| python-tornado: Tornado before 6.3.3 HTTP Request Smuggling via Content-Length CVE-2023-54397 | Severity | NVD high Red Hat critical | 2026-10-06 | |
| ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authenticated users to read arbitrary files. The path parameter is not properly validated before being passed to output_file, enabling attackers with Events view permission to access sensitive files like configuration files containing database credentials. CVE-2024-58386 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| libarchive: libarchive: Denial of Service via heap-based buffer overflow in gzip writer CVE-2025-64031 | Severity | NVD low Red Hat medium | 2026-10-06 | |
| Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially by Kubernetes, but containerd adds a mount point for it when Kubernetes sets none, requiring the runtime to be able to push arbitrary data to the Kata agent. As a result, on bare-metal Contrast deployments (AKS deployments are not affected) that run an image declaring at least one VOLUME for which no Kubernetes mount exists at that path, the untrusted host can write arbitrary file trees below that mount point inside the confidential container, compromising the integrity of a directory that is typically important to the application's core functionality. Version 1.9.1 fixes the issue by disallowing this configuration in `contrast generate`. CVE-2025-71424 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files. CVE-2025-71427 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| kernel: netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet CVE-2026-100070 | Severity | GitHub advisories unknown Red Hat medium | 2026-10-06 | |
| kernel: net: hsr: free learned nodes on device setup failure CVE-2026-100071 | Severity | GitHub advisories unknown Red Hat low | 2026-10-06 | |
| kernel: ACPI: platform: Use acpi_bus_get_primary_device() CVE-2026-100072 | Severity | GitHub advisories unknown Red Hat medium | 2026-10-06 | |
| kernel: ext4: fix transaction overflow during writeback CVE-2026-100073 | Severity | GitHub advisories unknown Red Hat medium | 2026-10-06 | |
| In the Linux kernel, the following vulnerability has been resolved:
bpf: Mark bpf_refcount field as unique
BPF_REFCOUNT is not marked as a unique field, while it should be. Fix
this oversight. CVE-2026-100074 | Severity | GitHub advisories unknown NVD medium | 2026-10-06 | |
| kernel: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters CVE-2026-100075 | CVSS | GitHub advisories 9.8 NVD 9.8 Red Hat 5.5 | 2026-10-06 | |
| kernel: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters CVE-2026-100075 | Severity | GitHub advisories critical NVD critical Red Hat medium | 2026-10-06 | |
| kernel: staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths CVE-2026-100076 | Severity | GitHub advisories unknown NVD medium Red Hat medium | 2026-10-06 | |
| kernel: drm/msm: Recover HW before retire hung submit CVE-2026-100077 | Severity | GitHub advisories unknown NVD medium Red Hat medium | 2026-10-06 | |
| In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mei: pass correct argument to function
The first argument to iwl_mei_write_cyclic_buf() should be the cldev
but the q_head pointer is passed instead. Fix it. CVE-2026-100078 | Severity | GitHub advisories unknown NVD medium | 2026-10-06 | |
| kernel: usb: typec: ucsi: unregister debugfs entries on teardown CVE-2026-100079 | Severity | GitHub advisories unknown NVD medium Red Hat low | 2026-10-06 | |
| In JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 administrator account takeover was possible via password reset CVE-2026-100255 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address CVE-2026-100266 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates CVE-2026-100268 | Severity | GitHub advisories high NVD low | 2026-10-06 | |
| In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution CVE-2026-100273 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action CVE-2026-100276 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature CVE-2026-100277 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible CVE-2026-100280 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption. CVE-2026-100299 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| libextractor: libextractor: Privilege escalation via LIBEXTRACTOR_PREFIX environment variable CVE-2026-100310 | Severity | GitHub advisories high NVD high Red Hat medium | 2026-10-06 | |
| A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php. Performing a manipulation of the argument gname/editassid results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100312 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file updatequery.php. Executing a manipulation of the argument queryx can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100313 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromstudent.php. The manipulation of the argument eno leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100314 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file mydetailsfaculty.php. The manipulation of the argument myfid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100315 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed. CVE-2026-100389 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls. CVE-2026-100390 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate limiting, attempt counters, lockouts, or delays to gain full administrator access and modify application configuration. CVE-2026-100501 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with a specific x86-64 sequence that triggers the vulnerability during decompilation, causing the decompile helper process to crash and denying service to analysts and automated analysis pipelines. CVE-2026-100503 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that allows attackers to reuse standing grants for unreviewed paths. Attackers can exploit glob metacharacter interpretation and node display name reuse to access sibling paths or different nodes beyond the operator's original approval scope. CVE-2026-100529 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks the share metadata used to prove it belongs to the requested conversation, the conversation-authorization check fails open. An authenticated caller restricted to a single conversation who knows or obtains a file identifier can therefore download file contents from outside that conversation's scope, disclosing data across configured conversation boundaries. The issue does not allow listing arbitrary Slack files and does not bypass Slack authentication itself. The issue is fixed in version 2026.8.1. CVE-2026-100531 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unvalidated host paths behind allowed attachment sources. Attackers can exploit this by providing multiple source fields to bypass sandbox path validation and cause Telegram delivery to read and send known host files that would otherwise be rejected. CVE-2026-100536 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySender policy when handling outbound attachments. A sender that has been explicitly denied filesystem read tools can still cause a known local file to be read and returned via a final-response media directive or a message attachment, disclosing local file contents to an admitted requester whose agent turn did not include the read tool. Exploitation requires knowledge or derivation of a useful host path and a delivery flow that accepts local attachments. The issue is fixed in version 2026.8.1. CVE-2026-100538 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it for model tool operations. Attackers can exploit multi-account setups where a disabled default account retains credentials to read or modify Feishu resources through a revoked identity. CVE-2026-100540 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by iOS system trust can serve a replacement Control UI page; opening the Terminal or a session Dashboard then allows that page to read the injected Gateway token or password. The stolen credential can grant operator access, including reading sensitive Gateway state and invoking host-capable tools. This issue is fixed in 2026.8.11. CVE-2026-100551 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorization when a paired node is revoked. Node revocation invalidates the WebSocket client, but Canvas HTTP authorization continues to accept and renew the previously granted capability until WebSocket close cleanup completes. As a result, a revoked paired node can continue exercising its Canvas capability against the capability's configured routes during the close grace period. The issue is fixed in 2026.8.1; as a workaround, restart the Gateway after revoking a node that has Canvas access. CVE-2026-100554 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows sandboxed coding-agent sessions to invoke tools explicitly denied by sandbox.tools.deny policy. Attackers can list and invoke denied tools to access data or perform actions the operator intended to exclude from the sandbox. CVE-2026-100573 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DNS checks. For fetches that use the trusted-host DNS recheck, a trusted hostname that resolves to an unspecified address (0.0.0.0 or ::) bypasses the SSRF destination validation. An attacker who can influence DNS for an allowed hostname can therefore cause a guarded fetch to reach a service bound only to loopback and disclose its response; the practical impact depends on the reachable service and the data it returns. Fixed in 2026.8.1. CVE-2026-100574 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a steered agent with access to a channel read action can therefore retrieve content or metadata from channels or rooms excluded by the operator's read policy; the practical impact depends on the permissions held by the connected bot account. The issue is fixed in 2026.8.1. CVE-2026-100582 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers can access prompts, model messages, tool schemas, runtime events, and local path metadata from affected sessions by exploiting insufficient authorization checks. CVE-2026-100594 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host diagnostic bundles. Attackers can request and receive diagnostic details about the host, configuration, runtime, and connected services intended only for owners. CVE-2026-100595 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A signed-in caller can invoke the public skills:generateChangelogPreview action for a skill they are not authorized to access; the previous version is read without the file-read authorization enforced on normal content access, and up to 8,000 characters of quarantined content may be submitted to the AI provider and reflected in the preview returned to the caller, disclosing restricted skill content. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. It is fixed by PR #3682, included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650, which was deployed to clawhub.ai on 2026-09-11; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected. CVE-2026-100602 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that skill from the catalog without any moderator decision. Because the reporter quota counts only reports filed against visible targets, the same accounts can repeat the process against additional skills; official skills are not exempt. The issue was confirmed at revision cbfee7343ddc867316dd9b3de6fa8856730f9f41; the complete historical affected range was not established. The fix (PR #3681) is included in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650; self-hosted deployments should update to that revision or a later descendant. The npm CLI and OpenClaw runtime are separate products and are not affected. CVE-2026-100603 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED, verifyAndLogin (SSOBase.ts:80-94) copies the user record from the database — including the server-stored single-use invitation tempToken — into the data passed to AccountService.register(). The register handler's token lookup, email match, and expiry checks therefore pass trivially against the server's own token instead of a caller-supplied one, and the account and its organization membership are flipped to ACTIVE. As a result, anyone able to authenticate at any configured SSO provider using a pending invitee's email address as the email claim can take over that invitation and obtain the invited user's access to the organization without ever possessing the emailed invitation token, for as long as the invitation is valid (24 hours by default). At the time of the advisory no patched version was available. CVE-2026-100606 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifier bindings, allowing attackers to authenticate as any existing user by claiming their email at any configured SSO provider. Attackers can gain complete account access including chatflows, credentials, and API keys by authenticating through a different SSO provider or local password than the victim's original registration method. CVE-2026-100607 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting user's workspace (findOneBy({ id: credentialId }) with no workspaceId condition) in several code paths: getAllOpenaiAssistants/getSingleOpenaiAssistant (GET /api/v1/openai-assistants and /api/v1/openai-assistants/:id), uploadFilesToAssistant (POST /api/v1/openai-assistants-file/upload/), deleteAssistant (DELETE /api/v1/assistants/:id, reachable by first importing a poisoned assistant row via POST /api/v1/export-import/import), and the shared helper used by getVoices (GET /api/v1/text-to-speech/voices). An authenticated user of one workspace can supply a credential UUID belonging to another workspace, causing the server to decrypt and use that workspace's OpenAI or ElevenLabs API key on the attacker's behalf. No patched version was available at the time of publication. CVE-2026-100609 