| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-64384 | Cri | 0.57 | 9.8 | 0.00 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cleanup retains the… | ||
| CVE-2026-64383 | Cri | 0.57 | 9.8 | 0.00 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received and the retry then fails before… | ||
| CVE-2026-64355 | Cri | 0.57 | 9.8 | 0.01 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination. For native XDP, that clone path copies only the linear xdp_frame data, while fragmented… | ||
| CVE-2026-64320 | Cri | 0.52 | 9.1 | 0.01 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo). The 64-bit offset is then… | ||
| CVE-2026-64319 | Cri | 0.52 | 9.1 | 0.01 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen (DH value length)… | ||
| CVE-2026-64303 | Cri | 0.57 | 9.8 | 0.01 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path When dmaengine_prep_slave_sg() fails for the TX channel, the error path terminates the TX DMA channel but leaves the RX channel running.… | ||
| CVE-2026-64269 | Cri | 0.52 | 9.1 | 0.01 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE that returns data to… | ||
| CVE-2026-64268 | Cri | 0.57 | 9.8 | 0.01 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr + wqe->processed and then… | ||
| CVE-2026-64257 | Cri | 0.52 | 9.1 | 0.01 | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception… | ||
| CVE-2026-16766 | Cri | 0.57 | 9.8 | 0.03 | Jul 25, 2026 | Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-controlled options such as the page_size,… | ||
| CVE-2026-16280 | Cri | 0.64 | 9.8 | 0.01 | Jul 24, 2026 | An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical… | ||
| CVE-2026-61884 | Cri | 0.64 | 9.8 | 0.01 | Jul 24, 2026 | The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and… | ||
| CVE-2026-62835 | Cri | 0.00 | 9.3 | 0.01 | Jul 24, 2026 | Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-48021 | Cri | 0.00 | 9.1 | 0.00 | Jul 24, 2026 | In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions,… | ||
| CVE-2026-64232 | Cri | 0.57 | 9.8 | 0.00 | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "the queue settings related to segment… | ||
| CVE-2026-64216 | Cri | 0.57 | 9.8 | 0.01 | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is wanting to unlock and compares that to rreq->no_unlock_folio so… | ||
| CVE-2026-58630 | Cri | 0.65 | 10.0 | 0.01 | Jul 24, 2026 | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-58586 | Cri | 0.00 | 9.8 | 0.01 | Jul 24, 2026 | Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. … | ||
| CVE-2026-57106 | Cri | 0.00 | 10.0 | 0.01 | Jul 24, 2026 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-56163 | Cri | 0.00 | 10.0 | 0.01 | Jul 24, 2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-12503 | Cri | 0.00 | — | 0.00 | Jul 24, 2026 | Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege… | ||
| CVE-2026-16634 | Cri | 0.00 | 9.8 | 0.01 | Jul 24, 2026 | TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker. Any caller that passes untrusted TOML to… | ||
| CVE-2026-24727 | Cri | 0.00 | — | 0.01 | Jul 24, 2026 | An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted… | ||
| CVE-2026-15704 | Cri | 0.00 | 9.8 | 0.01 | Jul 24, 2026 | In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's… | ||
| CVE-2026-12877 | Cri | 0.00 | 9.1 | 0.00 | Jul 24, 2026 | The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project… | ||
| CVE-2026-62825 | Cri | 0.65 | 10.0 | 0.01 | Jul 24, 2026 | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-58275 | Cri | 0.65 | 10.0 | 0.01 | Jul 24, 2026 | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-56191 | Cri | 0.00 | 10.0 | 0.01 | Jul 24, 2026 | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2026-56165 | Cri | 0.00 | 9.8 | 0.01 | Jul 24, 2026 | Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-56160 | Cri | 0.59 | 9.1 | 0.01 | Jul 24, 2026 | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-54120 | Cri | 0.64 | 9.9 | 0.01 | Jul 24, 2026 | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | ||
| CVE-2026-50517 | Cri | 0.00 | 9.9 | 0.02 | Jul 24, 2026 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | ||
| CVE-2026-42933 | Cri | 0.65 | 10.0 | 0.01 | Jul 23, 2026 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation. | ||
| CVE-2026-63732 | Cri | 0.00 | 9.9 | 0.01 | Jul 23, 2026 | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn()… | ||
| CVE-2025-71389 | Cri | 0.58 | 10.0 | 0.01 | Jul 23, 2026 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to… | ||
| CVE-2024-58354 | Cri | 0.57 | 9.9 | 0.00 | Jul 23, 2026 | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to… | ||
| CVE-2026-52439 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism | ||
| CVE-2026-47724 | Cri | 0.57 | 9.9 | 0.00 | Jul 23, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits this at `internal/api/hosts.go:384`: "API… | ||
| CVE-2026-15981 | Cri | 0.00 | 9.8 | 0.02 | Jul 23, 2026 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's… | ||
| CVE-2026-15630 | Cri | 0.64 | 9.9 | 0.00 | Jul 23, 2026 | A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body). | ||
| CVE-2026-63359 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and… | ||
| CVE-2026-47670 | Cri | 0.54 | — | 0.02 | Jul 23, 2026 | DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the… | ||
| CVE-2026-47669 | Cri | 0.53 | — | 0.01 | Jul 23, 2026 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes… | ||
| CVE-2026-6516 | Cri | 0.00 | 10.0 | 0.05 | Jul 23, 2026 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. | ||
