Common Vulnerabilities and Exposures (CVE)

CVE-2026-104335

Oct 6, 2026 23:57:43 UTC

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.

CVE-2026-106583

Oct 6, 2026 23:42:14 UTC

In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection.

CVE-2026-80048

Oct 6, 2026 23:28:11 UTC

A flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX socket can exploit this vulnerability. By sending a large request length header and then stalling the connection, an attacker can cause the syste...

CVE-2025-9290

Oct 6, 2026 23:18:29 UTC

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to i...

CVE-2026-96577

Oct 6, 2026 23:09:49 UTC

A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacke...

CVE-2026-83589

Oct 6, 2026 23:09:41 UTC

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially c...

CVE-2026-49329

Oct 6, 2026 23:09:24 UTC

A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-3214...

CVE-2026-105186

Oct 6, 2026 22:22:54 UTC

A flaw has been found in itsourcecode Online Admission System 1.0. This impacts an unknown function of the file /new.php. Executing a manipulation of the argument schedid can lead to sql injection. The attack can be launched remotely. The e...

CVE-2026-105182

Oct 6, 2026 22:21:56 UTC

A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=update. The manipulation of the argu...

CVE-2026-105178

Oct 6, 2026 22:20:31 UTC

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. The impacted element is the function mysqli_real_escape_string of the file /Admin/add_symptom.php of the component Symptom Creation. Performing a manipula...

CVE-2026-105292

Oct 6, 2026 22:19:41 UTC

Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback with...

CVE-2026-105174

Oct 6, 2026 22:18:19 UTC

A vulnerability has been found in Gerapy up to 0.9.13. This vulnerability affects the function project_create of the file gerapy/server/core/views.py of the component Project Management. The manipulation of the argument project_name leads t...

CVE-2026-95264

Oct 6, 2026 22:17:18 UTC

Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. Article image metadata is used to construct a filesystem path and is pa...

CVE-2026-95166

Oct 6, 2026 22:15:33 UTC

In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload.

CVE-2026-88396

Oct 6, 2026 22:12:46 UTC

ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move_uploa...