Common Vulnerabilities and Exposures (CVE)

CVE-2026-60011

Aug 3, 2026 11:16:54 UTC

Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.

CVE-2026-63545

Aug 3, 2026 11:12:38 UTC

Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.

CVE-2026-63563

Aug 3, 2026 11:11:35 UTC

Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a ...

CVE-2026-62416

Aug 3, 2026 11:09:46 UTC

Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, an...

CVE-2026-68582

Aug 3, 2026 11:03:04 UTC

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from...

CVE-2026-68581

Aug 3, 2026 11:03:03 UTC

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-s...

CVE-2026-65321

Aug 3, 2026 11:03:02 UTC

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statemen...

CVE-2025-71401

Aug 3, 2026 11:03:01 UTC

better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the server after startup can poison the rou...

CVE-2025-71399

Aug 3, 2026 11:03:00 UTC

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to ...

CVE-2026-69075

Aug 3, 2026 11:00:05 UTC

FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted values—including case titles, ticket identifiers, recurring-case information, user profile ...

CVE-2026-69078

Aug 3, 2026 10:56:06 UTC

CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI content, including conversion names, descriptions, and comments, is converted from Markdown...

CVE-2026-69079

Aug 3, 2026 10:52:28 UTC

CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a reasonable range. A remo...

CVE-2026-33591

Aug 3, 2026 10:51:35 UTC

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a valid session token for the targeted account.

CVE-2026-69082

Aug 3, 2026 10:45:04 UTC

CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoint accepted HTTP GET requests for an operation that modified application state. An unauthe...

CVE-2025-2842

Aug 3, 2026 10:42:43 UTC

A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to gr...