss 0.01
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
- risk 0.64cvss 9.9epss 0.01
Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
- risk 0.56cvss —epss 0.00
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
- risk 0.60cvss —epss 0.01
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
- risk 0.55cvss —epss 0.00
A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.
- risk 0.48cvss —epss 0.00
LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML…
- risk 0.43cvss 7.7epss 0.00
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the…
- risk 0.44cvss —epss 0.00
A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.
- risk 0.49cvss —epss 0.02
LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an alert transport entry are insufficiently escaped before being passed to an exec…
- risk 0.28cvss 5.4epss 0.00
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected into the page title without adequate…
- risk 0.46cvss 8.1epss 0.00
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter.…
- risk 0.29cvss 4.4epss 0.00
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.
- risk 0.25cvss 3.9epss 0.00
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.
- risk 0.47cvss —epss 0.00
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message. This issue affects…
- risk 0.51cvss —epss 0.01
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or…
- risk 0.16cvss 3.5epss 0.00
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs can perform server-side request forgery against internal services through DNS rebinding during VCS…
- risk 0.27cvss 5.3epss 0.00
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the permission checks used elsewhere, allowing unauthorized users to read change-history metadata from…
- risk 0.49cvss 7.5epss 0.00
AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing attackers to forge any user identity credential information, thereby…
- risk 0.64cvss 9.8epss 0.01
In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.
- risk 0.49cvss 7.5epss 0.00
DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.
- risk 0.57cvss 9.8epss 0.01
JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this…
- risk 0.44cvss 6.8epss 0.00
Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitize the display_name parameter. User-controlled input is concatenated via sprintf() into the unquoted shell command `/etc/rrd/graphinterface…
- risk 0.44cvss 6.8epss 0.00
An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.
- risk 0.35cvss 6.5epss 0.00
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role can store a malicious regular expression in a source string's flags that is executed without any timeout,…
- risk 0.21cvss 4.3epss 0.00
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project can retrieve the change history of restricted components in that project through nested API change endpoints,…
- risk 0.43cvss 7.7epss 0.01
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths…
- risk 0.22cvss 4.4epss 0.00
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure two-factor authentication before receiving the team's permissions, but this requirement is not enforced for…
- risk 0.46cvss 8.1epss 0.00
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the…
- risk 0.21cvss 4.3epss 0.00
Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user…
- risk 0.21cvss 4.3epss 0.00
An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder.
- risk 0.64cvss 9.8epss 0.01
A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.
- risk 0.33cvss 6.1epss 0.00
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components
- risk 0.55cvss —epss 0.00
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey menu entry containing attacker-controlled data. The value is…
- risk 0.49cvss 7.5epss 0.00
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.
- risk 0.49cvss 7.5epss 0.00
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session.
- risk 0.49cvss 7.5epss 0.00
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets.
- risk 0.59cvss 9.1epss 0.00
An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior.