| CVE-2026-106579 |
ImageMagick: Policy Bypass when using coder as the domain. |
07.10.2026 |
6.2 |
| CVE-2026-106580 |
ImageMagick: Policy Bypass in CUT encoder |
07.10.2026 |
4 |
| CVE-2026-107208 |
ImageMagick: Denial of service with crafted XMP profile |
07.10.2026 |
5.3 |
| CVE-2026-107270 |
Gophish through 0.12.1 Object Takeover via Client-Supplied ID on API Create Endpoints |
07.10.2026 |
|
| CVE-2026-107271 |
Gophish through 0.12.1 Login Rate Limit Bypass via X-Forwarded-For Spoofing |
07.10.2026 |
|
| CVE-2026-107272 |
Gophish through 0.12.1 XSS via Unescaped SMTP Server Error Messages |
07.10.2026 |
|
| CVE-2026-107273 |
Gophish 0.11.0 through 0.12.1 SSRF via POST /api/import/site |
07.10.2026 |
|
| CVE-2026-107278 |
MISP Object Sync Drops Objects and Attributes When Description Is Empty |
07.10.2026 |
|
| CVE-2026-92414 |
Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lock tokens |
07.10.2026 |
|
| CVE-2026-92415 |
Apache Jackrabbit: DavEx client runs Class.forName + (String)-constructor on server-controlled error bodies |
07.10.2026 |
|
| CVE-2026-106566 |
ImageMagick: Policy Bypass in delegate symlink cleanup due to missing check |
07.10.2026 |
4 |
| CVE-2026-106567 |
ImageMagick: Infinite Loop in PSD decoder on 32-bit builds |
07.10.2026 |
5.9 |
| CVE-2026-106568 |
ImageMagick: Infinite Loop when reading a crafted XMP profile |
07.10.2026 |
5.3 |
| CVE-2026-106569 |
ImageMagick: Denial of service in ASE decoder because of missing security checks |
07.10.2026 |
5.3 |
| CVE-2026-106570 |
ImageMagick: Denial of service in distributed pixel cache server |
07.10.2026 |
4.3 |
| CVE-2026-106571 |
ImageMagick: Heap Buffer Over-Write in GetVirtualPixels api will result in a crash |
07.10.2026 |
5.1 |
| CVE-2026-106572 |
ImageMagick: Stack Overflown CALS decoder due to missing depth check. |
07.10.2026 |
5.3 |
| CVE-2026-106573 |
ImageMagick: Denial of service in MVG decoder |
07.10.2026 |
5.3 |
| CVE-2026-106574 |
ImageMagick: Heap Buffer Over-Write in distributed pixel cache server will result in a crash |
07.10.2026 |
5.3 |
| CVE-2026-106575 |
ImageMagick: Unclosed file pointer in magick script |
07.10.2026 |
5.3 |
| CVE-2026-106576 |
ImageMagick: Denial of service possible when parsing an XMP profile. |
07.10.2026 |
5.3 |
| CVE-2026-106577 |
ImageMagick: Code Injection in the postscript coders |
07.10.2026 |
5.3 |
| CVE-2026-106578 |
ImageMagick: Invalid Memory Free in MVG decoder |
07.10.2026 |
5.9 |
| CVE-2026-107204 |
LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint |
07.10.2026 |
|
| CVE-2026-107205 |
LMCache through 0.5.5 Missing Authentication in MP Coordinator Fleet Control API |
07.10.2026 |
|
| CVE-2026-107206 |
LMCache through 0.5.5 Missing Authentication in MP HTTP Server Management API |
07.10.2026 |
|
| CVE-2026-107207 |
LMCache through 0.5.5 Missing Authentication in Frontend Node Catalog Allows SSRF Allowlist Bypass |
07.10.2026 |
|
| CVE-2026-107269 |
Gophish through 0.12.1 Username Enumeration via POST /login Timing Discrepancy |
07.10.2026 |
|
| CVE-2026-107276 |
MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Multiple Concurrent Requests |
07.10.2026 |
|
| CVE-2026-106564 |
ImageMagick: Heap Buffer Over-Write in EXR decoder |
07.10.2026 |
5.3 |
| CVE-2026-106565 |
ImageMagick: Infinite Loop in bzip2 compressed images. |
07.10.2026 |
5.9 |
| CVE-2026-33586 |
Authenticated SMTP Sender Address Forgery |
07.10.2026 |
|
| CVE-2025-70522 |
|
07.10.2026 |
|
| CVE-2026-106560 |
Backstage: Improper repository path validation in a Scaffolder backend module |
