Common Vulnerabilities and Exposures (CVE)

CVE-2026-60004

Aug 26, 2026 22:56:00 UTC

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

CVE-2026-47665

Aug 26, 2026 22:50:34 UTC

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with...

CVE-2026-47666

Aug 26, 2026 22:47:49 UTC

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and in...

CVE-2026-65956

Aug 26, 2026 22:40:55 UTC

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SA...

CVE-2026-77998

Aug 26, 2026 22:35:35 UTC

Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps ...

CVE-2026-75953

Aug 26, 2026 22:33:42 UTC

Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to ...

CVE-2026-63048

Aug 26, 2026 22:30:17 UTC

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

CVE-2026-81203

Aug 26, 2026 22:30:11 UTC

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possib...

CVE-2025-62341

Aug 26, 2026 22:24:39 UTC

HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass...

CVE-2026-75340

Aug 26, 2026 22:16:16 UTC

The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).

CVE-2026-75336

Aug 26, 2026 22:14:03 UTC

Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.

CVE-2026-75338

Aug 26, 2026 22:11:07 UTC

disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authenti...

CVE-2026-75330

Aug 26, 2026 22:09:05 UTC

The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() an...

CVE-2026-14330

Aug 26, 2026 22:08:31 UTC

Multiple unbounded alloca() calls in the PulseAudio protocol server.

CVE-2026-14324

Aug 26, 2026 22:08:30 UTC

RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.