Common Vulnerabilities and Exposures (CVE)

CVE-2026-74849

Sep 22, 2026 11:55:32 UTC

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

CVE-2026-87119

Sep 22, 2026 11:16:56 UTC

Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id, e...

CVE-2026-89420

Sep 22, 2026 11:16:29 UTC

Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats a v...

CVE-2026-95270

Sep 22, 2026 11:15:11 UTC

A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. This manipulation of the argument Password c...

CVE-2026-63279

Sep 22, 2026 11:10:41 UTC

LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the nu...

CVE-2026-63278

Sep 22, 2026 11:10:36 UTC

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 d...

CVE-2026-63276

Sep 22, 2026 11:10:32 UTC

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were ...

CVE-2026-63275

Sep 22, 2026 11:10:26 UTC

LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array c...

CVE-2026-63274

Sep 22, 2026 11:10:19 UTC

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually present, ...

CVE-2026-63273

Sep 22, 2026 11:10:13 UTC

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size key b...

CVE-2026-63272

Sep 22, 2026 11:10:03 UTC

LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were ...

CVE-2026-95511

Sep 22, 2026 10:53:33 UTC

A privilege escalation vulnerability was found in CUPS when used with the cups-filters serial backend. A local user who is a member of the lpadmin group can configure a printer that uses a privileged serial backend. The CUPS scheduler does ...

CVE-2026-87743

Sep 22, 2026 10:53:21 UTC

A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the securit...

CVE-2026-95623

Sep 22, 2026 10:52:20 UTC

The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally withou...

CVE-2026-68956

Sep 22, 2026 10:44:31 UTC

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are never assigned a handler. The "session" cla...