| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-26447 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that connection, the broker performs incorrect cleanup of its internal subscription structures. This results in… | ||
| CVE-2026-26446 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger… | ||
| CVE-2026-26445 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with the broker s use of edge-triggered epoll (EPOLLET) and MSG_PEEK in recv(), causes sockets to enter a permanent half-read… | ||
| CVE-2025-70340 | Med | 0.35 | 6.5 | 0.00 | Aug 26, 2026 | A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm… | ||
| CVE-2025-70293 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2026 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code… | ||
| CVE-2025-70290 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2026 | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading… | ||
| CVE-2026-79940 | Med | 0.38 | 5.9 | 0.00 | Aug 26, 2026 | Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to gaining access to unauthorized data. | ||
| CVE-2026-75466 | Med | 0.35 | 6.5 | 0.00 | Aug 26, 2026 | libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a… | ||
| CVE-2026-75325 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2026 | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. | ||
| CVE-2026-71171 | Hig | 0.47 | 7.2 | 0.02 | Aug 26, 2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this… | ||
| CVE-2026-70419 | Cri | 0.59 | 9.1 | 0.02 | Aug 26, 2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to… | ||
| CVE-2026-63179 | Med | 0.25 | 4.9 | 0.01 | Aug 26, 2026 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP process by injecting @import (inline) directives into LESS source that the backend… | ||
| CVE-2026-51106 | Cri | 0.60 | 9.3 | 0.00 | Aug 26, 2026 | An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component | ||
| CVE-2026-48786 | Med | 0.35 | 6.5 | 0.00 | Aug 26, 2026 | Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including credential-bearing agent options, to… | ||
| CVE-2026-41262 | Med | 0.21 | 4.3 | 0.00 | Aug 26, 2026 | Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowing an authenticated user with… | ||
| CVE-2026-36851 | Hig | 0.49 | 7.5 | 0.01 | Aug 26, 2026 | Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration. | ||
| CVE-2026-19485 | Cri | 0.60 | — | 0.00 | Aug 26, 2026 | A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error… | ||
| CVE-2025-61165 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2026 | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. | ||
| CVE-2025-61164 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint. | ||
| CVE-2025-61163 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2026 | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests. | ||
| CVE-2025-61162 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint | ||
| CVE-2026-76784 | Hig | 0.57 | — | 0.00 | Aug 26, 2026 | Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device… | ||
| CVE-2026-58474 | Hig | 0.50 | 8.8 | 0.01 | Aug 26, 2026 | whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special… | ||
| CVE-2026-54256 | Med | 0.28 | 5.4 | 0.00 | Aug 26, 2026 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget trusted an attacker-controlled file_id POST parameter when resolving the attachment it operates on, allowing an authenticated… | ||
| CVE-2026-47841 | Hig | 0.48 | 7.4 | 0.00 | Aug 26, 2026 | An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 | ||
| CVE-2026-47837 | Med | 0.44 | 6.8 | 0.01 | Aug 26, 2026 | Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from… | ||
| CVE-2026-47836 | Hig | 0.47 | 7.2 | 0.00 | Aug 26, 2026 | The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config… | ||
| CVE-2026-32639 | Med | 0.37 | 6.8 | 0.00 | Aug 26, 2026 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any single CMS permission to act… | ||
| CVE-2026-32593 | Med | 0.31 | 5.9 | 0.00 | Aug 26, 2026 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configured with a conditions key, allowing an… | ||
| CVE-2025-56798 | Hig | 0.57 | 8.8 | 0.00 | Aug 26, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy. | ||
| CVE-2025-29419 | Hig | 0.39 | 7.1 | 0.00 | Aug 26, 2026 | CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack. | ||
| CVE-2023-42179 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2026 | Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process. | ||
| CVE-2026-44701 | low | 0.00 | — | — | Aug 26, 2026 | ### Summary An HTML Injection vulnerability exists in the user group creation functionality that allows an attacker to inject arbitrary HTML content into the application interface. The vulnerability occurs when user-supplied input in the group name field is not properly… | ||
| CVE-2026-80153 | — | 0.00 | — | — | Aug 26, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||
| CVE-2026-35445 | Hig | 0.39 | — | 0.00 | Aug 26, 2026 | Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated backend user to invoke arbitrary controller… | ||
| CVE-2026-32258 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered… | ||
| CVE-2026-32257 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and… | ||
| CVE-2020-15878 | Hig | 0.50 | 8.8 | 0.00 | Aug 26, 2026 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address parameter in the /ajax_table.php API endpoint. | ||
| CVE-2020-15876 | Hig | 0.50 | 8.8 | 0.00 | Aug 26, 2026 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects address-search.inc.php,… | ||
| CVE-2020-15874 | Hig | 0.50 | 8.8 | 0.01 | Aug 26, 2026 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint. | ||
| CVE-2026-81036 | Hig | 0.46 | 8.1 | 0.00 | Aug 26, 2026 | Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is… | ||
| CVE-2026-81035 | Hig | 0.53 | 8.1 | 0.00 | Aug 26, 2026 | Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it records, and the data-layer… | ||
| CVE-2026-81034 | Med | 0.42 | 6.5 | 0.00 | Aug 26, 2026 | Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp.go assigns a TLS configuration whose skip-verify field is set to true unconditionally, directly beneath a comment stating that the setting should be false in… | ||
| CVE-2026-81033 | Med | 0.34 | 5.3 | 0.00 | Aug 26, 2026 | Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js looks the address up and chains a not-found throw onto the query, so an address… | ||
| CVE-2026-81032 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2026 | NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and writing gflags alongside status… | ||
