| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32561 | Hig | 0.57 | 8.8 | 0.00 | Aug 24, 2026 | Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions. | ||
| CVE-2026-32560 | Hig | 0.57 | 8.8 | 0.00 | Aug 24, 2026 | Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions. | ||
| CVE-2026-32559 | Cri | 0.64 | 9.9 | 0.00 | Aug 24, 2026 | Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. | ||
| CVE-2026-32556 | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. | ||
| CVE-2026-32555 | Cri | 0.60 | 9.3 | 0.00 | Aug 24, 2026 | Unauthenticated SQL Injection in Boost <= 2.0.4 versions. | ||
| CVE-2026-32554 | Cri | 0.60 | 9.3 | 0.00 | Aug 24, 2026 | Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. | ||
| CVE-2026-27364 | Med | 0.42 | 6.5 | 0.00 | Aug 24, 2026 | Subscriber Broken Access Control in Style Kits <= 2.6.5 versions. | ||
| CVE-2026-17113 | Med | 0.32 | 6.0 | 0.00 | Aug 24, 2026 | A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI `Envs` field, CRI-O falls… | ||
| CVE-2026-7455 | Hig | 0.51 | 7.8 | 0.00 | Aug 24, 2026 | A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | ||
| CVE-2026-77635 | Cri | 0.53 | — | 0.00 | Aug 24, 2026 | CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This… | ||
| CVE-2026-77634 | Hig | 0.46 | — | 0.01 | Aug 24, 2026 | CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection… | ||
| CVE-2026-77567 | Hig | 0.46 | 8.1 | 0.01 | Aug 24, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based… | ||
| CVE-2026-75554 | Low | 0.08 | — | 0.00 | Aug 24, 2026 | Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from an organization to keep reading its private packages. expand_repositories_scope/3 in lib/hexpm/permissions.ex only rewrites the literal repositories scope,… | ||
| CVE-2026-75542 | Hig | 0.47 | — | 0.00 | Aug 24, 2026 | Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages. When an API key is exchanged for a token through the OAuth client_credentials grant,… | ||
| CVE-2026-75464 | Hig | 0.46 | 8.1 | 0.00 | Aug 24, 2026 | OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link(). | ||
| CVE-2026-5006 | Med | 0.37 | 6.8 | 0.00 | Aug 24, 2026 | A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced… | ||
| CVE-2026-56136 | Med | 0.24 | 4.7 | 0.00 | Aug 24, 2026 | In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file… | ||
| CVE-2026-56135 | Hig | 0.41 | 7.4 | 0.00 | Aug 24, 2026 | In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by… | ||
| CVE-2026-55468 | Med | 0.21 | 4.3 | 0.00 | Aug 24, 2026 | Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user… | ||
| CVE-2026-52492 | Hig | 0.44 | 7.8 | 0.00 | Aug 24, 2026 | An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image | ||
| CVE-2026-52490 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2026 | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c | ||
| CVE-2026-19568 | Hig | 0.51 | 7.8 | 0.00 | Aug 24, 2026 | A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | ||
| CVE-2026-16783 | Hig | 0.51 | 7.8 | 0.00 | Aug 24, 2026 | A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | ||
| CVE-2026-16782 | Med | 0.34 | 5.3 | 0.00 | Aug 24, 2026 | A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | ||
| CVE-2026-16781 | Med | 0.36 | 5.5 | 0.00 | Aug 24, 2026 | A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. | ||
| CVE-2022-30983 | Med | 0.40 | 6.1 | 0.00 | Aug 24, 2026 | A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter. | ||
| CVE-2026-78555 | Cri | 0.54 | — | 0.00 | Aug 24, 2026 | RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each key, the full token was embedded in hidden form fields used by the enable/disable,… | ||
| CVE-2026-78553 | Hig | 0.39 | — | 0.00 | Aug 24, 2026 | RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was created using the process's default permissions and umask, resulting in permissions such as 0644 under a common 022 umask. Consequently, other local… | ||
| CVE-2026-78551 | Hig | 0.50 | — | 0.01 | Aug 24, 2026 | RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and potentially exhaust application worker resources. For local authentication, the… | ||
| CVE-2026-78430 | Med | 0.35 | 5.3 | 0.01 | Aug 24, 2026 | A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of the argument format results in os command injection. Attacking locally is a… | ||
| CVE-2026-77923 | Med | 0.21 | 4.3 | 0.00 | Aug 24, 2026 | Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authenticated users with project… | ||
| CVE-2026-77310 | Med | 0.27 | 5.3 | 0.00 | Aug 24, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of… | ||
| CVE-2026-76816 | Low | 0.16 | 3.5 | 0.00 | Aug 24, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, allowing prohibited null bytes in MQTT UTF-8… | ||
| CVE-2026-76098 | Hig | 0.42 | 7.5 | 0.00 | Aug 24, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in… | ||
| CVE-2026-75509 | Med | 0.35 | 6.5 | 0.00 | Aug 24, 2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the… | ||
| CVE-2026-75369 | — | Hig | 0.46 | 7.1 | 0.00 | Aug 24, 2026 | An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message. | |
| CVE-2026-75368 | Hig | 0.49 | 7.5 | 0.00 | Aug 24, 2026 | A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted ECSS TC message. | ||
| CVE-2026-72714 | Med | 0.41 | 6.3 | 0.00 | Aug 24, 2026 | Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local Unset Universe Checking inside a module is expected to last only until the module ends, and the global flag is restored, but the… | ||
| CVE-2026-72711 | Med | 0.34 | 6.3 | 0.00 | Aug 24, 2026 | The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and theorem paths perform, so a value containing a free variable that is absent from the local context is not… | ||
| CVE-2026-72705 | Med | 0.34 | 6.3 | 0.00 | Aug 24, 2026 | The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass itself as a higher-order argument to a second fixpoint, which then applies it to a value that is not a subterm of the structural argument. Passing the… | ||
| CVE-2026-72704 | Med | 0.34 | 6.3 | 0.00 | Aug 24, 2026 | The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by transport. A fixpoint may apply a rewrite along an equality between types to its recursive argument, which the guard… | ||
| CVE-2026-72703 | Med | 0.34 | 6.3 | 0.00 | Aug 24, 2026 | The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that fixpoint. find_uniform_parameters in kernel/inductive.ml inspects only self-recursive calls, so when no body calls itself the… | ||
