Common Vulnerabilities and Exposures (CVE)

CVE-2026-103474

Sep 30, 2026 17:50:39 UTC

yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directo...

CVE-2026-76504

Sep 30, 2026 17:49:40 UTC

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due...

CVE-2026-100653

Sep 30, 2026 17:46:36 UTC

vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-supplied model revision pin (--revision / --code-revision) is not propagated to several Hugging Face artifact loads for ...

CVE-2026-100697

Sep 30, 2026 17:43:47 UTC

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit ...

CVE-2025-50343

Sep 30, 2026 17:43:26 UTC

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and invalid...

CVE-2026-103399

Sep 30, 2026 17:42:31 UTC

A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the ...

CVE-2026-100689

Sep 30, 2026 17:41:12 UTC

GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field, and GitPyt...

CVE-2023-52355

Sep 30, 2026 17:39:49 UTC

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller...

CVE-2026-97265

Sep 30, 2026 17:39:48 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3.

CVE-2026-100681

Sep 30, 2026 17:39:28 UTC

Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint that accepts forged Bot Framework activities with arbitrary serviceUrl values. ...

CVE-2026-102392

Sep 30, 2026 17:39:08 UTC

Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.

CVE-2026-102391

Sep 30, 2026 17:39:07 UTC

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.

CVE-2026-102377

Sep 30, 2026 17:39:06 UTC

Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.

CVE-2026-102376

Sep 30, 2026 17:39:05 UTC

Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.

CVE-2026-102375

Sep 30, 2026 17:39:05 UTC

Subscriber Broken Access Control in Optimole <= 4.2.14 versions.