Common Vulnerabilities and Exposures (CVE)

CVE-2026-42218

Jul 20, 2026 17:52:34 UTC

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker can infer the existence of a username on t...

CVE-2026-52348

Jul 20, 2026 17:51:15 UTC

cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.

CVE-2026-32806

Jul 20, 2026 17:50:35 UTC

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenti...

CVE-2026-26483

Jul 20, 2026 17:48:45 UTC

Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input in the content parameter of the /templat...

CVE-2026-52584

Jul 20, 2026 17:48:03 UTC

Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function

CVE-2026-9323

Jul 20, 2026 17:46:06 UTC

The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twister PRNG, which is not cryptographically s...

CVE-2026-9147

Jul 20, 2026 17:46:05 UTC

uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the genera...

CVE-2026-61463

Jul 20, 2026 17:46:04 UTC

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATC...

CVE-2026-61462

Jul 20, 2026 17:46:04 UTC

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to esca...

CVE-2026-59713

Jul 20, 2026 17:46:03 UTC

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes t...

CVE-2026-59712

Jul 20, 2026 17:46:02 UTC

Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes, TOTP secrets, and session tokens. Attackers can exploit th...

CVE-2026-59709

Jul 20, 2026 17:46:02 UTC

Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attacker...

CVE-2026-59708

Jul 20, 2026 17:46:01 UTC

The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve...

CVE-2026-59707

Jul 20, 2026 17:46:00 UTC

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized gallery URL fields directly to gallery....

CVE-2026-59706

Jul 20, 2026 17:45:59 UTC

mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlled ollama_base_url parameter. Unauthenticated attackers can retrieve stored secrets like Ope...