07.10.2026 |
7.1 |
| CVE-2026-106561 |
Backstage: Sensitive information disclosure in Kubernetes resource queries |
07.10.2026 |
5 |
| CVE-2026-106562 |
Backstage: Incorrect authorization in search engine permission filtering |
07.10.2026 |
4.3 |
| CVE-2026-106563 |
Backstage: Improper entity validation in deprecated Kubernetes services endpoint |
07.10.2026 |
5.3 |
| CVE-2025-70515 |
|
07.10.2026 |
|
| CVE-2025-70516 |
|
07.10.2026 |
|
| CVE-2025-70517 |
|
07.10.2026 |
|
| CVE-2025-70518 |
|
07.10.2026 |
|
| CVE-2025-70519 |
|
07.10.2026 |
|
| CVE-2025-70520 |
|
07.10.2026 |
|
| CVE-2025-70521 |
|
07.10.2026 |
|
| CVE-2026-106556 |
Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization |
07.10.2026 |
7.7 |
| CVE-2026-106558 |
Backstage: Improper validation of TechDocs MkDocs configuration |
07.10.2026 |
8.8 |
| CVE-2026-106559 |
Backstage: Improper input validation in Confluence to Markdown scaffolder module |
07.10.2026 |
6.3 |
| CVE-2026-104074 |
Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE |
07.10.2026 |
|
| CVE-2026-106064 |
Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions |
07.10.2026 |
|
| CVE-2026-106510 |
Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml |
07.10.2026 |
7.7 |
| CVE-2026-107167 |
M17n-lib: heap use-after-free write in re_init_ic() |
07.10.2026 |
|
| CVE-2026-107169 |
M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8 |
07.10.2026 |
|
| CVE-2026-107174 |
Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction |
07.10.2026 |
|
| CVE-2026-107202 |
CVE-2026-107202 |
07.10.2026 |
|
| CVE-2026-62179 |
PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues |
07.10.2026 |
6.5 |
| CVE-2026-77214 |
libexpat Heap Buffer Over-read in xmlparse.c via XML_ParseBuffer |
07.10.2026 |
|
| CVE-2026-107125 |
XnView Classic FLI File heap-based overflow |
07.10.2026 |
|
| CVE-2026-46570 |
|
07.10.2026 |
|
| CVE-2026-42616 |
|
07.10.2026 |
|
| CVE-2026-42617 |
|
07.10.2026 |
|
| CVE-2026-46437 |
wger: API credentials remain valid after logout/password change |
07.10.2026 |
4.8 |
| CVE-2026-46438 |
wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry |
07.10.2026 |
6.5 |
| CVE-2026-46569 |
|
07.10.2026 |
|
| CVE-2026-46571 |
|
07.10.2026 |
|
| CVE-2026-107194 |
|
07.10.2026 |
|
| CVE-2026-42618 |
|
07.10.2026 |
|
| CVE-2026-46434 |
wger: Trainer Privilege Escalation - Improper Privilege Management |
07.10.2026 |
7.1 |
| CVE-2026-46572 |
|
07.10.2026 |
|
| CVE-2026-107181 |
Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme |
07.10.2026 |
|
| CVE-2026-107183 |
llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser |
07.10.2026 |
|
| CVE-2026-43976 |
wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views) |
07.10.2026 |
7.1 |
| CVE-2026-45161 |
wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding |
07.10.2026 |
5.4 |
| CVE-2026-102257 |
|
07.10.2026 |
|
| CVE-2026-102258 |
|
07.10.2026 |
|
| CVE-2026-88514 |
|
07.10.2026 |
|
| CVE-2026-102255 |
|
07.10.2026 |
|
| CVE-2026-102256 |
|
07.10.2026 |
|
| CVE-2026-98373 |
mm/hugetlb: preserve mremap address delta when skipping page tables |
07.10.2026 |
|
| CVE-2026-98374 |
tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() |
07.10.2026 |
|
| CVE-2026-103435 |
Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code |
07.10.2026 |
|
| CVE-2026-107151 |
Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated requests |
07.10.2026 |
|
| CVE-2026-107162 |
Express Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation Bypass |
07.10.2026 |
|
| CVE-2026-107168 |