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly created API keys. When an authenticated user holding only apikey_manager (permissions org.manage_apikeys and org.read) calls POST /apikey with a JWT session, the only checks applied are the org.manage_apikeys permission, a fixed deny-list of assignable role names (APIKEY_MANAGER_DENIED_ASSIGNABLE_ROLES in public/apikey/scope.ts), and a priority-rank comparison in createRoleBindingForPrincipal (private/role_bindings.ts). No check verifies that the caller actually holds the permissions conferred by the role being assigned. Because the deny-list omits the deploy roles app_developer, app_uploader, channel_developer and channel_uploader, and apikey_manager is seeded with priority_rank 78 — higher than those roles' ranks (68, 66, 58, 57) — the rank check also passes. As a result, an apikey_manager who cannot upload bundles or promote channels can mint an API key bound to a deploy role and use it to push arbitrary OTA JavaScript updates to all end users of the organization's apps. As of the advisory publication no patched version was available. CVE-2026-100611 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| capgo.app is an over-the-air update platform for Capacitor apps. In all versions prior to a fix, the row-level security UPDATE policy on the public.orgs table permits an organization admin (a user holding org.update_settings) to update the entire row, including the internal billing pointer column customer_id. The official organization update endpoint (supabase/functions/_backend/public/organization/put.ts) allowlists only a small set of editable settings fields and excludes customer_id, and the private Stripe billing route separately requires the org.update_billing permission. By sending an update directly to Supabase PostgREST, an authenticated org admin without org.update_billing can null or corrupt the organization's Stripe customer pointer, causing plan and billing checks that trust orgs.customer_id to fail and moving the organization from a valid paid plan state to unpaid/no-plan behavior. At the time of the advisory no patched version was available. CVE-2026-100616 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated Google Play service account with the account-wide Play Console permission CAN_MANAGE_DRAFT_APPS_GLOBAL (passed as developerAccountPermissions in the Android Publisher API User create request), even though the user-facing flow states the service account is invited into a single confirmed app with release-only permissions. As a result, anyone who obtains the generated service account key (PLAY_CONFIG_JSON) can create, edit, and delete draft apps across the entire Google Play developer account rather than being limited to the selected package. No patched version was available at the time of publication. CVE-2026-100620 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys. In the POST /apikey endpoint, requests that supply app_id but omit org_id, limited_to_orgs, and expires_at resolve the target app and scope the key to it, but never add the app's owner organization to the list of organization IDs passed to validateExpirationAgainstOrgPolicies; because that list is empty, the validation returns early. As a result, an authenticated organization member can create a non-expiring app-scoped API key even when the owning organization has require_apikey_expiration enabled and a max_apikey_expiration_days limit configured. The issue is fixed in version 12.128.12. CVE-2026-100628 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a subscription does not supply its own session token the event payload is redacted against an anonymous identity even though the read was authorized against the connected user. As a result, field masks defined for a role, for authenticated users, or for a specific user are not applied, so an authenticated subscriber can receive field values that the REST API correctly withholds and can use a masked field to filter or watch a subscription. Only classes with LiveQuery enabled that define protectedFields under a role:, authenticated, or per-user group are affected; masks under the public (*) group are applied correctly. The issue is fixed in 9.10.1-alpha.8 and 8.6.89. As a workaround, additionally define the affected field masks under the public (*) group, or disable LiveQuery for classes whose class-level permissions rely on role-scoped, authenticated, or per-user protectedFields groups. CVE-2026-100632 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensitive-path guard (util.IsForbiddenAbsPath(), invoked from resolvePath()) is applied only to the allowed root of recursive operations and not to each resolved descendant path — an incomplete fix for GHSA-c8r8-95hg-mp34. An authenticated administrator using the in-app Agent or the external MCP server can therefore bypass the protected-workspace-file denylist: file.grep can return matching lines from non-hidden protected descendants (for example conf/conf.json, TLS keys, data/snippets/conf.json, data/templates/, data/.siyuan/publishAccess.json, notebook .siyuan internals, or the kernel log), file.copy can copy protected descendants to an ordinary path where file.read can then retrieve them, and unzip can overwrite protected descendants using ordinary, lexically contained ZIP member names. Because file.grep is globally classified as a safe action, it receives no per-call confirmation, and the confirmation cards for file.copy and unzip show only the allowed root arguments. This issue is fixed in version 3.8.4. Suggested title: SiYuan 3.8.0 through 3.8.3 Sensitive-Path Guard Bypass in Recursive MCP File Operations. CVE-2026-100633 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP connections. An on-path attacker can observe a valid publish-visitor-session-id cookie from a Basic Auth exchange and replay it to access authenticated publish endpoints without knowing the account password. CVE-2026-100635 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to access native clipboard formats by invoking clipboardReadMathML, clipboardReadOffice, and clipboardReadWPS commands with matching plaintext. Attackers controlling remote renderer content can obtain MathML formulas, Office bytes, and WPS bytes from local clipboard during user-mediated paste operations. CVE-2026-100640 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| vllm: vLLM: Denial of Service via unbounded media ingestion CVE-2026-100650 | Severity | GitHub advisories high NVD medium Red Hat high | 2026-10-06 | |
| vllm: vLLM: Denial of Service via out-of-bounds stop token IDs CVE-2026-100652 | Severity | GitHub advisories high NVD medium Red Hat high | 2026-10-06 | |
| io.netty/netty-codec-http: Netty: HTTP response desynchronization via HttpServerCodec CVE-2026-100666 | Severity | GitHub advisories medium NVD high Red Hat high | 2026-10-06 | |
| Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on the sandbox allowlist but is registered without the needs_is_sandboxed guard that print_r, vardump, json_encode, yaml_encode and string carry, and its implementation calls toArray() — or falls back to an (array) cast — without consulting the sandbox method allowlist. Because the `grav` Twig global is the raw Pimple-based dependency injection container, a user who can author Twig in page content can evaluate `grav|array` to read the container's private $values array, including the un-redacted Config service; a second array cast returns the entire configuration tree, disclosing plugin credentials, SMTP and OAuth secrets, Redis passwords, proxy URLs and the security.* subtree that the sandbox's redaction is meant to hide. Because the payload is stored in page content, the disclosed configuration is rendered to anonymous visitors. Grav 1.7 is not affected as it has no Twig content sandbox. Fixed in Grav 2.0.25. CVE-2026-100668 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes mass mention messages. Authenticated users can send five crafted role-mention messages to terminate all acknowledgement workers, disabling push notifications and mention badges deployment-wide until the API process restarts. CVE-2026-100675 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access. CVE-2026-100678 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and without an email_verified check (the email_verified gate protects only the existing-account lookup). An attacker who can register at an IdP that the tenant trusts for OIDC and assert a victim's invited email address (even with email_verified=false) claims the pending invite and inherits all of its granted privileges, including builder and admin.global, with no admin exclusion. This results in takeover of the invited principal and, for admin invites, full tenant compromise (access to all apps, datasources including production credentials, and automations); the invite is consumed, denying onboarding to the legitimate invitee. CVE-2026-100684 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete operations. CVE-2026-100687 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage endpoint that allows authenticated users to read another tenant's application metadata and source code. Attackers can supply a victim tenant's app id to retrieve sensitive application details including navigation structure, role names, internal screen URLs, JavaScript snippets, and user identifiers without authorization checks. CVE-2026-100688 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| github.com/gohugoio/hugo: Hugo: Arbitrary file read via symbolic link sandbox escape CVE-2026-100690 | CVSS | GitHub advisories 7.5 NVD 7.5 Red Hat 5.5 | 2026-10-06 | |
| github.com/gohugoio/hugo: Hugo: Arbitrary file read via symbolic link sandbox escape CVE-2026-100690 | Severity | GitHub advisories high NVD high Red Hat medium | 2026-10-06 | |
| github.com/gohugoio/hugo: Hugo: Information disclosure via symlinked mount roots CVE-2026-100692 | CVSS | GitHub advisories 7.5 NVD 7.5 Red Hat 5.5 | 2026-10-06 | |
| github.com/gohugoio/hugo: Hugo: Information disclosure via symlinked mount roots CVE-2026-100692 | Severity | GitHub advisories high NVD high Red Hat medium | 2026-10-06 | |
| github.com/gohugoio/hugo: Hugo: Security restriction bypass via mixed-case URL schemes CVE-2026-100693 | CVSS | GitHub advisories 8.4 NVD 8.4 Red Hat 4 | 2026-10-06 | |
| github.com/gohugoio/hugo: Hugo: Security restriction bypass via mixed-case URL schemes CVE-2026-100693 | Severity | GitHub advisories high NVD high Red Hat medium | 2026-10-06 | |
| Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example http://127.0.0.1:18089), causing the Adminer server to issue an HTTP POST containing 'SELECT version()' to that host. In rootQuery(), if the target returns a status outside 200-299 (other than 401/403), the raw HTTP response body is assigned to the connection error and rendered on the login page, so the attacker receives the full response body of the internal service. This enables internal network/port reconnaissance and disclosure of sensitive information contained in internal error pages (stack traces, internal hostnames, file paths, configuration identifiers). Fixed in Adminer 6.0.2. CVE-2026-100697 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET request to the 2FA management page (e.g. /customer_index.php?page=2fa&action=delete), with no confirmation, re-authentication, or CSRF token. The global CSRF middleware only covers POST/PUT/PATCH/DELETE requests, and the session cookie is set to SameSite=Lax, so a cross-site top-level navigation (link click or redirect) carries the victim's session and silently clears type_2fa/data_2fa. Both the customer and admin 2FA handlers are affected. An attacker who lures a logged-in panel user into following a crafted link reduces that account to password-only authentication, which can be chained with a compromised password for account takeover. Fixed in 2.3.12. CVE-2026-100712 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because makeCorrectDir() appends a trailing slash, GNU rm dereferences a symlink used either as an intermediate path component or as the final component. An authenticated customer who can write to the FTP home directory can plant a symlink between task insertion and cron execution, causing the root cron job to recursively delete arbitrary directory trees, resulting in cross-tenant data destruction and host denial of service. This issue is fixed in Froxlor 2.3.12. CVE-2026-100715 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or change_serversettings privilege required) can supply a subdomain redirect URL that carries a CR/LF payload in the userinfo portion (e.g. http://user%0areturn 200 "pwned";%0a@evil.com/). The value passes validation, survives IDNA encoding, and is written verbatim into the generated nginx or Apache vhost configuration, allowing the attacker to break out of the emitted directive and inject arbitrary web-server configuration lines. froxlor regenerates and reloads the web-server configuration as root, so the injected directives take effect server-wide and can hijack responses or read local files. The issue is fixed in version 2.3.12. CVE-2026-100717 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that returns htpasswd password hashes. Authenticated API users can retrieve bcrypt password hashes for protected-directory users, enabling offline cracking attempts and exposure of reused credentials. CVE-2026-100719 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O']) value verbatim without sanitization. Froxlor's table-listing renderer then emits scalar cells through Twig's `raw` filter, disabling HTML auto-escaping, so when an administrator or reseller opens Domains > SSL certificates the attacker-supplied issuer value executes as script in the privileged user's session. This crosses a privilege boundary from customer to admin and can result in full administrator account takeover; because a Froxlor admin controls webserver, DNS, and PHP configuration applied by a cron job running as root, the issue can be further escalated to command execution as root on the managed server. The issue is fixed in Froxlor 2.3.12. CVE-2026-100720 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| vm2: vm2: Denial of Service via unhandled Promise rejection in construct trap CVE-2026-100722 | Severity | GitHub advisories high NVD medium Red Hat medium | 2026-10-06 | |
