CVE-2026-102395 - WordPress Easy Google Maps plugin <= 1.14.6 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-102395
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102395
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102396 - WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-102396
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102396
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102398 - WordPress Popup by Supsystic plugin <= 1.13.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-102398
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102398
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102399 - WordPress Photo Gallery by Supsystic plugin <= 1.21.0 - Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-102399
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102399
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103116 - OS4ED openSIS-Classic Student List Search Endpoint GetStuListFnc.php DBQuery sql injection
CVE ID :CVE-2026-103116
Published : Sept. 30, 2026, 12:45 p.m. | 45 minutes ago
Description :A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-103116
Published : Sept. 30, 2026, 12:45 p.m. | 45 minutes ago
Description :A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86778 - Username Enumeration in Maksisoft Technology's Maksisoft Gym
CVE ID :CVE-2026-86778
Published : Sept. 30, 2026, 12:59 p.m. | 30 minutes ago
Description :Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting. This issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-86778
Published : Sept. 30, 2026, 12:59 p.m. | 30 minutes ago
Description :Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting. This issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103117 - OS4ED openSIS-Classic Save Data DatabaseInc.php db_properties sql injection
CVE ID :CVE-2026-103117
Published : Sept. 30, 2026, 1 p.m. | 29 minutes ago
Description :A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-103117
Published : Sept. 30, 2026, 1 p.m. | 29 minutes ago
Description :A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76504 - Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability
CVE ID :CVE-2026-76504
Published : Sept. 30, 2026, 1:04 p.m. | 25 minutes ago
Description :A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-76504
Published : Sept. 30, 2026, 1:04 p.m. | 25 minutes ago
Description :A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91860 - Prototype Pollution in Vaadin Charts and Component Base via Unfiltered Deep Merge
CVE ID :CVE-2026-91860
Published : Sept. 30, 2026, 1:13 p.m. | 17 minutes ago
Description :A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the running application. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 23.0.0 - 23.6.13 Vaadin 24.0.0 - 24.9.20 Vaadin 24.10.0 - 24.10.9 Vaadin 25.0.0 - 25.1.11 Vaadin 25.2.0 - 25.2.6 Mitigation Upgrade to 23.6.14 Upgrade to 24.9.21 Upgrade to 24.10.10 Upgrade to 25.1.12 Upgrade to 25.2.7 or newer Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version. Artifacts Maven coordinates Vulnerable versions Fixed version com.vaadin:vaadin 23.0.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin 24.0.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-core 24.7.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin-core 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-core 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-core 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-charts-flow 23.0.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin-charts-flow 24.0.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin-charts-flow 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-charts-flow 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-charts-flow 25.2.0 - 25.2.6 >=25.2.7 npm packages npm package Vulnerable versions Fixed version @vaadin/charts 23.0.0 - 23.6.4 >=23.6.5 @vaadin/charts 24.0.0 - 24.9.17 >=24.9.18 @vaadin/charts 24.10.0 - 24.10.4 >=24.10.5 @vaadin/charts 25.0.0 - 25.1.11 >=25.1.12 @vaadin/charts 25.2.0 - 25.2.8 >=25.2.9 @vaadin/component-base 24.7.0 - 24.9.17 >=24.9.18 @vaadin/component-base 24.10.0 - 24.10.4 >=24.10.5 @vaadin/component-base 25.0.0 - 25.1.11 >=25.1.12 @vaadin/component-base 25.2.0 - 25.2.8 >=25.2.9
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-91860
Published : Sept. 30, 2026, 1:13 p.m. | 17 minutes ago
