Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-08-31 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-51677 | TOTOLINK T6 4.1.5cu.748_B20211015 UPnP Service /cgi-bin/cstecgi.cgi setUPnPCfg access control (EUVD-2026-68540)
A vulnerability identified as critical has been detected in TOTOLINK T6 4.1.5cu.748_B20211015. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component UPnP Service. Performing a manipulation results in imprope
CVE-2026-76763 | Red Hat Quarkus Number Scalar Coercion resource consumption (EUVD-2026-68525)
A vulnerability, which was classified as problematic, has been found in Red Hat Quarkus. Affected by this issue is some unknown functionality of the component Number Scalar Coercion. This manipulation causes resource consumption. This vulne
CVE-2026-51679 | TOTOLINK T6 4.1.5cu.748 /cgi-bin/cstecgi.cgi setPasswordCfg access control (EUVD-2026-68542)
A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been classified as very critical. Impacted is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. This vulnerability
CVE-2026-51679 | TOTOLINK T6 4.1.5cu.748 /cgi-bin/cstecgi.cgi setPasswordCfg access control (EUVD-2026-68542)
A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been classified as very critical. Impacted is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. This vulnerability
CVE-2026-51678 | TOTOLINK T6 4.1.5cu.748 /cgi-bin/cstecgi.cgi setSyslogCfg access control (EUVD-2026-68541)
A vulnerability was found in TOTOLINK T6 4.1.5cu.748 and classified as problematic. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation can lead to improper access controls. The identifica
CVE-2026-51678 | TOTOLINK T6 4.1.5cu.748 /cgi-bin/cstecgi.cgi setSyslogCfg access control (EUVD-2026-68541)
A vulnerability was found in TOTOLINK T6 4.1.5cu.748 and classified as problematic. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation can lead to improper access controls. The identifica
CVE-2026-19702 | Pardus Boot Repair up to 1.0.7 os command injection (EUVD-2026-68526)
A vulnerability has been found in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair up to 1.0.7 and classified as critical. This vulnerability affects unknown code. Performing a manipulation results in os command in
CVE-2026-78465 | GIMP file-pcx plugin integer overflow (EUVD-2026-64935 / Nessus ID 339188)
A vulnerability described as problematic has been identified in GIMP. This issue affects some unknown processing of the component file-pcx plugin. The manipulation results in integer overflow. This vulnerability was named CVE-2026-78465. Th
CVE-2026-51680 | TOTOLINK T6 4.1.5cu.748 /cgi-bin/cstecgi.cgi setLedCfg access control (EUVD-2026-68543)
A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been declared as problematic. The affected element is the function setLedCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in improper access controls. This vulnerabi
CVE-2026-51680 | TOTOLINK T6 4.1.5cu.748 /cgi-bin/cstecgi.cgi setLedCfg access control (EUVD-2026-68543)
A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been declared as problematic. The affected element is the function setLedCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in improper access controls. This vulnerabi
CVE-2026-78078 | Joomshaper Helix Ultimate Extension up to 2.2.9 unrestricted upload (EUVD-2026-68527)
A vulnerability classified as problematic was found in Joomshaper Helix Ultimate Extension up to 2.2.9. Affected by this vulnerability is an unknown functionality. The manipulation results in unrestricted upload. This vulnerability is known
CVE-2026-78078 | Joomshaper Helix Ultimate Extension up to 2.2.9 unrestricted upload (EUVD-2026-68527)
A vulnerability classified as problematic was found in Joomshaper Helix Ultimate Extension up to 2.2.9. Affected by this vulnerability is an unknown functionality. The manipulation results in unrestricted upload. This vulnerability is known
CVE-2026-78076 | JoomShaper Helix Ultimate Extension up to 2.2.9 MegaMenu Settings access control (EUVD-2026-68528)
A vulnerability described as problematic has been identified in JoomShaper Helix Ultimate Extension up to 2.2.9. This impacts an unknown function of the component MegaMenu Settings. Executing a manipulation can lead to improper access contr