| vm2: vm2: Information disclosure via zlib shared buffer pool CVE-2026-100723 | Severity | GitHub advisories medium NVD high Red Hat high | 2026-10-06 | |
| http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping rules for the cookie domain, path, and Secure attributes. When a single BasicCookieStorage instance is used to talk to more than one origin or scheme, cookies stored for one origin can be sent to other origins, and cookies marked Secure can be sent over plain HTTP, potentially disclosing session cookies or other sensitive values to unauthorized hosts or network observers. Clients that use a storage instance for a single origin are not affected. CVE-2026-100725 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file viewresult.php. Performing a manipulation of the argument seno results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100739 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used. CVE-2026-100740 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 4.2.0 is sufficient to fix this issue. This patch is called 39ae16de4248075de8c08f3259114e064b20d52d. It is advisable to upgrade the affected component. CVE-2026-100744 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform/formWizSurvey of the component Wireless Wizard Handler. The manipulation of the argument interface1/interface2 leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. CVE-2026-100745 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results in missing authentication. The attack can be executed remotely. The exploit has been made public and could be used. Upgrading to version 4.1.1 mitigates this issue. The patch is identified as fc89e357feed5180ed1ab5eb9cb330578f025539. The affected component should be upgraded. CVE-2026-100746 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| firefox: Privilege escalation due to use-after-free in the Graphics: WebGPU component CVE-2026-100761 | CVSS | GitHub advisories 8.8 NVD 8.8 Red Hat 7.5 | 2026-10-06 | |
| firefox: Sandbox escape due to use-after-free in the DOM: Content Processes component CVE-2026-100762 | CVSS | GitHub advisories 9.6 NVD 9.6 Red Hat 7.5 | 2026-10-06 | |
| firefox: Sandbox escape due to use-after-free in the DOM: Content Processes component CVE-2026-100762 | Severity | GitHub advisories critical NVD critical Red Hat high | 2026-10-06 | |
| firefox: Use-after-free in the Graphics: WebGPU component CVE-2026-100768 | CVSS | GitHub advisories 8.8 NVD 8.8 Red Hat 7.5 | 2026-10-06 | |
| firefox: Sandbox escape due to use-after-free in the DOM: Content Processes component CVE-2026-100770 | CVSS | GitHub advisories 9.6 NVD 9.6 Red Hat 7.5 | 2026-10-06 | |
| firefox: Sandbox escape due to use-after-free in the DOM: Content Processes component CVE-2026-100770 | Severity | GitHub advisories critical NVD critical Red Hat high | 2026-10-06 | |
| firefox: Use-after-free in the DOM: Core & HTML component CVE-2026-100774 | CVSS | GitHub advisories 8.8 NVD 8.8 Red Hat 7.5 | 2026-10-06 | |
| firefox: Sandbox escape due to use-after-free in the DOM: Core & HTML component CVE-2026-100778 | CVSS | GitHub advisories 9.6 NVD 9.6 Red Hat 7.5 | 2026-10-06 | |
| firefox: Sandbox escape due to use-after-free in the DOM: Core & HTML component CVE-2026-100778 | Severity | GitHub advisories critical NVD critical Red Hat high | 2026-10-06 | |
| firefox: Use-after-free in the Layout: Text and Fonts component CVE-2026-100784 | CVSS | GitHub advisories 8.8 NVD 8.8 Red Hat 7.5 | 2026-10-06 | |
| firefox: Sandbox escape due to use-after-free in the Graphics component CVE-2026-100786 | CVSS | GitHub advisories 9.6 NVD 9.6 Red Hat 7.5 | 2026-10-06 | |
| firefox: thunderbird: Use-after-free in the Graphics: Canvas2D component CVE-2026-100789 | CVSS | GitHub advisories 8.8 NVD 8.8 Red Hat 7.5 | 2026-10-06 | |
| firefox: Use-after-free in the DOM: Core & HTML component CVE-2026-100791 | CVSS | GitHub advisories 8.8 NVD 8.8 Red Hat 7.5 | 2026-10-06 | |
| firefox: Privilege escalation due to use-after-free in the Graphics: WebRender component CVE-2026-100797 | CVSS | GitHub advisories 8.8 NVD 8.8 Red Hat 6.1 | 2026-10-06 | |
| firefox: Privilege escalation due to use-after-free in the Graphics: WebRender component CVE-2026-100797 | Severity | GitHub advisories high NVD high Red Hat medium | 2026-10-06 | |
| firefox: Sandbox escape due to use-after-free in the Disability Access APIs component CVE-2026-100800 | CVSS | GitHub advisories 9.6 NVD 9.6 Red Hat 6.1 | 2026-10-06 | |
| firefox: Sandbox escape due to use-after-free in the Disability Access APIs component CVE-2026-100800 | Severity | GitHub advisories critical NVD critical Red Hat medium | 2026-10-06 | |
| firefox: Sandbox escape due to use-after-free in the Preferences: Backend component CVE-2026-100804 | CVSS | GitHub advisories 9.6 NVD 9.6 Red Hat 6.1 | 2026-10-06 | |
| firefox: Sandbox escape due to use-after-free in the Preferences: Backend component CVE-2026-100804 | Severity | GitHub advisories critical NVD critical Red Hat medium | 2026-10-06 | |
| firefox: Race condition, use-after-free in the Audio/Video component CVE-2026-100805 | CVSS | GitHub advisories 7.5 NVD 7.5 Red Hat 6.1 | 2026-10-06 | |
| firefox: Race condition, use-after-free in the Audio/Video component CVE-2026-100805 | Severity | GitHub advisories high NVD high Red Hat medium | 2026-10-06 | |
| firefox: firefox: Sandbox escape via use-after-free in DOM component CVE-2026-100811 | CVSS | GitHub advisories 9.6 NVD 9.6 Red Hat 6.1 | 2026-10-06 | |
| firefox: Use-after-free in the CSS Parsing and Computation component CVE-2026-100815 | CVSS | GitHub advisories 8.8 NVD 8.8 Red Hat 6.1 | 2026-10-06 | |
| firefox: Use-after-free in the CSS Parsing and Computation component CVE-2026-100815 | Severity | GitHub advisories high NVD high Red Hat medium | 2026-10-06 | |
| firefox: thunderbird: Sandbox escape due to use-after-free in the Widget: Gtk component CVE-2026-100818 | CVSS | GitHub advisories 9.6 NVD 9.6 Red Hat 6.1 | 2026-10-06 | |
| firefox: thunderbird: Sandbox escape due to use-after-free in the Widget: Gtk component CVE-2026-100818 | Severity | GitHub advisories critical NVD critical Red Hat medium | 2026-10-06 | |
| firefox: Use-after-free in the DOM: UI Events & Focus Handling component CVE-2026-100831 | CVSS | GitHub advisories 8.8 NVD 8.8 Red Hat 3.4 | 2026-10-06 | |
| firefox: Use-after-free in the DOM: UI Events & Focus Handling component CVE-2026-100831 | Severity | GitHub advisories high NVD high Red Hat low | 2026-10-06 | |
| http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.0 defaults the nonceVerifier parameter of ServerFilters.DigestAuth and DigestAuthProvider to { true }, so every nonce is accepted regardless of its value, age, or prior use. Applications relying on this default have no replay protection on Digest authentication: an attacker who can capture a valid 'Authorization: Digest' response (for example by observing network traffic or reading logs) can replay it indefinitely against the same protected resource. CVE-2026-100834 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specific, physically trusted hardware. An attacker who can both intercept network traffic between the CLI and the Coordinator (or between the Coordinator and an attested component) and forge reports or extract secrets from any single TEE machine under their physical control can relay such a report to impersonate a Contrast Coordinator or a Contrast workload, defeating identity verification in Contrast's attested TLS (aTLS). CVE-2026-100835 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration in the imagepuller. Config.registryFor strips a single trailing dot and then uses strings.HasSuffix(hostname, fqdn) without requiring a DNS label boundary, so a registry entry such as [registries."ghcr.io."] is also applied to any host whose name merely ends in that byte sequence, including attacker-registered domains such as evilghcr.io. When an image or layer is pulled from such a sibling domain, the imagepuller sends the configured Authorization header (basic auth, registry token, or identity token), trusts the configured custom CA bundle, follows the configured mirror, and honours insecure-skip-verify (disabling TLS verification) for that host. Image integrity is not affected, as image bytes remain pinned by digest in the policy and are validated after the pull. Configurations that use a leading dot (e.g., [registries.".example.registry"]) are unaffected. CVE-2026-100837 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can create or update a playlist with source=remote_url and remote_type=playlist whose remote_url points at a file:// path or an internal/loopback/link-local HTTP endpoint. When AutoDJ builds the queue, the backend passes the user-supplied URL directly to file_get_contents() with no scheme allowlist and no private/loopback/metadata IP policy (PHP allow_url_fopen is enabled by default, including in the Docker image). Lines from the fetched resource are parsed as M3U/PLS entries, stored in StationQueue.autodj_custom_uri, and returned by GET /api/station/{station_id}/queue to any user with the Broadcasting permission, disclosing host files readable by the web container (for example /etc/passwd or the application .env) and the bodies of non-blind internal HTTP requests. No patched version was available at the time of publication. CVE-2026-100850 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allowing unauthenticated users to download media files excluded from On-Demand-enabled playlists. Attackers can bypass the station operator's intended access restrictions by directly requesting media via the download endpoint using valid media identifiers, exposing private or restricted audio content. CVE-2026-100853 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}/play endpoint that allows authenticated users to download media files from any station. Attackers can enumerate media files using sequential IDs and exfiltrate the complete media library of stations they lack permissions for. CVE-2026-100855 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nodes. These nodes issue HTTP requests to URLs taken from user-created credentials (webhook_url / flaresolverr_url) using an unguarded HTTP client, bypassing the SSRF egress guard that already protects the HTTP, WebSocket, and MCP nodes; the credential API validates only that the URL is non-empty. Any registered user can create a credential pointing at an internal address and execute a workflow, causing the backend to reach loopback, private, link-local, or cloud-metadata endpoints and return the full response body in the node output (non-blind SSRF). CVE-2026-100858 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that allows collaborators with shared credential access to exfiltrate the credential owner's secret. Attackers can override the destination URL in the config parameter to cause the server to send decrypted authentication secrets to attacker-controlled endpoints. CVE-2026-100859 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch. CVE-2026-100866 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. Attackers can embed ANSI/OSC escape sequences in version fields of package manifests to manipulate terminal output, rewrite window titles, or spoof displayed text when victims enter the directory. CVE-2026-100867 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that payment gateways execute while Sylius maintains order as paid, causing financial loss. CVE-2026-100869 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100873 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file addnewstudent.php. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100874 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromfaculty.php. Such manipulation of the argument myfid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100875 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file loginlinkstudent.php. Performing a manipulation of the argument umail results in missing authentication. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100876 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file registrationform.php. Executing a manipulation of the argument FName/LName/Addrs can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100877 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java of the component authRole Endpoint. The manipulation of the argument userId/roleIds leads to authorization bypass. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100878 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in missing authorization. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100879 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been published and may be used. Upgrading to version 2.2.6 is sufficient to fix this issue. This patch is called a399404a388d8ad2700a01349d0d98069c8e85a4. The affected component should be upgraded. CVE-2026-100883 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component. CVE-2026-100884 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this issue. The patch is identified as 89f2916b6a46ff91bd1999ce38158fa0de8b9490. Upgrading the affected component is recommended. CVE-2026-100885 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the component Database Query Builder. Performing a manipulation of the argument orderBy results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project maintainer confirms: "I stopped maintaining that project for a while now, so I'm not sure it's worth fixing." This vulnerability only affects products that are no longer supported by the maintainer. CVE-2026-100887 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100888 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100889 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100891 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100893 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument gname leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100894 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management Interface. This manipulation of the argument wlanif causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. CVE-2026-100896 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100898 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. This impacts the function whereRaw of the file app/Filament/Widgets/Timesheet/MonthlyReport.php of the component Timesheet Dashboard. Executing a manipulation of the argument filter can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100899 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/token leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100900 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Commit 6ffe823 'better security for public/stream.php' only added CURLOPT_PROTOCOLS http/https restriction and MAXREDIRS cap, does not restrict destination host. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100901 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security vulnerability has been detected in amirsanni mini-inventory-and-sales-management-system up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. Impacted is an unknown function of the file application/controllers/Items.php of the component Items Management Module. The manipulation of the argument itemName leads to cross site scripting. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-100904 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is sufficient to resolve this issue. The patch is identified as 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58. The affected component should be upgraded. CVE-2026-100909 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101002 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component. CVE-2026-101005 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it." CVE-2026-101006 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/server/panel/class/files.py of the component File Merge Handler. Performing a manipulation of the argument split_file_path results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101008 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /www/server/panel/class/data.py. The manipulation of the argument log_type leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101010 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the file /www/server/panel/mod/project/domain/domainMod.py of the component Domain Handler. The manipulation of the argument get results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101011 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101012 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101013 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| opendmarc: OpenDMARC: DMARC policy bypass via Unicode dot character equivalence in policy.c Domain Handler CVE-2026-101015 | CVSS | GitHub advisories 7.3 NVD 7.3 Red Hat 7.5 | 2026-10-06 | |
| opendmarc: OpenDMARC: DMARC policy bypass via Unicode dot character equivalence in policy.c Domain Handler CVE-2026-101015 | Severity | GitHub advisories medium NVD high Red Hat high | 2026-10-06 | |
| A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the file dayrui/App/Member/Controllers/Admin/Home.php of the component Group Editing. This manipulation of the argument groupid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101018 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This impacts the function path.join of the file /src/main/core/createParsedTrack.ts. The manipulation leads to path traversal. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101036 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the component devdiscover Service. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101037 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101038 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo) verify the client's authorization code with the external provider on signup and on provider linking, but not when authentication data is supplied together with a username and password on the login endpoint. As a result, a low-privileged authenticated user can attach an arbitrary, unverified provider identity to their own account without the provider ever being contacted, spoofing an external identity toward application logic that trusts the linked provider ID. An attacker can also pre-hijack accounts: by claiming the provider ID of a victim who has not yet linked that provider, the victim's later legitimate sign-in with that provider resolves to the attacker's account. Only deployments configuring one of the affected code-based auth adapters are impacted. Versions 9.10.1-alpha.10 and 8.6.91 fix the issue by running the adapter's credential verification on the login and challenge endpoints and rejecting a provider identity already linked to another user. As a workaround, disable the affected code-based auth adapters. CVE-2026-101042 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential IDs or have empty signing secrets. Remote unauthenticated attackers can send forged Slack events to known webhook URLs to trigger workflows with the owner's credentials. CVE-2026-101049 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook endpoints when credential_id is absent or secret_token is empty. Remote unauthenticated attackers can post forged Telegram updates to trigger workflows with the owner's configured credentials and execute actions on attacker-supplied input. CVE-2026-101050 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component JWT Token Handler. The manipulation with the input test leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101052 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa_supplicant.conf of the component TCP Service. Executing a manipulation of the argument path can lead to improper access controls. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101053 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensure_secure_url intentionally permits loopback HTTP for local development and native manuals bypassed the loopback check performed by the OpenAPI converter, an attacker who can serve a UTCP manual that a victim registers can cause the client to issue requests to services bound only to 127.0.0.1 on the victim host and have the response bodies returned to the caller (server-side request forgery). The http, sse and streamable_http protocols are all affected. Reach is limited to loopback, and exploitation further requires a loopback service that answers unauthenticated requests with useful data. Fixed in utcp-http 1.1.12, which rejects manuals fetched from a non-loopback origin that declare loopback tool URLs, keyed off the final post-redirect discovery URL. CVE-2026-101058 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable prefix check allowing bypass URLs like http://127.0.0.1.attacker.example, while the WebSocket plugin performs no URL validation despite documented security requirements. Attackers can force connections to internal services and cloud metadata endpoints by supplying malicious tool URLs in call templates, and receive configured API keys and OAuth tokens sent to attacker-controlled hosts. CVE-2026-101061 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101066 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101067 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101071 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101073 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101074 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. Such manipulation leads to improper isolation or compartmentalization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. It is advisable to implement a patch to correct this issue. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101078 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version 4.6.0 is able to mitigate this issue. The identifier of the patch is ac0384edc9dbea3b226edefcf50613bd8509134f. You should upgrade the affected component. CVE-2026-101080 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. CVE-2026-101081 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. Attackers can submit a crafted alert rule via the POST /api/v1/alert-rule endpoint to crash the dashboard process, which persists the rule and causes repeated crashes on restart, disabling all monitoring and control plane functionality. CVE-2026-101085 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execution or Agent configuration tasks to Agents within their authorization scope by exploiting the shared protobuf Task.Type namespace between service monitors and privileged operations. CVE-2026-101086 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions. CVE-2026-101104 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprofile_form of the file /create_profile of the component Profile Creation Endpoint. This manipulation of the argument fname causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. CVE-2026-101105 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component Questionnaire Audio Upload. The manipulation leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101142 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of the file /qm/cz.zoom.scorecard.webui.Scorecard/cz.zoom.scorecard.webui.Scorecard/QMBODownload. The manipulation results in information disclosure. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101143 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101144 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such manipulation of the argument Username leads to ldap injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101145 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.createAndSaveAudit of the file /qm/cz.zoom.scorecard.webui.Scorecard/QMUtilsService of the component GWT RPC Handler. Performing a manipulation results in information disclosure. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101146 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device Management API. This manipulation of the argument path causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101187 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak password recovery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101188 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw has been found in FastStone Image Viewer up to 8.3. The affected element is an unknown function of the component TGA Image Handler. Executing a manipulation can lead to out-of-bounds write. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101202 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in FastStone Image Viewer up to 8.3. The impacted element is an unknown function of the component 1bpp RLE Decoder. The manipulation leads to out-of-bounds write. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101203 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe of the component TGA Image Handler. The manipulation results in out-of-bounds read. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101204 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in FastStone Image Viewer up to 8.3. This impacts an unknown function of the component PCX Decoder. This manipulation causes out-of-bounds read. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101205 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of the argument firstLogin results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101260 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101261 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101262 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101263 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101264 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead to origin validation error. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101278 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101280 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c758677fc5272a73eff15ffdbf8afda1a6. Applying a patch is the recommended action to fix this issue. CVE-2026-101281 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| keycloak-services: keycloak-services: Unbounded metric series creation via idp tag on broker login endpoint CVE-2026-101333 | Severity | GitHub advisories low NVD low Red Hat medium | 2026-10-06 | |
| A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101354 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101858 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation of the argument cfg_id leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-101859 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction. CVE-2026-101879 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes. CVE-2026-101881 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable. CVE-2026-101889 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| axios: axios: Security control bypass via unapplied HTTP/2 proxy and DNS settings CVE-2026-101898 | Severity | GitHub advisories high Red Hat medium | 2026-10-06 | |
| axios: Axios: Server-Side Request Forgery via bypassed redirect restrictions in fetch adapter CVE-2026-101907 | Severity | GitHub advisories high Red Hat medium | 2026-10-06 | |
| gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: Denial of Service via use-after-free in binary heap erase_if CVE-2026-102010 | Severity | GitHub advisories high NVD high Red Hat medium | 2026-10-06 | |
| A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-102243 | Severity | GitHub advisories low NVD high | 2026-10-06 | |