M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars() |
07.10.2026 |
|
| CVE-2026-107170 |
M17n-lib: null dereference in minput_open_im() after failed m17n_init() |
07.10.2026 |
|
| CVE-2026-107175 |
MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing Group Changes |
07.10.2026 |
|
| CVE-2026-107177 |
Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens |
07.10.2026 |
|
| CVE-2026-107180 |
MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_required Instances |
07.10.2026 |
|
| CVE-2026-41958 |
|
07.10.2026 |
6.5 |
| CVE-2026-42532 |
|
07.10.2026 |
5.5 |
| CVE-2026-105138 |
Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API |
07.10.2026 |
|
| CVE-2026-105139 |
Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and Resources |
07.10.2026 |
|
| CVE-2026-105140 |
Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Revoked Group Membership |
07.10.2026 |
|
| CVE-2026-106056 |
Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting |
07.10.2026 |
|
| CVE-2026-106057 |
patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt |
07.10.2026 |
|
| CVE-2026-106058 |
GitAhead through 2.7.1 OS Command Injection via Git Filter Filenames |
07.10.2026 |
|
| CVE-2026-106059 |
GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript |
07.10.2026 |
|
| CVE-2026-107159 |
MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header |
07.10.2026 |
|
| CVE-2026-42708 |
WordPress WP Post Author plugin <= 4.0.0 - SQL Injection vulnerability |
07.10.2026 |
7.6 |
| CVE-2026-42710 |
WordPress Slider by 10Web plugin <= 1.2.63 - SQL Injection vulnerability |
07.10.2026 |
7.6 |
| CVE-2026-42713 |
WordPress Post title marquee scroll plugin <= 9.9 - SQL Injection vulnerability |
07.10.2026 |
7.6 |
| CVE-2026-42714 |
WordPress Pix por Piggly (para Woocommerce) plugin <= 2.1.2 - SQL Injection vulnerability |
07.10.2026 |
7.6 |
| CVE-2026-92531 |
Improper Neutralization of Special Elements used in an OS Command in BugTracker.NET |
07.10.2026 |
|
| CVE-2026-92532 |
Unrestricted Upload of File with Dangerous Type in BugTracker.NET |
07.10.2026 |
|
| CVE-2026-92533 |
Path Traversal in BugTracker.NET |
07.10.2026 |
|
| CVE-2026-103668 |
|
07.10.2026 |
|
| CVE-2026-96408 |
|
07.10.2026 |
|
| CVE-2026-42720 |
WordPress Dynamic User Directory plugin <= 2.4 - SQL Injection vulnerability |
07.10.2026 |
7.6 |
| CVE-2026-42721 |
WordPress affiliate-toolkit plugin <= 3.9.1 - SQL Injection vulnerability |
07.10.2026 |
7.6 |
| CVE-2026-105192 |
LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization |
07.10.2026 |
9.8 |
| CVE-2026-103075 |
WordPress Hustle plugin <= 7.8.14.2 - Broken Access Control vulnerability |
07.10.2026 |
4.3 |
| CVE-2026-104390 |
WordPress Booktics plugin <= 1.0.27 - Broken Access Control vulnerability |
07.10.2026 |
4.3 |
| CVE-2026-104391 |
WordPress Quiz And Survey Master plugin <= 11.2.7 - Cross Site Scripting (XSS) vulnerability |
07.10.2026 |
6.5 |
| CVE-2026-104393 |
WordPress Happy Addons for Elementor plugin <= 3.50.0 - Cross Site Scripting (XSS) vulnerability |
07.10.2026 |
6.5 |
| CVE-2026-105871 |
WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability |
07.10.2026 |
6.5 |
| CVE-2026-105873 |
WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulnerability |
07.10.2026 |
6.5 |
| CVE-2026-105875 |
WordPress Prime Slider – Addons For Elementor plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability |
07.10.2026 |
6.5 |
| CVE-2026-105876 |
WordPress Modula Image Gallery plugin <= 3.0.11 - Sensitive Data Exposure vulnerability |
07.10.2026 |
5.3 |
| CVE-2026-105884 |