CVE-2026-78076 | JoomShaper Helix Ultimate Extension up to 2.2.9 MegaMenu Settings access control (EUVD-2026-68528)
A vulnerability described as problematic has been identified in JoomShaper Helix Ultimate Extension up to 2.2.9. This impacts an unknown function of the component MegaMenu Settings. Executing a manipulation can lead to improper access contr
CVE-2026-82217 | Eclipse Theia up to 1.74.x Agent Mode writeFileContent path path traversal (EUVD-2026-68519)
A vulnerability was found in Eclipse Theia up to 1.74.x and classified as critical. Affected by this issue is the function writeFileContent of the component Agent Mode. Such manipulation of the argument path leads to path traversal. This vu
CVE-2026-82217 | Eclipse Theia up to 1.74.x Agent Mode writeFileContent path path traversal (EUVD-2026-68519)
A vulnerability was found in Eclipse Theia up to 1.74.x and classified as critical. Affected by this issue is the function writeFileContent of the component Agent Mode. Such manipulation of the argument path leads to path traversal. This vu
CVE-2026-78075 | Joomshaper Helix Ultimate Extension up to 2.2.9 Blog Image Deletion Blog::remove_image src improper authorization (EUVD-2026-68529)
A vulnerability labeled as problematic has been found in Joomshaper Helix Ultimate Extension up to 2.2.9. Affected is the function Blog::remove_image of the component Blog Image Deletion. Executing a manipulation of the argument src can lea
CVE-2026-78075 | Joomshaper Helix Ultimate Extension up to 2.2.9 Blog Image Deletion Blog::remove_image src improper authorization (EUVD-2026-68529)
A vulnerability labeled as problematic has been found in Joomshaper Helix Ultimate Extension up to 2.2.9. Affected is the function Blog::remove_image of the component Blog Image Deletion. Executing a manipulation of the argument src can lea
CVE-2026-82700 | code-projects Online Shopping System 1.0 Newsletter Subscription /offersmail.php email cross site scripting (EUVD-2026-68530)
A vulnerability categorized as problematic has been discovered in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component Newsletter Subscription. The
CVE-2026-82700 | code-projects Online Shopping System 1.0 Newsletter Subscription /offersmail.php email cross site scripting (EUVD-2026-68530)
A vulnerability categorized as problematic has been discovered in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component Newsletter Subscription. The
CVE-2026-51681 | TOTOLINK T6 4.1.5cu.748_B20211015 /cgi-bin/cstecgi.cgi setRemoteCfg access control (EUVD-2026-68544)
A vulnerability classified as very critical has been found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. This vulnerability
CVE-2026-51681 | TOTOLINK T6 4.1.5cu.748_B20211015 /cgi-bin/cstecgi.cgi setRemoteCfg access control (EUVD-2026-68544)
A vulnerability classified as very critical has been found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. This vulnerability
USN-8678-3: OpenSSL vulnerability
USN-8673-1 fixed vulnerabilities in OpenSSL. The update inadvertently left out the fix for CVE-2026-75803 in Ubuntu 26.04 LTS. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered t
USN-8678-3: OpenSSL vulnerability
USN-8673-1 fixed vulnerabilities in OpenSSL. The update inadvertently left out the fix for CVE-2026-75803 in Ubuntu 26.04 LTS. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered t
USN-8699-1: libssh vulnerabilities
It was discovered that libssh had a stack buffer overflow in its SFTP server when constructing directory listing entries for long filenames. An attacker could possibly use this issue to cause libssh to crash or execute arbitrary code. This
USN-8699-1: libssh vulnerabilities
It was discovered that libssh had a stack buffer overflow in its SFTP server when constructing directory listing entries for long filenames. An attacker could possibly use this issue to cause libssh to crash or execute arbitrary code. This
Root-Sicherheitslücke bedroht cPanel/WHM
In aktuellen Versionen haben die Entwickler der Webhosting-Control-Panel-Software cPanel/WHM eine Schwachstelle geschlossen. Weiterlesen
Exchange-Sicherheitslücke: 85 Prozent der On-Prem-Server in Deutschland anfällig
Ein Proof-of-Concept-Exploit für eine hochriskante Exchange-Lücke ist öffentlich. 85 Prozent der On-Premises-Server sind anfällig. Weiterlesen
PaperCut vulnerability poc.