Description :A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the running application. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 23.0.0 - 23.6.13 Vaadin 24.0.0 - 24.9.20 Vaadin 24.10.0 - 24.10.9 Vaadin 25.0.0 - 25.1.11 Vaadin 25.2.0 - 25.2.6 Mitigation Upgrade to 23.6.14 Upgrade to 24.9.21 Upgrade to 24.10.10 Upgrade to 25.1.12 Upgrade to 25.2.7 or newer Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version. Artifacts Maven coordinates Vulnerable versions Fixed version com.vaadin:vaadin 23.0.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin 24.0.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-core 24.7.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin-core 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-core 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-core 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-charts-flow 23.0.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin-charts-flow 24.0.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin-charts-flow 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-charts-flow 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-charts-flow 25.2.0 - 25.2.6 >=25.2.7 npm packages npm package Vulnerable versions Fixed version @vaadin/charts 23.0.0 - 23.6.4 >=23.6.5 @vaadin/charts 24.0.0 - 24.9.17 >=24.9.18 @vaadin/charts 24.10.0 - 24.10.4 >=24.10.5 @vaadin/charts 25.0.0 - 25.1.11 >=25.1.12 @vaadin/charts 25.2.0 - 25.2.8 >=25.2.9 @vaadin/component-base 24.7.0 - 24.9.17 >=24.9.18 @vaadin/component-base 24.10.0 - 24.10.4 >=24.10.5 @vaadin/component-base 25.0.0 - 25.1.11 >=25.1.12 @vaadin/component-base 25.2.0 - 25.2.8 >=25.2.9
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93547 - Missing Authorization Check in Vaadin Spreadsheet Allows Cell Comments to Be Written to Protected Sheets and Locked Cells
CVE ID :CVE-2026-93547
Published : Sept. 30, 2026, 1:13 p.m. | 16 minutes ago
Description :A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell comments on a sheet that has protection enabled, including on cells that are locked. Writing a comment to a cell that does not exist yet also creates the row and the cell. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 23.1.0 - 23.6.13 Vaadin 24.0.0 - 24.9.21 Vaadin 24.10.0 - 24.10.9 Vaadin 25.0.0 - 25.1.11 Vaadin 25.2.0 - 25.2.6 Vaadin Framework 7 and 8 with the Spreadsheet add-on 2.0.0 - 3.1.0 Mitigation Upgrade to 23.6.14 Upgrade to 24.9.22 Upgrade to 24.10.10 Upgrade to 25.1.12 Upgrade to 25.2.7 or newer Upgrade the Spreadsheet add-on to 3.1.1 Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version. Artifacts Maven coordinates Vulnerable versions Fixed version com.vaadin:vaadin 23.1.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin 24.0.0 - 24.9.21 >=24.9.22 com.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-spreadsheet-flow 23.1.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin-spreadsheet-flow 24.0.0 - 24.9.21 >=24.9.22 com.vaadin:vaadin-spreadsheet-flow 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-spreadsheet-flow 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-spreadsheet-flow 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-spreadsheet 2.0.0 - 3.1.0 >=3.1.1
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-93547
Published : Sept. 30, 2026, 1:13 p.m. | 16 minutes ago
Description :A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell comments on a sheet that has protection enabled, including on cells that are locked. Writing a comment to a cell that does not exist yet also creates the row and the cell. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 23.1.0 - 23.6.13 Vaadin 24.0.0 - 24.9.21 Vaadin 24.10.0 - 24.10.9 Vaadin 25.0.0 - 25.1.11 Vaadin 25.2.0 - 25.2.6 Vaadin Framework 7 and 8 with the Spreadsheet add-on 2.0.0 - 3.1.0 Mitigation Upgrade to 23.6.14 Upgrade to 24.9.22 Upgrade to 24.10.10 Upgrade to 25.1.12 Upgrade to 25.2.7 or newer Upgrade the Spreadsheet add-on to 3.1.1 Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version. Artifacts Maven coordinates Vulnerable versions Fixed version com.vaadin:vaadin 23.1.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin 24.0.0 - 24.9.21 >=24.9.22 com.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-spreadsheet-flow 23.1.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin-spreadsheet-flow 24.0.0 - 24.9.21 >=24.9.22 com.vaadin:vaadin-spreadsheet-flow 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-spreadsheet-flow 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-spreadsheet-flow 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-spreadsheet 2.0.0 - 3.1.0 >=3.1.1
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82307 - Multiple Vulnerabilities in Dolusoft Software's SOPLOG
CVE ID :CVE-2026-82307
Published : Sept. 30, 2026, 1:20 p.m. | 9 minutes ago
Description :Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-82307
Published : Sept. 30, 2026, 1:20 p.m. | 9 minutes ago
Description :Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55174 - UltrafastSecp256k1: ECDSA adaptor verification accepts non-adaptable pre-signatures due to missing DLEQ binding
CVE ID :CVE-2026-55174
Published : Sept. 30, 2026, 4:17 p.m. | 1 hour, 13 minutes ago
Description :UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verification accepts forged adaptor pre-signatures whose "r" value is not cryptographically bound to the adaptor point "T". This issue has been patched in version 4.2.0.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-55174
Published : Sept. 30, 2026, 4:17 p.m. | 1 hour, 13 minutes ago
