| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-57170 | Hig | 0.44 | 7.8 | 0.00 | Aug 26, 2026 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown… | ||
| CVE-2026-54467 | Hig | 0.46 | 7.0 | 0.00 | Aug 26, 2026 | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer. | ||
| CVE-2026-52776 | Hig | 0.49 | — | 0.00 | Aug 26, 2026 | Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypassed to reach… | ||
| CVE-2026-29988 | Hig | 0.49 | 7.6 | 0.00 | Aug 26, 2026 | A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D… | ||
| CVE-2026-19632 | Cri | 0.57 | 9.8 | 0.09 | Aug 26, 2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated… | ||
| CVE-2026-74749 | mod | 0.29 | 5.5 | 0.00 | Aug 26, 2026 | kernel: rseq: Prevent hard lockup on granted time slice extension | ||
| CVE-2026-80529 | mod | 0.29 | 5.5 | 0.00 | Aug 26, 2026 | kernel: xfs: don't swallow dquot recovery verification errors | ||
| CVE-2026-80532 | low | 0.29 | 5.5 | 0.00 | Aug 26, 2026 | kernel: xfs: fix another iunlink infinite loop bug in online fsck | ||
| CVE-2026-80533 | low | 0.29 | 5.5 | 0.00 | Aug 26, 2026 | kernel: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair | ||
| CVE-2026-80535 | low | 0.29 | 5.5 | 0.00 | Aug 26, 2026 | kernel: xfs: don't double-lock when deleting a self-referential directory | ||
| CVE-2026-80138 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary… | ||
| CVE-2026-79912 | Hig | 0.54 | 8.3 | 0.02 | Aug 25, 2026 | A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely.… | ||
| CVE-2026-79911 | Cri | 0.65 | 10.0 | 0.01 | Aug 25, 2026 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer… | ||
| CVE-2026-70665 | Med | 0.20 | 4.2 | 0.00 | Aug 25, 2026 | Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured… | ||
| CVE-2026-55805 | Med | 0.28 | 5.4 | 0.00 | Aug 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from… | ||
| CVE-2026-54757 | Hig | 0.44 | 7.8 | 0.00 | Aug 25, 2026 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote code execution. This occurs… | ||
| CVE-2026-44476 | Med | 0.34 | — | 0.01 | Aug 25, 2026 | Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its… | ||
| CVE-2026-41707 | Hig | 0.48 | 7.4 | 0.00 | Aug 25, 2026 | Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict… | ||
| CVE-2026-18985 | Hig | 0.46 | 8.1 | 0.00 | Aug 25, 2026 | Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. | ||
| CVE-2026-18261 | Med | 0.37 | 5.7 | 0.00 | Aug 25, 2026 | Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*. | ||
| CVE-2026-18260 | Med | 0.30 | 5.7 | 0.00 | Aug 25, 2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4. | ||
| CVE-2026-18259 | Hig | 0.42 | 7.5 | 0.00 | Aug 25, 2026 | Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2. | ||
| CVE-2026-16646 | Med | 0.37 | 5.7 | 0.00 | Aug 25, 2026 | Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*. | ||
| CVE-2026-16645 | Cri | 0.52 | 9.1 | 0.00 | Aug 25, 2026 | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0. | ||
| CVE-2026-16644 | Cri | 0.52 | 9.1 | 0.00 | Aug 25, 2026 | Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0. | ||
| CVE-2026-16643 | Med | 0.37 | 5.7 | 0.00 | Aug 25, 2026 | Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*. | ||
| CVE-2026-16642 | Med | 0.37 | 5.7 | 0.00 | Aug 25, 2026 | Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. | ||
| CVE-2026-16641 | Cri | 0.64 | 9.8 | 0.00 | Aug 25, 2026 | Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*. | ||
| CVE-2026-16640 | Med | 0.40 | 6.1 | 0.00 | Aug 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0. | ||
| CVE-2026-16639 | Cri | 0.64 | 9.8 | 0.00 | Aug 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0. | ||
| CVE-2026-16638 | Med | 0.33 | 6.1 | 0.00 | Aug 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8. | ||
| CVE-2026-15917 | Med | 0.24 | 4.7 | 0.00 | Aug 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*. | ||
| CVE-2026-15916 | Med | 0.20 | 4.2 | 0.00 | Aug 25, 2026 | Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. | ||
| CVE-2026-15088 | Med | 0.37 | 5.7 | 0.00 | Aug 25, 2026 | Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*. | ||
| CVE-2026-80186 | Hig | 0.49 | 7.6 | 0.01 | Aug 25, 2026 | A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth… | ||
| CVE-2026-80185 | Med | 0.37 | 5.7 | 0.00 | Aug 25, 2026 | BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd. | ||
| CVE-2026-80184 | Hig | 0.42 | — | 0.01 | Aug 25, 2026 | In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an… | ||
| CVE-2026-80182 | Hig | 0.42 | — | 0.01 | Aug 25, 2026 | In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain… | ||
| CVE-2026-79845 | Hig | 0.47 | 7.3 | 0.00 | Aug 25, 2026 | A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The… | ||
| CVE-2026-79804 | Hig | 0.47 | 7.3 | 0.00 | Aug 25, 2026 | A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation of the argument search_box results in sql injection. Remote… | ||
| CVE-2026-78655 | Cri | 0.59 | 9.1 | 0.01 | Aug 25, 2026 | Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session. The POST handler on challenge_path keeps the failure count as tries inside the… | ||
| CVE-2026-78619 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2026 | Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the recovery model for the submitted code's digest alone, across every user's… | ||