| CVE-2026-71511 | Med | 0.35 | 6.5 | 0.00 | Aug 24, 2026 | Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can call the individual member or member list… | ||
| CVE-2026-71510 | Med | 0.35 | 6.5 | 0.00 | Aug 24, 2026 | Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column restrictions. Attackers can… | ||
| CVE-2026-63693 | Med | 0.43 | 6.6 | 0.00 | Aug 24, 2026 | Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write | ||
| CVE-2026-61419 | Hig | 0.51 | 7.8 | 0.00 | Aug 24, 2026 | Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. | ||
| CVE-2020-37268 | Med | 0.41 | 6.3 | 0.00 | Aug 24, 2026 | Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter, and the inlining drops the record that… | ||
| CVE-2026-78541 | Hig | 0.55 | — | 0.02 | Aug 24, 2026 | A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during… | ||
| CVE-2026-78417 | Med | 0.28 | 4.3 | 0.00 | Aug 24, 2026 | Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key… | ||
| CVE-2026-75371 | — | Hig | 0.49 | 7.5 | 0.00 | Aug 24, 2026 | An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input. |
- risk 0.57cvss 8.8epss 0.00
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
- risk 0.57cvss 8.8epss 0.00
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
- risk 0.32cvss 6.0epss 0.00
A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI `Envs` field, CRI-O falls…
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
- risk 0.53cvss —epss 0.00
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This…
- risk 0.46cvss —epss 0.01
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF bytes removed, allowing header injection…
- risk 0.46cvss 8.1epss 0.01
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based…
- risk 0.08cvss —epss 0.00
Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from an organization to keep reading its private packages. expand_repositories_scope/3 in lib/hexpm/permissions.ex only rewrites the literal repositories scope,…
- risk 0.47cvss —epss 0.00
Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages. When an API key is exchanged for a token through the OAuth client_credentials grant,…
- risk 0.46cvss 8.1epss 0.00
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
- risk 0.37cvss 6.8epss 0.00
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced…
- risk 0.24cvss 4.7epss 0.00
In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file…
- risk 0.41cvss 7.4epss 0.00
In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by…
- risk 0.21cvss 4.3epss 0.00
Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user…
- risk 0.44cvss 7.8epss 0.00
An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image
- risk 0.64cvss 9.8epss 0.01
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
- risk 0.51cvss 7.8epss 0.00
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
- risk 0.34cvss 5.3epss 0.00
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
- risk 0.36cvss 5.5epss 0.00
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service.
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter.
- risk 0.54cvss —epss 0.00
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each key, the full token was embedded in hidden form fields used by the enable/disable,…
- risk 0.39cvss —epss 0.00
RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was created using the process's default permissions and umask, resulting in permissions such as 0644 under a common 022 umask. Consequently, other local…
- risk 0.50cvss —epss 0.01
RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and potentially exhaust application worker resources. For local authentication, the…
- risk 0.35cvss 5.3epss 0.01
A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of the argument format results in os command injection. Attacking locally is a…
- risk 0.21cvss 4.3epss 0.00
Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authenticated users with project…
- risk 0.27cvss 5.3epss 0.00
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of…
- risk 0.16cvss 3.5epss 0.00
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, allowing prohibited null bytes in MQTT UTF-8…
- risk 0.42cvss 7.5epss 0.00
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in…
- risk 0.35cvss 6.5epss 0.00
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the…
- risk 0.46cvss 7.1epss 0.00
An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.
- risk 0.49cvss 7.5epss 0.00
A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted ECSS TC message.
- risk 0.41cvss 6.3epss 0.00
Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local Unset Universe Checking inside a module is expected to last only until the module ends, and the global flag is restored, but the…
- risk 0.34cvss 6.3epss 0.00
The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and theorem paths perform, so a value containing a free variable that is absent from the local context is not…
- risk 0.34cvss 6.3epss 0.00
The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass itself as a higher-order argument to a second fixpoint, which then applies it to a value that is not a subterm of the structural argument. Passing the…
- risk 0.34cvss 6.3epss 0.00
The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by transport. A fixpoint may apply a rewrite along an equality between types to its recursive argument, which the guard…
- risk 0.34cvss 6.3epss 0.00
The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that fixpoint. find_uniform_parameters in kernel/inductive.ml inspects only self-recursive calls, so when no body calls itself the…
- risk 0.35cvss 6.5epss 0.00
Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can call the individual member or member list…
- risk 0.35cvss 6.5epss 0.00
Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column restrictions. Attackers can…
- risk 0.43cvss 6.6epss 0.00
Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write
- risk 0.51cvss 7.8epss 0.00
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
- risk 0.41cvss 6.3epss 0.00
Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter, and the inlining drops the record that…
- risk 0.55cvss —epss 0.02
A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during…
- risk 0.28cvss 4.3epss 0.00
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key…
- risk 0.49cvss 7.5epss 0.00
An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input.