Description :UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verification accepts forged adaptor pre-signatures whose "r" value is not cryptographically bound to the adaptor point "T". This issue has been patched in version 4.2.0.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-80490 - Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified
CVE ID :CVE-2026-80490
Published : Sept. 30, 2026, 4:19 p.m. | 1 hour, 11 minutes ago
Description :Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the haystack input, and the SvCUR macro to determine the length of the SV. When the input SVs are references, integers (IVs) or floats (NVs), the SvCUR macro will return an invalid length if it is run before the input is stringified, leading to an out-of-bounds read which can abort the process. Note that the evaluation order of arguments to std::string is unspecified. Depending on the compiler, SvCUR may be run first and lead to an abort that cannot be caught within Perl. This can be triggered when the haystack is a numeric value, for example, my $ac = Algorithm::AhoCorasick::XS->new( [ "11", "22" ] ); $ac->matches( 211 ); This can occur when the haystack is the result of reading data from decoded JSON or a numeric database column. It can also be triggered when using a blessed object as a haystack.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-80490
Published : Sept. 30, 2026, 4:19 p.m. | 1 hour, 11 minutes ago
Description :Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the haystack input, and the SvCUR macro to determine the length of the SV. When the input SVs are references, integers (IVs) or floats (NVs), the SvCUR macro will return an invalid length if it is run before the input is stringified, leading to an out-of-bounds read which can abort the process. Note that the evaluation order of arguments to std::string is unspecified. Depending on the compiler, SvCUR may be run first and lead to an abort that cannot be caught within Perl. This can be triggered when the haystack is a numeric value, for example, my $ac = Algorithm::AhoCorasick::XS->new( [ "11", "22" ] ); $ac->matches( 211 ); This can occur when the haystack is the result of reading data from decoded JSON or a numeric database column. It can also be triggered when using a blessed object as a haystack.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87004 - Tugtainer: OIDC id_token claims accepted without signature/audience/expiry verification
CVE ID :CVE-2026-87004
Published : Sept. 30, 2026, 5:01 p.m. | 29 minutes ago
Description :Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-87004
Published : Sept. 30, 2026, 5:01 p.m. | 29 minutes ago
Description :Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103445 - Stored XSS through PageForms #autoedit redirect links
CVE ID :CVE-2026-103445
Published : Sept. 30, 2026, 5:04 p.m. | 26 minutes ago
Description :Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43.
Severity: 1.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-103445
Published : Sept. 30, 2026, 5:04 p.m. | 26 minutes ago
Description :Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43.
Severity: 1.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55107 - Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
CVE ID :CVE-2026-55107
Published : Sept. 30, 2026, 5:06 p.m. | 25 minutes ago
Description :Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-55107
Published : Sept. 30, 2026, 5:06 p.m. | 25 minutes ago
Description :Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-53605 - Reachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo systemctl Grant
CVE ID :CVE-2026-53605
Published : Sept. 30, 2026, 5:09 p.m. | 21 minutes ago
Description :Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-53605
Published : Sept. 30, 2026, 5:09 p.m. | 21 minutes ago
Description :Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103446 - WikiLambda exposes anonymous execution of unsaved Abstract Wikipedia fragments
CVE ID :CVE-2026-103446
Published : Sept. 30, 2026, 5:13 p.m. | 18 minutes ago
Description :Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-103446
Published : Sept. 30, 2026, 5:13 p.m. | 18 minutes ago
Description :Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103500 - Heap buffer overflow opening large email
CVE ID :CVE-2026-103500
Published : Sept. 30, 2026, 5:15 p.m. | 15 minutes ago
Description :An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-103500
Published : Sept. 30, 2026, 5:15 p.m. | 15 minutes ago
Description :An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102489 - Undisclosed RCE in Zammad v6.3 and higher
CVE ID :CVE-2026-102489
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102489
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102490 - Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha
CVE ID :CVE-2026-102490
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102490
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...