| A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.0.36.3 is recommended to address this issue. The patch is named 2faff7b3823322a9cb6797973e6caf089386c354. The affected component should be upgraded. CVE-2026-102244 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-102245 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack may be launched remotely. The exploit is now public and may be used. CVE-2026-102247 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-102248 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument url/fileKey results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-102249 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop Handler. This manipulation of the argument saved_avatar causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 2.9.3 is recommended to address this issue. Patch name: c143e145caa600947e70a240e87f2fed889149d3. It is suggested to upgrade the affected component. CVE-2026-102261 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown function of the file manage-food.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-102263 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected by this issue is some unknown functionality of the file users.php. This manipulation of the argument Search causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 6406308df9771d2fd477b56dafe4878dd846df6e. Applying a patch is the recommended action to fix this issue. CVE-2026-102292 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. CVE-2026-102293 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixed-size buffers by sending oversized response headers. Attackers can send crafted HTTP responses with oversized status messages, Connection headers, Content-Type values, or multipart boundaries to corrupt parser state and crash the capture process or corrupt memory. CVE-2026-102296 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| chromium-browser: chromium-browser: UI misrepresentation in SignIn CVE-2026-102305 | CVSS | GitHub advisories 5.4 NVD 5.4 Red Hat 4.3 | 2026-10-06 | |
| chromium-browser: chromium-browser: Use after free in Bluetooth CVE-2026-102306 | CVSS | GitHub advisories 9.6 NVD 9.6 Red Hat 8.8 | 2026-10-06 | |
| chromium-browser: chromium-browser: Use after free in Bluetooth CVE-2026-102306 | Severity | GitHub advisories critical NVD critical Red Hat high | 2026-10-06 | |
| chromium-browser: chromium-browser: Uninitialized resource in Dawn CVE-2026-102307 | CVSS | GitHub advisories 4.7 NVD 4.7 Red Hat 7.4 | 2026-10-06 | |
| chromium-browser: chromium-browser: Uninitialized resource in Dawn CVE-2026-102307 | Severity | GitHub advisories medium NVD medium Red Hat high | 2026-10-06 | |
| chromium-browser: angle: chromium-browser: Information disclosure via uninitialized resource in ANGLE CVE-2026-102313 | CVSS | GitHub advisories 4.7 NVD 4.7 Red Hat 7.4 | 2026-10-06 | |
| chromium-browser: angle: chromium-browser: Information disclosure via uninitialized resource in ANGLE CVE-2026-102313 | Severity | GitHub advisories medium NVD medium Red Hat high | 2026-10-06 | |
| chromium-browser: chromium-browser: UI misrepresentation in TabStrip CVE-2026-102314 | CVSS | GitHub advisories 5.4 NVD 5.4 Red Hat 4.3 | 2026-10-06 | |
| chromium-browser: chromium-browser: UI misrepresentation in TabStrip CVE-2026-102314 | Severity | GitHub advisories medium NVD medium Red Hat low | 2026-10-06 | |
| chromium-browser: chromium-browser: Uninitialized resource in Media CVE-2026-102315 | CVSS | GitHub advisories 3.4 NVD 3.4 Red Hat 7.4 | 2026-10-06 | |
| chromium-browser: chromium-browser: Uninitialized resource in Media CVE-2026-102315 | Severity | GitHub advisories low NVD low Red Hat high | 2026-10-06 | |
| chromium-browser: chromium-browser: Use after free in Views CVE-2026-102316 | CVSS | GitHub advisories 9.6 NVD 9.6 Red Hat 8.8 | 2026-10-06 | |
| chromium-browser: chromium-browser: Use after free in Views CVE-2026-102316 | Severity | GitHub advisories critical NVD critical Red Hat high | 2026-10-06 | |
| chromium-browser: chromium-browser: Improper privilege management in Mojo CVE-2026-102317 | CVSS | GitHub advisories 8.6 NVD 8.6 Red Hat 8.8 | 2026-10-06 | |
| chromium-browser: chromium-browser: Uninitialized resource in GPU CVE-2026-102319 | CVSS | GitHub advisories 3.4 NVD 3.4 Red Hat 7.4 | 2026-10-06 | |
| chromium-browser: chromium-browser: Uninitialized resource in GPU CVE-2026-102319 | Severity | GitHub advisories low NVD low Red Hat high | 2026-10-06 | |
| chromium-browser: chromium-browser: Uninitialized resource in Skia CVE-2026-102325 | CVSS | GitHub advisories 4.3 NVD 4.3 Red Hat 6.5 | 2026-10-06 | |
| chromium-browser: angle: chromium-browser: arbitrary code execution via buffer overflow in ANGLE CVE-2026-102331 | Severity | GitHub advisories critical NVD critical Red Hat high | 2026-10-06 | |
| Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control. CVE-2026-102334 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification. CVE-2026-102363 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information. CVE-2026-102365 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the local storage path, resulting in stored cross-site scripting. CVE-2026-102366 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks. CVE-2026-102373 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents. CVE-2026-102456 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files. CVE-2026-102457 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| A vulnerability was identified in mahonelau kykms up to 8f130c2d85842d5b44caae78cc46d65e505949f7. The impacted element is the function QueryGenerator.doMultiFieldsOrder of the file QueryGenerator.java of the component SqlInjectionUtil. The manipulation of the argument column leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-102491 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an UPDATE statement without proper escaping. An authenticated administrator with video_moderation permission can inject arbitrary SQL commands to extract or modify database contents. CVE-2026-102569 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function where the language_id parameter is concatenated unescaped into the WHERE clause of an UPDATE statement. An authenticated administrator with basic_settings permission can inject arbitrary SQL payloads to extract or modify database contents. CVE-2026-102570 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database. CVE-2026-102578 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior. CVE-2026-102580 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface. CVE-2026-102582 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. Performing a manipulation of the argument year/processInstanceId results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The sink is injectable on two independent positions, not just one. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-102616 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators execute attacker-supplied code in their authenticated sessions. CVE-2026-102630 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, microphone, and GPS tracking. CVE-2026-102667 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the function MailController::templatePut of the file cmf-api/src/admin/controller/MailController.php of the component Email Template. The manipulation leads to improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-102771 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results in command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-102792 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonename causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-102793 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-102794 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
This CVE supersedes CVE-2026-41920, whose record listed the affected 9.x versions as 9.0.0 through 9.1.14 and the fixed version as 9.1.15. All 9.2.x releases before 9.2.15 are affected. CVE-2026-102795 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before being passed to malloc() and memset(). Attackers with shell access, including through MAVLink, can supply invalid byte count values to crash the flight controller. CVE-2026-102808 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers with shell access can supply an excessively large value to the -c option to trigger stack overflow and crash the flight controller. CVE-2026-102809 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| simple-git: simple-git unsafe-operation guard does not block trailer command configuration CVE-2026-102828 | Severity | GitHub advisories critical Red Hat high | 2026-10-06 | |
| A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the argument ADMIN_RS_KCFINDER leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-102842 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. Performing a manipulation of the argument gbr results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-102843 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Impacted is the function sistem.php::simpan of the file application/modules/admin/controllers/sistem.php of the component Configuration Handler. The manipulation of the argument tipe/title/content_setting results in improper authorization. The attack may be launched remotely. The exploit is now public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-102846 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. The affected element is the function kirim of the file application/modules/web/controllers/buku_tamu.php of the component Guest Book. This manipulation of the argument nama/email/pesan causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-102847 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of the argument command/shell leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-102874 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal services or cloud metadata endpoints. CVE-2026-102877 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-102906 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. CVE-2026-102908 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. CVE-2026-102909 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. CVE-2026-102910 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised. CVE-2026-102911 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. CVE-2026-102912 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. CVE-2026-102913 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| next: Next.js: Information disclosure via cache key omission in nested cache handlers CVE-2026-103004 | Severity | NVD medium Red Hat low | 2026-10-06 | |
| Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption. CVE-2026-103109 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103113 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment Management Endpoint. The manipulation of the argument Tables leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103114 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103115 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103116 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103117 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103229 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103230 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103231 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103232 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin Area. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103233 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retain victim credentials and redirect secrets to attacker-controlled hosts. CVE-2026-103247 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request. CVE-2026-103248 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Workflow authors can inject malicious script URLs that execute arbitrary JavaScript in the editor origin when other users open the node dropdown and click the external-link icon, with the payload persisting across workflow imports and shares. CVE-2026-103249 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in signed resume URL generation for Send-and-Wait approvals. Attackers with workflow creation permissions can mint valid approval URLs for gates in projects they cannot access by exploiting unresolved traversal sequences in caller-controlled node IDs, enabling cross-project approval forgery. CVE-2026-103254 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security and enabling unauthorized data access and modification. CVE-2026-103255 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access to user accounts even after the associated user changes their password. CVE-2026-103279 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Ghost versions 1.18.0 before 6.27.0 contain a server-side request forgery vulnerability in the webhooks feature that allows staff users to probe internal hosts. Attackers with staff privileges can craft webhook requests to access internal network resources from the Ghost server. CVE-2026-103287 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data. CVE-2026-103288 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized to view, resulting in disclosure of restricted comment data. CVE-2026-103289 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Ghost versions 6.14.0 through versions prior to 6.27.0 contain a path traversal vulnerability in the ImageSize service. Insufficient input validation of user-supplied file paths may allow authenticated staff users to access local files outside the intended data storage directories on the server. CVE-2026-103290 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges. CVE-2026-103473 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible CVE-2026-103489 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue. CVE-2026-103530 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been made public and could be used. Upgrading to version 1.7.2 will fix this issue. You should upgrade the affected component. CVE-2026-103533 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.2 is able to address this issue. The affected component should be upgraded. CVE-2026-103534 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103536 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103539 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation of the argument page_titles leads to improper neutralization of special elements used in a template engine. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103540 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the function Files::uploadFile of the file global/code/actions.php of the component Ajax Handler. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103541 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX Endpoint. This manipulation of the argument url causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-103542 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in itsourcecode Leave Management System 1.0. The affected element is an unknown function of the file /module/leavetype/controller.php. Such manipulation of the argument LEAVTID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. CVE-2026-103543 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al Provider Configuration Handler. Performing a manipulation results in exposure of data element to wrong session. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 15.0.0 is sufficient to resolve this issue. It is suggested to upgrade the affected component. CVE-2026-103544 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| In MongoDB Controllers for Kubernetes, insufficient validation of Ops Manager backup configuration may allow a user who can modify an OpsManager custom resource to cause unintended administrative changes in Ops Manager. This affects deployments using Enterprise Ops Manager backup reconciliation. CVE-2026-103546 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files. CVE-2026-103678 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is disabled, an attacker can supply a specially crafted Transport Neutral Encapsulation Format (TNEF) file with an excessive number of colliding attachment filenames, causing the numeric counter to write past the allocated memory buffer. This issue may result in an application crash, leading to a Denial of Service (DoS), or potentially arbitrary code execution. CVE-2026-103680 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended. CVE-2026-103687 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects unknown code of the file /module/leave/controller.php. Executing a manipulation of the argument LEAVEID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. CVE-2026-103690 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests. CVE-2026-103760 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server memory. CVE-2026-103765 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. CVE-2026-104052 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. CVE-2026-104053 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance. CVE-2026-104054 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. CVE-2026-104120 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. CVE-2026-104123 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform unauthorized deletion of hosted files without needing to read the code from the info endpoint. CVE-2026-104356 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner's mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work. CVE-2026-104424 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block, stalling every validating node for over 52 seconds. CVE-2026-104426 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block's hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks. CVE-2026-104427 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline. CVE-2026-104434 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance. CVE-2026-104436 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these actions with a chosen tag or page name to disclose the names and body-derived titles of ACL-restricted pages. CVE-2026-104438 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid accounts for targeted phishing or password-spraying. CVE-2026-104439 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submit a crafted entry with an attacker-controlled id_fiche matching an existing page, overwriting its body for mass defacement and content destruction. CVE-2026-104449 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| YesWiki before 4.6.7 contains a missing authorization flaw in the pointimage action (tools/attach/actions/pointimage.php), which saves content to an attacker-chosen page with write ACL checks bypassed. Unauthenticated attackers can POST pagetag, title, and description fields to any page rendering {{pointimage}} to append raw HTML or JavaScript to any wiki page, including pages whose write ACL restricts editing, causing stored cross-site scripting in viewers' and administrators' browsers. CVE-2026-104450 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl() that allows unauthenticated attackers to bypass the SSRF guard using 6to4, NAT64, or IPv4-compatible IPv6 addresses. Attackers can send a crafted Signature keyId to the public actor inbox route to reach cloud metadata, loopback services, or internal hosts. CVE-2026-104458 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/ci/update_config and api/archives to overwrite configuration and list, download, or delete backup archives. CVE-2026-104467 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private content and perform actions with the victim's privileges. CVE-2026-104469 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings. CVE-2026-104476 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The impacted element is an unknown function of the file confirm.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. CVE-2026-104606 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function get of the file edit_accounts.php. This manipulation of the argument user_id/patient_id/physician_id/discounts_id/services_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-104609 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. CVE-2026-104611 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| A vulnerability was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file script/academic/core/new_announcement.php of the component Announcement Module. The manipulation of the argument title/announcement results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. CVE-2026-104612 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. CVE-2026-104613 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. CVE-2026-104614 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. CVE-2026-104625 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of the argument img can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-104637 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| org.apache.struts/struts2-core: Apache Struts: Arbitrary code execution via expression injection in legacy RESTful action mapper CVE-2026-104711 | Severity | GitHub advisories unknown Red Hat high | 2026-10-06 | |
| org.apache.struts/struts2-core: Apache Struts: Denial of Service via resource amplification in tag library CVE-2026-104712 | Severity | GitHub advisories unknown Red Hat high | 2026-10-06 | |
| @opentelemetry/instrumentation-cassandra-driver: @opentelemetry/instrumentation-knex: @opentelemetry/instrumentation-mongoose: @opentelemetry/instrumentation-mysql: @opentelemetry/instrumentation-mysql2: @opentelemetry/instrumentation-oracledb: @opentelemetry/instrumentation-pg: @opentelemetry/instrumentation-tedious: opentelemetry-js-contrib: Information disclosure via default database username emission in telemetry data CVE-2026-104872 | CVSS | GitHub advisories 5.8 NVD 5.8 Red Hat 5.3 | 2026-10-06 | |
| FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack. CVE-2026-104905 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function setup_document_content_list/g_strdup_printf of the file backend/epub/epub-document.c of the component EPUB File Handler. This manipulation causes path traversal. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 4.6.6 is capable of addressing this issue. Patch name: a5aecea074e8564b7a22f1ce054b31ec862974b7. It is advisable to upgrade the affected component. One of the project maintainers explains, that "EPUB support was removed from Xreader and reimplemented in Xepub". CVE-2026-104982 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in Linux Mint Xreader up to 4.6.9. Impacted is the function g_file_get_child of the file shell/ev-window.c of the component PDF Attachment Saving Handler. Such manipulation of the argument attachment leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. One of the project maintainers closed this issue as "completed", because "EPUB support was removed from Xreader and reimplemented in Xepub". Code analysis indicates that this might be a misunderstanding of the situation. CVE-2026-104983 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages. CVE-2026-105086 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers. CVE-2026-105089 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-105096 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-105097 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. The manipulation of the argument status/page/count results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-105098 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests. CVE-2026-105113 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers can name any realm client in a forged hint to redirect victims to any registered post-logout URI, enabling phishing that borrows the OpenAM host's trust. CVE-2026-105118 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code can redeem it for a public client's tokens with any non-empty code_verifier. CVE-2026-105119 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files. CVE-2026-105125 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens. CVE-2026-105129 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls. CVE-2026-105130 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component. CVE-2026-105133 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation results in download of code without integrity check. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-105137 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. Affected by this issue is the function modmedalsubmit of the file upload/source/app/admin/child/medals/mod.php of the component Admin Medal Moderation. The manipulation of the argument delete results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-105146 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-105147 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-105148 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of the argument rating results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-105149 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security vulnerability has been detected in RainyGao DocSys up to 2.02.85. The affected element is the function DocController.doGetTmp of the file /Doc/doGetTmpFile.do of the component Document Controller. The manipulation of the argument path/fileName leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105157 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database Management. The manipulation of the argument url results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105158 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance. CVE-2026-105164 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. Performing a manipulation of the argument image-choice results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105166 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file admin/donate.php. Executing a manipulation of the argument location can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105167 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file admin/admin.php of the component Order Assignment Block. The manipulation of the argument order_id/delivery_person_id leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105168 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This impacts an unknown function of the file delivery/delivery.php of the component Take Order Handler. The manipulation of the argument order_id/delivery_person_id results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105169 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation of the argument sign causes missing authentication. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105170 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected by this vulnerability is an unknown functionality of the file admin/admin.php of the component Role Attribute Handler. Such manipulation of the argument Name leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Multiple endpoints are affected. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105171 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is some unknown functionality of the file /login1.php. Performing a manipulation of the argument User results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. CVE-2026-105172 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability has been found in Gerapy up to 0.9.13. This vulnerability affects the function project_create of the file gerapy/server/core/views.py of the component Project Management. The manipulation of the argument project_name leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is 6e481078cfba6388a67ca2d9792288405019ba3e. Applying a patch is the recommended action to fix this issue. CVE-2026-105174 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. The manipulation of the argument cmdschool results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. CVE-2026-105175 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /Admin/edit_class.