Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54449
Total
4308
Critical
16178
High
15893
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-56724 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission checks in the knowledge base management area … | Sep 25, 2026 |
| CVE-2026-56723 | UNKNOWN | — | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a customer who can view a ticket cannot see internal ticket articles … | Sep 25, 2026 |
| CVE-2026-18320 | MEDIUM | 6.1 | Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule. This configuration … | Sep 25, 2026 |
| CVE-2026-18312 | MEDIUM | 6.1 | Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping. The application interpolates untrusted values directly into URL … | Sep 25, 2026 |
| CVE-2026-18311 | MEDIUM | 6.1 | Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as … | Sep 25, 2026 |
| CVE-2026-100248 | UNKNOWN | — | The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin. | Sep 25, 2026 |
| CVE-2026-100237 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension allows Stored XSS. This issue affects … | Sep 25, 2026 |
| CVE-2026-97869 | MEDIUM | 4.1 | A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the function AgenticScopeSerializer.fromJson of the file AgenticScopeJsonSerializationIT.java of the component LangChain4j-agentic. This … | Sep 25, 2026 |
| CVE-2026-97868 | LOW | 3.5 | A security vulnerability has been detected in sheshbabu zen up to 1.5.0. Affected by this issue is the function dangerouslySetInnerHTML of the file features/notes/NotesEditor.jsx of … | Sep 25, 2026 |
| CVE-2026-97469 | MEDIUM | 4.3 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline … | Sep 25, 2026 |
| CVE-2026-96874 | UNKNOWN | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - … | Sep 25, 2026 |
| CVE-2026-92161 | CRITICAL | 9.8 | FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider … | Sep 25, 2026 |
| CVE-2026-85293 | MEDIUM | 4.8 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and … | Sep 25, 2026 |
| CVE-2026-85292 | MEDIUM | 4.8 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the … | Sep 25, 2026 |
| CVE-2026-85291 | MEDIUM | 6.5 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL … | Sep 25, 2026 |
| CVE-2026-85290 | MEDIUM | 5.3 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from … | Sep 25, 2026 |
| CVE-2026-85289 | MEDIUM | 6.5 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), … | Sep 25, 2026 |
| CVE-2026-85274 | MEDIUM | 6.5 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without … | Sep 25, 2026 |
| CVE-2026-67236 | UNKNOWN | — | RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing … | Sep 25, 2026 |
| CVE-2026-62262 | CRITICAL | 9.1 | Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can … | Sep 25, 2026 |
| CVE-2026-54790 | MEDIUM | 6.0 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it … | Sep 25, 2026 |
| CVE-2026-50547 | HIGH | 7.5 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the … | Sep 25, 2026 |
| CVE-2026-49850 | HIGH | 7.5 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without … | Sep 25, 2026 |
| CVE-2026-44642 | HIGH | 8.1 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only … | Sep 25, 2026 |
| CVE-2026-42324 | HIGH | 7.2 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing … | Sep 25, 2026 |