| CVE-2026-81031 | Hig | 0.47 | 7.2 | 0.00 | Aug 26, 2026 | IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves the authenticated user from the request that… | ||
| CVE-2026-81030 | Med | 0.35 | 6.5 | 0.00 | Aug 26, 2026 | Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in mage_ai/api/resources/BrowserItemResource.py passes a caller-supplied path to the filesystem read and write helpers without calling the containment helper that… | ||
| CVE-2026-81029 | Hig | 0.46 | 8.1 | 0.01 | Aug 26, 2026 | OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the… | ||
| CVE-2026-81028 | Med | 0.32 | 4.9 | 0.01 | Aug 26, 2026 | ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration loader in server/WebApi.cpp builds each root with File::absolutePath("", item, true); because the… | ||
| CVE-2026-81027 | Hig | 0.55 | 8.5 | 0.00 | Aug 26, 2026 | one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after model.IsAdmin succeeds and… |
- risk 0.49cvss 7.5epss 0.00
Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that connection, the broker performs incorrect cleanup of its internal subscription structures. This results in…
- risk 0.49cvss 7.5epss 0.00
Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger…
- risk 0.49cvss 7.5epss 0.00
stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with the broker s use of edge-triggered epoll (EPOLLET) and MSG_PEEK in recv(), causes sockets to enter a permanent half-read…
- risk 0.35cvss 6.5epss 0.00
A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading…
- risk 0.38cvss 5.9epss 0.00
Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to gaining access to unauthorized data.
- risk 0.35cvss 6.5epss 0.00
libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a…
- risk 0.64cvss 9.8epss 0.01
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.
- risk 0.47cvss 7.2epss 0.02
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this…
- risk 0.59cvss 9.1epss 0.02
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…
- risk 0.25cvss 4.9epss 0.01
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP process by injecting @import (inline) directives into LESS source that the backend…
- risk 0.60cvss 9.3epss 0.00
An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component
- risk 0.35cvss 6.5epss 0.00
Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including credential-bearing agent options, to…
- risk 0.21cvss 4.3epss 0.00
Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowing an authenticated user with…
- risk 0.49cvss 7.5epss 0.01
Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.
- risk 0.60cvss —epss 0.00
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error…
- risk 0.64cvss 9.8epss 0.00
An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file.
- risk 0.49cvss 7.5epss 0.00
Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
- risk 0.64cvss 9.8epss 0.00
Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint
- risk 0.57cvss —epss 0.00
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device…
- risk 0.50cvss 8.8epss 0.01
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special…
- risk 0.28cvss 5.4epss 0.00
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget trusted an attacker-controlled file_id POST parameter when resolving the attachment it operates on, allowing an authenticated…
- risk 0.48cvss 7.4epss 0.00
An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18
- risk 0.44cvss 6.8epss 0.01
Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from…
- risk 0.47cvss 7.2epss 0.00
The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config…
- risk 0.37cvss 6.8epss 0.00
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any single CMS permission to act…
- risk 0.31cvss 5.9epss 0.00
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configured with a conditions key, allowing an…
- risk 0.57cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy.
- risk 0.39cvss 7.1epss 0.00
CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.
- risk 0.64cvss 9.8epss 0.00
Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.
- risk 0.00cvss —epss —
### Summary An HTML Injection vulnerability exists in the user group creation functionality that allows an attacker to inject arbitrary HTML content into the application interface. The vulnerability occurs when user-supplied input in the group name field is not properly…
- CVE-2026-80153Aug 26, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- risk 0.39cvss —epss 0.00
Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated backend user to invoke arbitrary controller…
- risk 0.46cvss 8.1epss 0.00
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered…
- risk 0.46cvss 8.1epss 0.00
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and…
- risk 0.50cvss 8.8epss 0.00
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address parameter in the /ajax_table.php API endpoint.
- risk 0.50cvss 8.8epss 0.00
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects address-search.inc.php,…
- risk 0.50cvss 8.8epss 0.01
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.
- risk 0.46cvss 8.1epss 0.00
Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is…
- risk 0.53cvss 8.1epss 0.00
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it records, and the data-layer…
- risk 0.42cvss 6.5epss 0.00
Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp.go assigns a TLS configuration whose skip-verify field is set to true unconditionally, directly beneath a comment stating that the setting should be false in…
- risk 0.34cvss 5.3epss 0.00
Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js looks the address up and chains a not-found throw onto the query, so an address…
- risk 0.64cvss 9.8epss 0.00
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and writing gflags alongside status…
- risk 0.47cvss 7.2epss 0.00
IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves the authenticated user from the request that…
- risk 0.35cvss 6.5epss 0.00
Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in mage_ai/api/resources/BrowserItemResource.py passes a caller-supplied path to the filesystem read and write helpers without calling the containment helper that…
- risk 0.46cvss 8.1epss 0.01
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the…
- risk 0.32cvss 4.9epss 0.01
ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration loader in server/WebApi.cpp builds each root with File::absolutePath("", item, true); because the…
- risk 0.55cvss 8.5epss 0.00
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after model.IsAdmin succeeds and…