WordPress Rocket Lazy Load plugin <= 2.4.0 - Cross Site Scripting (XSS) vulnerability |
07.10.2026 |
6.5 |
| CVE-2026-27434 |
WordPress WP Rentals theme <= 3.14.2 - Broken Access Control vulnerability |
07.10.2026 |
5.3 |
| CVE-2026-78243 |
Apache YuniKorn: LDAP Group provider panics on lowercase attribute name |
07.10.2026 |
|
| CVE-2026-92393 |
Apache YuniKorn: Admission control bypass via workload UPDATE operation |
07.10.2026 |
|
| CVE-2026-97146 |
Apache YuniKorn: Admission control bypass via system label forgery |
07.10.2026 |
|
| CVE-2026-97294 |
WordPress Media LIbrary Assistant plugin <= 3.41 - Cross Site Scripting (XSS) vulnerability |
07.10.2026 |
6.5 |
| CVE-2026-103416 |
|
07.10.2026 |
|
| CVE-2026-15894 |
Bluetooth Mesh solicitation PDU stack buffer overflow via oversized advertisement |
07.10.2026 |
8.8 |
| CVE-2026-19186 |
Integer underflow in IEEE 802.15.4 frame decryption leads to out-of-bounds read and write |
07.10.2026 |
8.1 |
| CVE-2025-64391 |
|
07.10.2026 |
|
| CVE-2025-64392 |
|
07.10.2026 |
|
| CVE-2025-64393 |
|
07.10.2026 |
|
| CVE-2026-58068 |
|
07.10.2026 |
|
| CVE-2026-58069 |
|
07.10.2026 |
|
| CVE-2026-5703 |
Path Traversal in Satel Iberia SenNet Datalogger Serie 200 |
07.10.2026 |
|
| CVE-2026-90466 |
Apache Impala: Path traversal executes JARs outside trusted paths |
07.10.2026 |
|
| CVE-2026-93026 |
|
07.10.2026 |
|
| CVE-2026-93684 |
Apache Impala: Stored XSS in Impala query plans |
07.10.2026 |
|
| CVE-2026-97720 |
Apache Impala: Impala Executor Webserver Auth Bypass |
07.10.2026 |
|
| CVE-2026-102781 |
Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 |
07.10.2026 |
|
| CVE-2026-102782 |
Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 |
07.10.2026 |
|
| CVE-2026-107102 |
Account Takeover Vulnerability in Manacle Technologies ERP System |
07.10.2026 |
|
| CVE-2026-107103 |
SQL Injection Vulnerability in Manacle Technologies ERP System |
07.10.2026 |
|
| CVE-2026-107104 |
Unsafe Deserialization Vulnerability in Manacle Technologies ERP System |
07.10.2026 |
|
| CVE-2026-89417 |
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. <= 6.3.10 - Unauthenticated Stored Cross-Site Scripting via 's' Search Parameter in comments-atom Feed |
07.10.2026 |
7.2 |
| CVE-2026-107121 |
Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downgrade |
07.10.2026 |
|
| CVE-2026-105322 |
Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form |
07.10.2026 |
5.3 |
| CVE-2026-82211 |
Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure |
07.10.2026 |
8.2 |
| CVE-2026-82212 |
Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification Handler |
07.10.2026 |
7.5 |
| CVE-2026-86833 |
MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcodes |
07.10.2026 |
5.4 |
| CVE-2026-103323 |
Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler Queue Disclosure |
07.10.2026 |
|
| CVE-2026-103378 |
Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Public Log File |
07.10.2026 |
|
| CVE-2026-103681 |
Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_profile_delete |
07.10.2026 |
|
| CVE-2026-104049 |
Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpoint |
07.10.2026 |
|
| CVE-2026-104050 |
Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answers |
07.10.2026 |
|
| CVE-2026-104651 |
Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulation via IDOR |
07.10.2026 |
|
| CVE-2026-104652 |
Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID |
07.10.2026 |
|
| CVE-2026-104653 |
Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions |
07.10.2026 |
|
| CVE-2026-104667 |
Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order |
07.10.2026 |
|
| CVE-2026-104677 |
WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP |
07.10.2026 |
|
| CVE-2026-104678 |
CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update |
07.10.2026 |
|
| CVE-2026-104953 |
MPG < 4.2.3 - Editor+ SQLi via Project Import |
07.10.2026 |
|
| CVE-2026-105316 |
Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Actions |
07.10.2026 |
|
| CVE-2026-86816 |
WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API |
07.10.2026 |
|
| CVE-2026-87782 |
Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator |
07.10.2026 |
|
| CVE-2026-87971 |
If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter |
07.10.2026 |
|
| CVE-2026-96530 |
Optimole 4.0.0 - 4.2.14 - Subscriber+ Sensitive Data Disclosure via Dashboard Widget |
07.10.2026 |
|
| CVE-2026-97188 |
String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor |
07.10.2026 |
|
| CVE-2026-97331 |
User Private Files < 2.1.9 - Subscriber+ User Email Address Disclosure via dpk_upvf_rmv_access |
07.10.2026 |
|
| CVE-2026-97354 |
PowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL Redirects |
07.10.2026 |
|
| CVE-2026-103868 |
Pulp-container: registry credentials are reused across remotes in a worker |
07.10.2026 |
|
| CVE-2026-103869 |
Pulp-ansible: bearer tokens are reused across remotes in a worker |
07.10.2026 |
|
| CVE-2026-103870 |
Pulp-rpm: distribution tree publish creates directories from .treeinfo ids |
07.10.2026 |
|
| CVE-2026-59346 |
VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability |
07.10.2026 |
9.3 |
| CVE-2026-59347 |
VMware Workstation and Fusion HGFS stack-based buffer-overflow vulnerability |
07.10.2026 |
8.1 |
| CVE-2026-102173 |
Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Unauthenticated Stored Cross-Site Scripting via Registration Metadata |
07.10.2026 |
7.2 |
| CVE-2026-19572 |
FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability |
07.10.2026 |
|
| CVE-2026-83742 |
wstrncat() unsigned integer underflow leads to an off-by-one null write in wolfSSH on non-Windows platforms |
07.10.2026 |
|
| CVE-2026-84897 |
wolfSSH server accepts server-to-client DH group exchange messages from an unauthenticated client, causing pre-authentication primality-test CPU exhaustion and key exchange role confusion |
07.10.2026 |
|
| CVE-2026-106061 |
Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file |
07.10.2026 |
|
| CVE-2026-14911 |
|
07.10.2026 |
|
| CVE-2026-16516 |
wolfSSH ECDSA host key curve not validated against negotiated algorithm |
07.10.2026 |
|
| CVE-2026-81535 |
wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without an authorization check |
07.10.2026 |
|
| CVE-2026-83540 |
wolfSSHd on Windows race condition leading to logon token reused across connections |
07.10.2026 |
|
| CVE-2026-106471 |
Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter multi-@verify hasaccess latching |
07.10.2026 |
|
| CVE-2026-16528 |
|
07.10.2026 |
|
| CVE-2026-19386 |
|
07.10.2026 |
|
| CVE-2026-19396 |
|
07.10.2026 |
|
| CVE-2026-102478 |
|
07.10.2026 |
|
| CVE-2026-105324 |
An HTTP header injection vulnerability was found in the ADM |
07.10.2026 |
|
| CVE-2026-101329 |
Langflow OSS is affected by multiple vulnerabilities |
06.10.2026 |
6.5 |
| CVE-2026-101331 |
Langflow OSS is affected by multiple vulnerabilities |
06.10.2026 |
7.7 |
| CVE-2026-103360 |
Langflow OSS is affected by multiple vulnerabilities |
06.10.2026 |
8.1 |
| CVE-2026-104334 |
