An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component
CVSSv3.1 9.3 (CRITICAL)
CWECWE 502CWECWE 400VNDToktokTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
3w ago
2026-08-26 19:16Z
CRIT
CVE-2025-61165 — An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5
An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 19:16Z
CRIT
CVE-2025-61163 — Cohere: North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted
Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 942VNDCohereTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 18:16Z
HIGH
CVE-2026-58474 — whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special characters. The script generation function in cli.py interpolates HuggingFace-derived values, including GGUF variant filenames from the Hub API siblings rfilename field, directly into Python source cod
CVSSv3.1 8.8 (HIGH)
CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 18:16Z
HIGH
CVE-2025-56798 — Site: Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and
Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy.
CVSSv3.1 8.8 (HIGH)
CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 18:16Z
CRIT
CVE-2023-42179 — Bird: Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the
Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.
CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile
CWECWE 284VNDBirdTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 17:16Z
HIGH
CVE-2026-32258 — Winter: From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting. This issue is fixed in version 1.2.13.
CVSSv3.1 8.1 (HIGH)
CWECWE 79VNDWinterTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-26 17:16Z
HIGH
CVE-2026-32257 — Winter: Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting against backend users. This issue is fixed in version 1.2.13.
CVSSv3.1 8.1 (HIGH)
CWECWE 79VNDWinterTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 17:16Z
HIGH
CVE-2020-15878 — LibreNMS: A remote authenticated attacker with normal privileges can extract all the information from the
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address parameter in the /ajax_table.php API endpoint.
CVSSv3.1 8.8 (HIGH) · EPSS 20th percentile
CWECWE 89VNDLibrenmsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 17:16Z
HIGH
CVE-2020-15876 — LibreNMS: A remote authenticated attacker with normal privileges can extract all the information from the
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects address-search.inc.php, alertlog.inc.php, arp-search.inc.php, as-selection.inc.php, bills.inc.php, device_mibs.inc.php, device_oids.inc.php, edit-ports.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php,
CVSSv3.1 8.8 (HIGH) · EPSS 14th percentile
CWECWE 89VNDLibrenmsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 17:16Z
HIGH
CVE-2020-15874 — LibreNMS: A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.
CVSSv3.1 8.8 (HIGH) · EPSS 44th percentile
CWECWE 77VNDLibrenmsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-26 16:16Z
HIGH
CVE-2026-81036 — Stalwart: Mail Server does not compare an OAuth redirect target against any registered destination
Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled, and that requirement is false in the shipped settings, so the supplied redirect value is neither matched against a registered client nor otherwise constrained. The value is stored with the authorizat
CVSSv3.1 8.1 (HIGH)
CWECWE 601VNDStalwartTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 16:16Z
HIGH
CVE-2026-81035 — Midday: allows any member of a team to delete it.
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it records, and the data-layer function it calls re-checks the same helper and nothing else. The neighbouring procedures that remove or update a member in the same router each resolve the caller's role and refuse the request unless it
CVSSv3.1 8.1 (HIGH)
CWECWE 862VNDMiddayTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 16:16Z
CRIT
CVE-2026-81032 — NebulaGraph: The read route returns the daemon's full set of runtime flag values, which includes
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and writing gflags alongside status and statistics. Neither the service nor its router carries any authentication, token check or address restriction. The read route returns the daemon's full set of runtime flag values, which includes the
CVSSv3.1 9.8 (CRITICAL)
CWECWE 306VNDNebulagraphTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 16:16Z
HIGH
CVE-2026-81029 — OpenMetadata: accepts a caller-supplied post-authentication redirect target and appends the issued token to it.
