Common Vulnerabilities and Exposures (CVE)

CVE-2026-85082

Sep 24, 2026 23:48:37 UTC

Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command.

CVE-2026-84283

Sep 24, 2026 23:41:34 UTC

Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy, a...

CVE-2026-82368

Sep 24, 2026 23:35:11 UTC

Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed acce...

CVE-2024-1753

Sep 24, 2026 23:35:07 UTC

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root ...

CVE-2026-82369

Sep 24, 2026 23:34:32 UTC

Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authenticated users to break out of restricted execution contexts on managed switches. An attacker with command execution permissi...

CVE-2026-14441

Sep 24, 2026 23:31:29 UTC

A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue has been remediated by updating the internal comparison routines to ...

CVE-2026-14442

Sep 24, 2026 23:16:33 UTC

An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sensit...

CVE-2026-94493

Sep 24, 2026 22:55:54 UTC

A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can...

CVE-2026-94426

Sep 24, 2026 22:55:25 UTC

A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotel...

CVE-2026-94626

Sep 24, 2026 22:54:41 UTC

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode di...

CVE-2026-94540

Sep 24, 2026 22:53:24 UTC

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's loca...

CVE-2026-61852

Sep 24, 2026 22:51:50 UTC

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in server/modules/ai/orchestrator/tools/runQuery.js interpo...

CVE-2026-94532

Sep 24, 2026 22:50:33 UTC

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can iterate the userId parameter to harvest sensitive ...

CVE-2026-59815

Sep 24, 2026 22:49:51 UTC

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to items with a share ID when any share_users row exists ...

CVE-2026-55105

Sep 24, 2026 22:48:03 UTC

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, packages/renderer/MdToHtml/rules/fountain.ts passes HTML generated by the vendored fountain.js renderer int...