| CVE-2026-73180 | Med | 0.44 | 6.8 | 0.00 | Aug 25, 2026 | Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as… | ||
| CVE-2026-68763 | Hig | 0.42 | 7.5 | 0.01 | Aug 25, 2026 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The… | ||
| CVE-2026-68569 | Hig | 0.53 | 8.1 | 0.01 | Aug 25, 2026 | Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from… | ||
| CVE-2026-68525 | Cri | 0.52 | 9.1 | 0.01 | Aug 25, 2026 | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1… | ||
| CVE-2026-66422 | Hig | 0.53 | 8.1 | 0.01 | Aug 25, 2026 | Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through… | ||
| CVE-2026-65927 | Hig | 0.42 | 7.5 | 0.01 | Aug 25, 2026 | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through… | ||
| CVE-2026-65905 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is… | ||
| CVE-2026-65637 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2026 | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version… |
- risk 0.44cvss 7.8epss 0.00
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown…
- risk 0.46cvss 7.0epss 0.00
On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.
- risk 0.49cvss —epss 0.00
Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypassed to reach…
- risk 0.49cvss 7.6epss 0.00
A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D…
- risk 0.57cvss 9.8epss 0.09
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated…
- risk 0.29cvss 5.5epss 0.00
kernel: rseq: Prevent hard lockup on granted time slice extension
- risk 0.29cvss 5.5epss 0.00
kernel: xfs: don't swallow dquot recovery verification errors
- risk 0.29cvss 5.5epss 0.00
kernel: xfs: fix another iunlink infinite loop bug in online fsck
- risk 0.29cvss 5.5epss 0.00
kernel: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
- risk 0.29cvss 5.5epss 0.00
kernel: xfs: don't double-lock when deleting a self-referential directory
- risk 0.57cvss 9.8epss 0.01
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary…
- risk 0.54cvss 8.3epss 0.02
A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely.…
- risk 0.65cvss 10.0epss 0.01
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer…
- risk 0.20cvss 4.2epss 0.00
Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured…
- risk 0.28cvss 5.4epss 0.00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from…
- risk 0.44cvss 7.8epss 0.00
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote code execution. This occurs…
- risk 0.34cvss —epss 0.01
Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its…
- risk 0.48cvss 7.4epss 0.00
Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict…
- risk 0.46cvss 8.1epss 0.00
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.
- risk 0.37cvss 5.7epss 0.00
Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.
- risk 0.30cvss 5.7epss 0.00
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
- risk 0.42cvss 7.5epss 0.00
Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.
- risk 0.37cvss 5.7epss 0.00
Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.
- risk 0.52cvss 9.1epss 0.00
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.
- risk 0.52cvss 9.1epss 0.00
Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.
- risk 0.37cvss 5.7epss 0.00
Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.
- risk 0.37cvss 5.7epss 0.00
Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
- risk 0.64cvss 9.8epss 0.00
Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
- risk 0.40cvss 6.1epss 0.00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.
- risk 0.64cvss 9.8epss 0.00
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
- risk 0.33cvss 6.1epss 0.00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8.
- risk 0.24cvss 4.7epss 0.00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*.
- risk 0.20cvss 4.2epss 0.00
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.
- risk 0.37cvss 5.7epss 0.00
Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.
- risk 0.49cvss 7.6epss 0.01
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth…
- risk 0.37cvss 5.7epss 0.00
BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.
- risk 0.42cvss —epss 0.01
In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an…
- risk 0.42cvss —epss 0.01
In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation of the argument search_box results in sql injection. Remote…
- risk 0.59cvss 9.1epss 0.01
Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session. The POST handler on challenge_path keeps the failure count as tries inside the…
- risk 0.64cvss 9.8epss 0.01
Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the recovery model for the submitted code's digest alone, across every user's…
- risk 0.44cvss 6.8epss 0.00
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as…
- risk 0.42cvss 7.5epss 0.01
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The…
- risk 0.53cvss 8.1epss 0.01
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from…
- risk 0.52cvss 9.1epss 0.01
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1…
- risk 0.53cvss 8.1epss 0.01
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through…
- risk 0.42cvss 7.5epss 0.01
Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through…
- risk 0.57cvss 9.8epss 0.01
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is…
- risk 0.57cvss 9.8epss 0.01
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version…