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the assertion consumer servlet later formats that stored value into a URL carrying the freshly issued JWT together with the account's email and name before sending the redirect. The OIDC and OAuth2 handler
CVSSv3.1 8.1 (HIGH)
CWECWE 601VNDOpenmetadataTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-26 16:16Z
HIGH
CVE-2026-81027 — middleware/auth.go permits a request to name a specific channel either through a suffix on
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after model.IsAdmin succeeds and otherwise rejects the caller, while the path-parameter branch sets the selected-channel value from c.Param("channelid") with no role check at all. The route carrying that parameter sits behind token authentica
CVSSv3.1 8.5 (HIGH)
CWECWE 862TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-26 16:16Z
CRIT
CVE-2026-80428 — ILIAS: A class bundled with the application writes a JSON-encoded structure to a file named
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its logout-notification handler locates the session to terminate by reading every live row of the session table and passing each row's stored data to a hand-written parser that calls unserialize without restricting which classes may be con
CVSSv3.1 9.8 (CRITICAL)
CWECWE 502VNDIliasTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 16:16Z
HIGH
CVE-2026-80427 — bestzip builds the argument list for the system zip utility without separating options from
bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so any source entry beginning with a hyphen is interpreted by zip as an option rather than a file name. zip accepts -T to test the finished archive and -TT to name the command used to perform that test, so a source list containing those two entr
CVSSv3.1 8.4 (HIGH)
CWECWE 88TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3w ago
2026-08-26 16:16Z
CRIT
CVE-2026-54569 — SENAITE: From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many, and getusers, do not enforce the senaite.core: Access JSON API permission befor
CVSSv3.1 9.8 (CRITICAL)
CWECWE 862CWECWE 95VNDSenaiteTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:17Z
CRIT
CVE-2026-80589 — Linux: nvme gets there because nvme_update_ns_info() submits Report Zones or FDP io-mgmt-recv on ns->queue before
In the Linux kernel, the following vulnerability has been resolved:
block: stop the timeout timer when releasing a never added disk
disk_release() undoes blk_mq_init_allocated_queue() for a disk whose
probe failed before add_disk(), but it only calls blk_mq_exit_queue().
Nothing there stops q->timeout, and that timer rolls forward: it stays
pending until it next expires, not until the last request completes.
So if the driver issued any I/O before adding the disk, the
reques
CVSSv3.1 9.8 (CRITICAL)
TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:17Z
CRIT
CVE-2026-80587 — Linux: In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some
In the Linux kernel, the following vulnerability has been resolved:
mptcp: avoid combining some incoming suboptions
Some MPTCP suboptions are mutually exclusive according to the RFC8684,
but also because in different places, the code doesn't expect some
combinations to be present. That's specially true for suboptions that
would be present twice, but with different attributes.
The new restrictions are the same as the ones applied on the output
side, with mptcp_write_options
CVSSv3.1 9.8 (CRITICAL)
TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:17Z
CRIT
CVE-2026-80586 — Linux: In this case, the first suboption will be ignored, but leaving some fields written
In the Linux kernel, the following vulnerability has been resolved:
mptcp: options: reset DSS fields in case of unexpected size
A remote peer could send a malformed DSS with a wrong size, followed by
another DSS or MPC + Data. In this case, the first suboption will be
ignored, but leaving some fields written, which could lead to
inconsistency or access uninitialized data.
Explicitly reset the fields that could have been modified in case of
unexpected size.
CVSSv3.1 9.8 (CRITICAL)
TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-26 15:17Z
CRIT
CVE-2026-80585 — Linux: In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fastopen: only mark MPTFO subflows with SYN data
Passive TCP Fast Open accepts a valid-cookie SYN even when it carries
no data. In that case the child socket's receive queue is intentionally
left empty.
mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking
for queued SYN data. That made data-less TFO SYNs hit a WARN and, if
the warning was non-fatal, left stale MPTFO state behind.
CVSSv3.1 9.4 (CRITICAL)
TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
3w ago
2026-08-26 15:17Z
HIGH
CVE-2026-80584 — Linux: In the Linux kernel, the following vulnerability has been resolved: s390/qeth: validate user buffer
In the Linux kernel, the following vulnerability has been resolved:
s390/qeth: validate user buffer length in SNMP and ARP query ioctls
qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by
a user-supplied length (udata_len) without checking a lower bound, then
set udata_offset to a fixed non-zero value and pass both to a reply
callback. The callback bounds-checks the copy with
if ((udata_len - udata_offset) < len)
Both fields are u32, so a udata_
CVSSv3.1 8.4 (HIGH)
TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3w ago
2026-08-26 15:17Z
HIGH
CVE-2026-80576 — Linux: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: reject oversized IBs with per-ring packet limits
On GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through
to ib->length_dw without a limit, while ring_emit_ib() encodes length
into packet fields. Oversized values can corrupt adjacent control bits
and destabilize command submission.
Add a per-ring IB packet size limit helper and reject command
submissions exceeding the corresponding
CVSSv3.1 8.8 (HIGH)