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. CVE-2026-105176 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. The affected element is an unknown function of the file /Admin/add_drug.php of the component Drug Creation. Such manipulation of the argument txtname/cmdtype/txtusage/txtsideeffect/cmdcontraindication leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. CVE-2026-105177 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. The impacted element is the function mysqli_real_escape_string of the file /Admin/add_symptom.php of the component Symptom Creation. Performing a manipulation of the argument txtname results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. CVE-2026-105178 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in Jeebase 0.0.1. This vulnerability affects the function updateUser of the file /user/update/info of the component UserService. Executing a manipulation of the argument user/tempUser can lead to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105180 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in itsourcecode Online Admission System 1.0. This issue affects some unknown processing of the file register1.php. The manipulation of the argument fname leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. CVE-2026-105181 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=update. The manipulation of the argument Title results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. CVE-2026-105182 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. CVE-2026-105183 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The impacted element is an unknown function of the file /admin/creteria.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. CVE-2026-105184 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown function of the file /admin/examinee.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. CVE-2026-105185 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw has been found in itsourcecode Online Admission System 1.0. This impacts an unknown function of the file /new.php. Executing a manipulation of the argument schedid can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. CVE-2026-105186 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in itsourcecode Online Admission System 1.0. Affected is an unknown function of the file /admin/key.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. CVE-2026-105187 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover. CVE-2026-105211 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials. CVE-2026-105216 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses. CVE-2026-105218 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| gist: gist: Traffic interception and credential theft via improper TLS certificate validation CVE-2026-105221 | Severity | GitHub advisories critical NVD high Red Hat high | 2026-10-06 | |
| The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses. CVE-2026-105222 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic. CVE-2026-105223 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| A vulnerability was identified in osCommerce osCommerce2 up to 2.3.4.1. This affects the function include of the file includes/classes/payment.php of the component Payment Page. Such manipulation of the argument MODULE_PAYMENT_INSTALLED leads to code injection. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105225 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in osCommerce osCommerce2 up to 2.3.4.1. This vulnerability affects the function include of the file admin/newsletters.php of the component Newsletter Management. Performing a manipulation of the argument module results in code injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105226 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This issue affects some unknown processing of the file signup.php of the component User Registration Endpoint. Executing a manipulation of the argument email/name/gender can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105229 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Impacted is an unknown function of the file delivery/deliverymyord.php. The manipulation of the argument delivery_person_id/order_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105230 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is an unknown function of the file admin/signup.php of the component Admin Registration. The manipulation of the argument email/username/location results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105231 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file delivery/deliverysignup.php of the component Registration Page. This manipulation of the argument username/email/location causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105232 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file login.php of the component Login Flow. Such manipulation of the argument PHPSESSID leads to session fixiation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105233 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance. CVE-2026-105238 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=update. Performing a manipulation of the argument Subject results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. CVE-2026-105246 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=course. Executing a manipulation of the argument Subject can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. CVE-2026-105247 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue. CVE-2026-105249 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. CVE-2026-105253 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was identified in itsourcecode Online Admission System 1.0. Impacted is an unknown function of the file /admin/schoolyear.php. Such manipulation of the argument sy leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. CVE-2026-105254 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit is now public and may be used. CVE-2026-105286 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105287 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in feelec-yishu feelcrm-os 1.0.0. Affected by this vulnerability is the function IndexController::index of the file App/ThinkPHP/Common/functions.php of the component Crm Endpoint. Such manipulation of the argument redirect_url leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105288 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105290 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105291 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory. CVE-2026-105293 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy. CVE-2026-105294 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVE-2026-105307 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of the argument result_class leads to improper neutralization of directives in dynamically evaluated code. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.4.0 is able to address this issue. The name of the patch is eb05f193c9771a68dcc8cfac6674a0d48a52ee9d. It is suggested to upgrade the affected component. CVE-2026-105315 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in TallCMS up to 4.8.0. This affects an unknown function of the file packages/tallcms/cms/src/Filament/Pages/ThemeManager.php of the component PluginManager. Executing a manipulation can lead to code injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called fdc18f4c6a36134f8986ca1d7e4e97092e3deb93. It is best practice to apply a patch to resolve this issue. CVE-2026-105329 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function update_subaccount of the file php/controller.php of the component Account Administration. This manipulation of the argument user_id causes improper authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105382 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This impacts an unknown function of the file php/controller.php. Such manipulation of the argument transaction_idS leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105383 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was found in UNION HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected is an unknown function of the file patient_info.php. Performing a manipulation of the argument patient_id results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105384 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this vulnerability is an unknown functionality of the file transaction_details.php. Executing a manipulation of the argument transaction_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105385 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the function get of the file print.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105386 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105387 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A weakness has been identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function index of the file App/Feelcrm/Index/Controller/MemberController.class.php of the component Member Endpoint. This manipulation of the argument group_id causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105388 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security vulnerability has been detected in feelec-yishu feelcrm-os 1.0.0. This issue affects some unknown processing of the file App/Feelcrm/Crm/Controller/UploadController.class.php of the component UploadTicketFile Endpoint. Such manipulation of the argument cmd leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105389 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key
. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment." CVE-2026-105392 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_assemble_control/jaxrs/excel/upload/with/url of the component General Module. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105438 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component Ordering API. Performing a manipulation of the argument OrderNumber results in improper control of resource identifiers. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105444 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105468 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105469 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search Endpoint. The manipulation of the argument doctorname leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105470 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105471 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected element is an unknown function of the file book.php of the component Booking Handler. This manipulation of the argument Doctor/appointment causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105472 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d96368b61f6e0c21df51df. The affected component should be upgraded. CVE-2026-105486 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of the argument Name results in os command injection. The attack can be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance. CVE-2026-105487 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105571 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice List. Such manipulation of the argument memberId leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105572 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105573 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted element is an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/ParamController.java of the component Parameter Submit Management. The manipulation of the argument initPassword results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105610 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105621 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect authorization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. CVE-2026-105703 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used. CVE-2026-105704 | Severity | GitHub advisories medium NVD high | 2026-10-06 | |
| A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. CVE-2026-105705 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. CVE-2026-105706 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. CVE-2026-105708 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| docling: docling: Server-Side Request Forgery via improper URL validation CVE-2026-105743 | CVSS | NVD 4 Red Hat 3.7 | 2026-10-06 | |
| docling: docling: Server-Side Request Forgery via improper URL validation CVE-2026-105743 | Severity | NVD medium Red Hat low | 2026-10-06 | |
| docling: docling: Arbitrary file read and write via unrestricted TeX primitives in Tectonic engine CVE-2026-105744 | CVSS | NVD 7.5 Red Hat 7 | 2026-10-06 | |
| docling: docling: Arbitrary file read and write via unrestricted TeX primitives in Tectonic engine CVE-2026-105744 | Severity | NVD high Red Hat medium | 2026-10-06 | |
| docling: Docling: Information disclosure via local image file references CVE-2026-105748 | CVSS | NVD 4.3 Red Hat 3.3 | 2026-10-06 | |
| docling: Docling: Information disclosure via local image file references CVE-2026-105748 | Severity | NVD medium Red Hat low | 2026-10-06 | |
| docling: docling: Information disclosure via crafted OpenDocument image reference CVE-2026-105751 | Severity | GitHub advisories medium Red Hat low | 2026-10-06 | |
| curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack CVE-2026-13608 | Severity | NVD high Red Hat low | 2026-10-06 | |
| In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a partial wolfSSL_read() which is sometimes caused by a small user buffer passed in, then called wolfSSL_shutdown for a bidirectional close and attempted to wolfSSL_read() again while the peer continues trying to send data during the shutdown it would lead to a state where a potential heap-use-after free happened. CVE-2026-15442 | Severity | GitHub advisories low NVD medium | 2026-10-06 | |
| Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600).