Langflow OSS is affected by multiple vulnerabilities |
06.10.2026 |
9.8 |
| CVE-2026-88962 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
8.8 |
| CVE-2026-93443 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
7.5 |
| CVE-2026-93445 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
8.1 |
| CVE-2026-93447 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
7.5 |
| CVE-2026-93448 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
6.5 |
| CVE-2026-93449 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
8.5 |
| CVE-2026-93674 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
9.8 |
| CVE-2026-93675 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
8.8 |
| CVE-2026-93677 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
7.7 |
| CVE-2026-93678 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
7.6 |
| CVE-2026-93679 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
4.3 |
| CVE-2026-97655 |
Langflow OSS is affected by multiple vulnerabilities |
06.10.2026 |
8.8 |
| CVE-2026-97671 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
6.5 |
| CVE-2026-97673 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
8.8 |
| CVE-2026-97674 |
Langflow OSS is affected by multiple vulnerabilities |
06.10.2026 |
8.1 |
| CVE-2026-97676 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
8.8 |
| CVE-2026-97678 |
Langflow OSS is affected by multiple vulnerabilities |
06.10.2026 |
8.8 |
| CVE-2026-97679 |
Langflow OSS is affected by multiple vulnerabilities |
06.10.2026 |
8.8 |
| CVE-2026-97680 |
Langflow OSS is affected by multiple vulnerabilities |
06.10.2026 |
8.3 |
| CVE-2026-104335 |
Langflow OSS is affected by multiple vulnerabilities |
07.10.2026 |
8.8 |
| CVE-2026-106583 |
|
06.10.2026 |
2.5 |
| CVE-2026-80048 |
Sssd: sssd-kcm: local denial of service via excessive memory preallocation |
06.10.2026 |
|
| CVE-2026-106509 |
Backstage: Improper validation of MkDocs theme configuration in TechDocs |
06.10.2026 |
7.7 |
| CVE-2026-106505 |
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend |
06.10.2026 |
7.7 |
| CVE-2026-106506 |
Backstage: Improper input validation in scaffolder task list ordering |
06.10.2026 |
5.3 |
| CVE-2026-106507 |
Backstage: TechDocs arbitrary file read via mkdocs snippets |
07.10.2026 |
5.3 |
| CVE-2026-106508 |
Backstage: Potential file exposure through local TechDocs publisher |
06.10.2026 |
5.3 |
| CVE-2026-101023 |
Gitea OAuth2 refresh token grant accepts access tokens |
06.10.2026 |
|
| CVE-2026-104633 |
Gitea migration memory exhaustion from zero page size |
07.10.2026 |
|
| CVE-2026-105267 |
Gitea tag delete route deletes releases without release permission |
06.10.2026 |
|
| CVE-2026-105268 |
Gitea issue attachment API allows changing comment attachments |
06.10.2026 |
|
| CVE-2026-106501 |
Backstage: Sensitive information exposure in Scaffolder |
06.10.2026 |
9.6 |
| CVE-2026-106502 |
Backstage: Sensitive information may be exposed in Scaffolder task failure events |
07.10.2026 |
5.3 |
| CVE-2026-106503 |
Backstage: Scaffolder action input authorization bypass |
06.10.2026 |
8.1 |
| CVE-2026-106504 |
Backstage: Sensitive information exposure in scaffolder task logs |
06.10.2026 |
6.5 |
| CVE-2026-89182 |
Gitea push-to-create bypass of FORCE_PRIVATE policy |
07.10.2026 |
|
| CVE-2026-96594 |
Gitea repository media API stored XSS |
07.10.2026 |
|
| CVE-2026-97626 |
Gitea profile feed disclosure bypassing user visibility |
06.10.2026 |
|
| CVE-2026-106500 |
Backstage: Improper task state validation in Scaffolder backend |
07.10.2026 |
8.5 |