Common Vulnerabilities and Exposures (CVE)

CVE-2026-103530

Sep 30, 2026 23:45:11 UTC

A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options....

CVE-2024-11831

Sep 30, 2026 23:41:31 UTC

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicio...

CVE-2026-103592

Sep 30, 2026 23:02:36 UTC

simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwar...

CVE-2026-103591

Sep 30, 2026 23:02:35 UTC

DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks...

CVE-2026-103590

Sep 30, 2026 23:02:35 UTC

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payl...

CVE-2026-103589

Sep 30, 2026 23:02:34 UTC

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-of...

CVE-2026-103588

Sep 30, 2026 23:02:33 UTC

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions paramete...

CVE-2026-103587

Sep 30, 2026 23:02:32 UTC

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Atta...

CVE-2026-84268

Sep 30, 2026 22:58:09 UTC

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the serve...

CVE-2026-16529

Sep 30, 2026 22:58:03 UTC

A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for...

CVE-2026-16527

Sep 30, 2026 22:57:57 UTC

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

CVE-2026-16526

Sep 30, 2026 22:57:56 UTC

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.

CVE-2026-16524

Sep 30, 2026 22:57:56 UTC

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

CVE-2026-83596

Sep 30, 2026 22:56:32 UTC

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

CVE-2026-78376

Sep 30, 2026 22:56:29 UTC

A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.