This issue affects Protection and control IED manager (PCM600): through 2.14. CVE-2026-15952 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted ICNS RLE block CVE-2026-18090 | Severity | NVD medium Red Hat low | 2026-10-06 | |
| curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections CVE-2026-18924 | Severity | NVD critical Red Hat low | 2026-10-06 | |
| qt: qt: Denial of Service via empty image tag attribute in styled text CVE-2026-19395 | Severity | GitHub advisories medium Red Hat high | 2026-10-06 | |
| python: Use-after-free of a server-side SSLContext when sni_callback switches contexts CVE-2026-19445 | Severity | GitHub advisories critical Red Hat high | 2026-10-06 | |
| glibc: Buffer Overflow in strfmon right-justification padding CVE-2026-19499 | Severity | NVD high Red Hat medium | 2026-10-06 | |
| quarkus-oidc: Quarkus OIDC: Cross-tenant authentication bypass via shared token-introspection cache CVE-2026-19625 | Severity | NVD medium Red Hat high | 2026-10-06 | |
| curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication CVE-2026-19931 | Severity | NVD critical Red Hat medium | 2026-10-06 | |
| ghostscript: ghostscript: Heap buffer overflow via JPEG 2000 output adapter CVE-2026-39919 | Severity | NVD critical Red Hat medium | 2026-10-06 | |
| libxfont2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client CVE-2026-44950 | Severity | NVD critical Red Hat high | 2026-10-06 | |
| suricata: Suricata http2: protocol-change type confusion can lead to denial of service CVE-2026-45764 | Severity | NVD critical Red Hat high | 2026-10-06 | |
| artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0 CVE-2026-49363 | Severity | NVD high Red Hat medium | 2026-10-06 | |
| wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof CVE-2026-49364 | Severity | NVD critical Red Hat high | 2026-10-06 | |
| github.com/osrg/gobgp: GoBGP: Malformed BGP OPEN message can disrupt BGP sessions CVE-2026-49837 | Severity | NVD medium Red Hat high | 2026-10-06 | |
| freetype: Integer overflow in FreeType tt_face_colr_blend_layer() leads to heap buffer overflow during COLR font rendering CVE-2026-49919 | Severity | NVD high Red Hat medium | 2026-10-06 | |
| A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locations attribute of an image in the queued state by sending a crafted HTTP PATCH request CVE-2026-51772 | Severity | GitHub advisories high, unknown NVD medium | 2026-10-06 | |
| langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing route accepts raw Python source and forwards it into a server-side compile/exec validation path without any visible entitlement guard. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.9.3. langflow contains a code injection vulnerability in validate-post_validate_code-a-real-authenticated-http-post-to-api-v1 (src/backend/base/langflow/api/v1/validate.py:13). An authenticated attacker can execute arbitrary Python code on the server by submitting malicious code to the /api/v1/validate/code endpoint, which directly executes user-supplied code without sandboxing or security controls. CVE-2026-51886 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function CVE-2026-51996 | Severity | GitHub advisories critical, unknown NVD critical | 2026-10-06 | |
| ffmpeg: out-of-bounds read due to missing required padding in WMA extradata allocation paths CVE-2026-52296 | Severity | NVD low Red Hat medium | 2026-10-06 | |
| ffmpeg: out-of-bounds read due to insufficiently padded extradata in the MOV parsing path CVE-2026-52297 | Severity | NVD low Red Hat medium | 2026-10-06 | |
| artemis-server: Apache Artemis — session hijack via missing authentication CVE-2026-57967 | Severity | NVD critical Red Hat high | 2026-10-06 | |
| libxfont2: Font Server Client encoding[] Out-Of-Bounds Read/Write CVE-2026-59679 | Severity | NVD critical Red Hat high | 2026-10-06 | |
| zookeeper: Apache ZooKeeper: Information disclosure via SetWatches reconnect replay CVE-2026-59739 | Severity | NVD high Red Hat medium | 2026-10-06 | |
| zabbix: Zabbix: Denial of service via null byte input in binary items CVE-2026-59783 | Severity | GitHub advisories low Red Hat medium | 2026-10-06 | |
| cyrus-imapd: cyrus-imapd: VPATCH BYPARAM double-free in CalDAV CVE-2026-61915 | Severity | NVD high Red Hat medium | 2026-10-06 | |
| Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/Controllers/Api/UploadedFilesController.php show() path does not apply the safe-inline allowlist used by the equivalent web controller, so the browser can process an attacker-controlled xml-stylesheet reference and execute JavaScript generated by the stylesheet in the Snipe-IT origin. A victim who is authorized to view the object must open the attachment URL, after which the script can read same-origin data and perform authenticated actions with the victim's privileges. This issue is fixed in version 8.7.0. CVE-2026-63498 | Severity | GitHub advisories high NVD medium | 2026-10-06 | |
| The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability. CVE-2026-63713 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system. CVE-2026-6730 | Severity | GitHub advisories critical NVD high | 2026-10-06 | |
| artemis-openwire-protocol: AMQ Broker Artemis: pre-authentication arbitrary durable queue deletion via OpenWire RemoveSubscriptionInfo CVE-2026-67593 | Severity | NVD critical Red Hat high | 2026-10-06 | |
| The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability. CVE-2026-68068 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| org.apache.myfaces.core/myfaces-impl: Apache MyFaces: Server-Side Request Forgery and Local File Inclusion Vulnerability CVE-2026-68536 | Severity | NVD critical Red Hat medium | 2026-10-06 | |
| The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability. CVE-2026-68954 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| c-ares: c-ares: Denial of Service via unvalidated DNS header record counts CVE-2026-69186 | Severity | NVD medium Red Hat high | 2026-10-06 | |
| An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. CVE-2026-71189 | Severity | GitHub advisories medium NVD low | 2026-10-06 | |
| gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit CVE-2026-71220 | Severity | NVD high Red Hat medium | 2026-10-06 | |
| gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta CVE-2026-71221 | Severity | NVD high Red Hat medium | 2026-10-06 | |
| A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried.
An authenticated user who does not have permission to access a specific project can invoke the API with parameters referencing workflows belonging to that project and retrieve workflow information. This allows users to access workflow data outside their authorized project scope, resulting in unauthorized information disclosure.
This issue affects Apache DolphinScheduler: from 3.2.0 before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue. CVE-2026-71899 | Severity | GitHub advisories unknown NVD medium | 2026-10-06 | |
| The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability. CVE-2026-72507 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection. CVE-2026-72510 | Severity | GitHub advisories high NVD critical | 2026-10-06 | |
| org.apache.parquet/parquet-hadoop: Apache Parquet Hadoop: KMS token disclosure due to missing host validation CVE-2026-73334 | Severity | NVD high Red Hat medium | 2026-10-06 | |
| tomcat: Apache Tomcat: TLS implementations ignore Certificate Revocation Lists CVE-2026-73581 | Severity | GitHub advisories unknown NVD medium Red Hat medium | 2026-10-06 | |
| kernel: tcp: clear sock_ops cb flags before force-closing a child socket CVE-2026-74268 | CVSS | NVD 9.8 Red Hat 5.5 | 2026-10-06 | |
| kernel: tcp: clear sock_ops cb flags before force-closing a child socket CVE-2026-74268 | Severity | NVD critical Red Hat medium | 2026-10-06 | |