CVE IDSeverityCVSSDescriptionDate
CVE-2026-81624HIGH7.5Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow h…2026-08-31
CVE-2026-82659HIGH7.1nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw optio…2026-08-31
CVE-2026-82660MEDIUM5.4Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normali…2026-08-31
CVE-2026-82661MEDIUM5.4Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, all…2026-08-31
CVE-2026-82662MEDIUM6.5Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized…2026-08-31
CVE-2026-82664MEDIUM4.3A security vulnerability has been detected in yaojingang GEOFlow up to 2.1.0. This affects an unknown part of …2026-08-31
CVE-2026-82665LOW3.8A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink…2026-08-31
CVE-2026-82666MEDIUM4.7A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue affects the function preview of the file a…2026-08-31
CVE-2026-82667MEDIUM4.7A vulnerability has been found in yaojingang GEOFlow up to 2.1.0. Impacted is the function DistributionControl…2026-08-31
CVE-2026-82668HIGH7.3A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by this vulnerability is t…2026-08-31
CVE-2026-82853MEDIUM4.9Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option …2026-08-31
CVE-2026-82854CRITICAL9.8Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size paramete…2026-08-31
CVE-2026-82855CRITICAL9.8@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and d…2026-08-31
CVE-2026-82856CRITICAL9.8@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in …2026-08-31
CVE-2026-82857CRITICAL9.8hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM polic…2026-08-31
CVE-2026-82858CRITICAL9.8@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance val…2026-08-31
CVE-2026-82859CRITICAL9.8hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:…2026-08-31
CVE-2026-82860CRITICAL9.8@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the a…2026-08-31
CVE-2026-82861HIGH7.5@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to su…2026-08-31
CVE-2026-82862HIGH8.4Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace f…2026-08-31
CVE-2026-82863LOW3.3@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing aud…2026-08-31
CVE-2026-82864MEDIUM6.5pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensu…2026-08-31
CVE-2026-82865MEDIUM4.4pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property pa…2026-08-31
CVE-2026-82866MEDIUM6.8@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function…2026-08-31
CVE-2026-82867MEDIUM6.1@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fai…2026-08-31
CVE-2026-82868MEDIUM6.1@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that render…2026-08-31
CVE-2026-82869HIGH7.7ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endp…2026-08-31
CVE-2026-82870CRITICAL9.6ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allo…2026-08-31
CVE-2026-82871HIGH7.7ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authe…2026-08-31
CVE-2026-82872CRITICAL9.1ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's works…2026-08-31
CVE-2026-82873MEDIUM5.0ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/ex…2026-08-31
CVE-2026-82874CRITICAL9.9ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in th…2026-08-31
CVE-2026-82875MEDIUM5.5ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that…2026-08-31
CVE-2026-19873HIGH7.5HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the q…2026-08-31
CVE-2026-49003CRITICAL9.6Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monit…2026-08-31
CVE-2026-82669MEDIUM5.3A vulnerability was detected in klaussilveira GitList 2.0.0. Affected by this issue is the function SimpleXMLE…2026-08-31
CVE-2026-82670MEDIUM4.4A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the function IRP_MJ_DEVICE_CONTROL in the l…2026-08-31
CVE-2026-82671LOW3.4A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminate…2026-08-31
CVE-2026-82677LOW2.4A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the f…2026-08-31
CVE-2026-82678MEDIUM4.7A vulnerability was identified in diem-project diem up to 5.1.3. The affected element is the function executeC…2026-08-31
CVE-2026-82679MEDIUM6.3A security flaw has been discovered in diem-project diem up to 5.1.3. The impacted element is an unknown funct…2026-08-31
CVE-2026-82680HIGH8.8A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_fil…2026-08-31
CVE-2026-82688CRITICAL9.1A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. Th…2026-08-31
CVE-2026-82876HIGH8.2Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmw…2026-08-31
CVE-2026-82877MEDIUM6.5ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 contain an arbitrary file read vulnerabil…2026-08-31
CVE-2026-82878MEDIUM6.3DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard l…2026-08-31
CVE-2026-82879MEDIUM6.3DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not b…2026-08-31
CVE-2026-82880HIGH7.5YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and…2026-08-31
CVE-2026-82881MEDIUM5.4Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowin…2026-08-31
CVE-2026-70449MEDIUM5.3Improper validation of resource URL attributes in Apache Wicket allows an unauthenticated remote attacker to r…2026-08-31
16 / 7715