🛠️ CVE-2023-27350 (and Chained CVE-2026-81578/82078) - Step-by-Step Exploitation &amp; Analysis Workflow A critical vulnerability has been analyzed. Here is the technical breakdown, tool usage, and execution workflow for security teams
CVE-2026-82485 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the argument ID leads to sql injection. The atta
CVE-2026-82484 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The
CVE-2026-82483 | A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.6.29 will fix this issue. It is recommended to upgrade the affected component.
A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site script
CVE-2026-82482 | A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biography leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.6.29 mitigates this issue. Upgrading the affected component is recomme
A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biogra
CVE-2026-82480 | A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation
CVE-2026-82479 | A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow
CVE-2026-15980 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for unauthenticated attackers to generate an activation token for an unconfirmed user account and obtain a valid authentication cookie for that account, including administrators. Successful ex
The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() fu
CVE-2026-82478 | A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket H
CVE-2026-77846 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested JSON the application never exposed, disclosing private or sensitive? embedded fields. AshSqlite.SqlImplementation builds the SQLite json_extract path with "$." <> Enum.join(right, "."), so a single segment containing ., [, ], or $ re-interprets the JSON path (for example "private.
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested JSON the application never exposed, disclosing private or s
CVE-2026-75759 | Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. oidcc instead accepted a
Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1
CVE-2026-77831 | Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, AshPaperTrail.ChangeBuilders.FullDiff.ListChange pairs each prior array element against the new list by rebuilding the remaining-elements accumulator with acc ++ [tuple] on every step, co
Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory us
CVE-2026-77970 | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. sensitive_attributes :redact and :ignore only act on the tracked resource's top-level attributes. maybe_redact_changes/3 and the stored-action-input path in AshPaperTrail.Resource.Changes.CreateNewVersion derive the sensitiv
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. s
CVE-2026-75847 | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes. AshPaperTrail stores the values of tracked sensitive? attributes in the generated version resource's changes map, which is declared public? true and sensitive? false, so the values are returned by the version resource's default read action and printed i
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes. AshPaperTrail stores the value
CVE-2026-82562 | ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`), an indexed key (`a[0]=`), a nested key (`a[b]=`), or a dotted key (`a.b=` with `allowDots`) throws the documented `RangeError`. A single parameter such as `a[]=1,2,2,...` therefore pr
### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the sam
CVE-2026-82417 | ### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor: { isBuffer: "x" } }` makes the call throw `TypeError: obj.constructor.isBuffer is not a function`. ### Details `lib/stringify.js:127` c
### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` af
CVE-2026-82424 | A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a manipulation of the argument ID can lead to sql injection. T
CVE-2026-82423 | A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement
CVE-2026-82422 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of the argument ID results in sql injection. The attack may be launched rem
CVE-2026-82421 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the argument ID leads to sql injection. The attack may be initiat
CVE-2026-15369 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in the af_reg_checkout_data_to_order_meta_data_block() function, persisting it in order meta, and then passing it directly to WP_User::add_role()
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value
CVE-2026-75807 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_saml_required_certificate option before the signature-validation verdict is enforced, because mo_saml_find_certificate() returns false on a fingerprint mismatch rather than halting exec
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from
CVE-2026-82476 | Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server request internal hosts in that range including cloud metadata services and read page titles and descriptions back.
Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server request internal hosts
CVE-2026-82475 | iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' wo
CVE-2026-82473 | KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade scheduling.
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane
CVE-2026-82474 | Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, b
CVE-2026-82472 | Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust st
CVE-2026-82469 | Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST methods to obtain a new valid access token, enabling indefinite account access with temporary token possession.
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST meth
CVE-2026-82470 | Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift window to bypass the second authentication factor.
Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift window to bypa
CVE-2026-82468 | Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings t
CVE-2026-82466 | Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credential binding to complete authentication as arbitrary users.
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to s
CVE-2026-82467 | Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers resolve as protocol-relative URLs, redirecting authenticated users to attacker-controlled sites after login or password confirmation.
Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slas