| CVE-2026-65701 | Cri | 0.00 | 9.1 | 0.01 | Jul 23, 2026 | SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the… | ||
| CVE-2026-65700 | Cri | 0.00 | 9.8 | 0.02 | Jul 23, 2026 | h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The… | ||
| CVE-2026-47752 | Cri | 0.00 | 9.9 | 0.01 | Jul 23, 2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed… | ||
| CVE-2026-47668 | Cri | 0.58 | 10.0 | 0.04 | Jul 23, 2026 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated… | ||
| CVE-2026-44210 | Cri | 0.57 | 9.9 | 0.01 | Jul 23, 2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into… | ||
| CVE-2026-65761 | Cri | 0.00 | — | 0.01 | Jul 23, 2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions. |
- risk 0.57cvss 9.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cleanup retains the…
- risk 0.57cvss 9.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received and the retry then fails before…
- risk 0.57cvss 9.8epss 0.01
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination. For native XDP, that clone path copies only the linear xdp_frame data, while fragmented…
- risk 0.52cvss 9.1epss 0.01
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Page Offset (lpo). The 64-bit offset is then…
- risk 0.52cvss 9.1epss 0.01
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (hash length) and dhvlen (DH value length)…
- risk 0.57cvss 9.8epss 0.01
In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path When dmaengine_prep_slave_sg() fails for the TX channel, the error path terminates the TX DMA channel but leaves the RX channel running.…
- risk 0.52cvss 9.1epss 0.01
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE that returns data to…
- risk 0.57cvss 9.8epss 0.01
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr + wqe->processed and then…
- risk 0.52cvss 9.1epss 0.01
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception…
- risk 0.57cvss 9.8epss 0.03
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-controlled options such as the page_size,…
- risk 0.64cvss 9.8epss 0.01
An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical…
- risk 0.64cvss 9.8epss 0.01
The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and…
- risk 0.00cvss 9.3epss 0.01
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 9.1epss 0.00
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions,…
- risk 0.57cvss 9.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "the queue settings related to segment…
- risk 0.57cvss 9.8epss 0.01
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages() netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it is wanting to unlock and compares that to rreq->no_unlock_folio so…
- risk 0.65cvss 10.0epss 0.01
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
- risk 0.00cvss 9.8epss 0.01
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863. …
- risk 0.00cvss 10.0epss 0.01
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
- risk 0.00cvss 10.0epss 0.01
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
- risk 0.00cvss —epss 0.00
Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege…
- risk 0.00cvss 9.8epss 0.01
TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker. Any caller that passes untrusted TOML to…
- risk 0.00cvss —epss 0.01
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted…
- risk 0.00cvss 9.8epss 0.01
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's…
- risk 0.00cvss 9.1epss 0.00
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project…
- risk 0.65cvss 10.0epss 0.01
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
- risk 0.00cvss 10.0epss 0.01
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
- risk 0.59cvss 9.1epss 0.01
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.01
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
- risk 0.00cvss 9.9epss 0.02
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
- risk 0.65cvss 10.0epss 0.01
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.
- risk 0.00cvss 9.9epss 0.01
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn()…
- risk 0.58cvss 10.0epss 0.01
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to…
- risk 0.57cvss 9.9epss 0.00
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to…
- risk 0.00cvss 9.8epss 0.01
An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism
- risk 0.57cvss 9.9epss 0.00
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits this at `internal/api/hosts.go:384`: "API…
- risk 0.00cvss 9.8epss 0.02
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's…
- risk 0.64cvss 9.9epss 0.00
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
- risk 0.00cvss 9.8epss 0.01
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and…
- risk 0.54cvss —epss 0.02
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the…
- risk 0.53cvss —epss 0.01
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes…
- risk 0.00cvss 10.0epss 0.05
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
- risk 0.00cvss 9.1epss 0.01
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the…
- risk 0.00cvss 9.8epss 0.02
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The…
- risk 0.00cvss 9.9epss 0.01
Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed…
- risk 0.58cvss 10.0epss 0.04
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated…
- risk 0.57cvss 9.9epss 0.01
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into…
- risk 0.00cvss —epss 0.01
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions.