Common Vulnerabilities and Exposures (CVE)

CVE-2026-107208

Oct 7, 2026 22:06:12 UTC

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a recursion limit that is handled as a fatal condition instead of an ordinary ex...

CVE-2026-107166

Oct 7, 2026 22:06:04 UTC

A weakness has been identified in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pfcp_xact_local_create of the file src/upf/gtp-path.c of the component GTP-U Receive Path. This manipulation causes allocation of resources. ...

CVE-2026-62251

Oct 7, 2026 22:05:52 UTC

Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used thr...

CVE-2026-107213

Oct 7, 2026 22:05:46 UTC

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.9.0 to 2.11.0, GetSlicers checks for ExtLst but dereferences ws.Drawing without checking whether the independently optional drawing element exist...

CVE-2026-107218

Oct 7, 2026 22:05:36 UTC

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with UTF-16 code-unit counts but slices a rune array using Unicode code-point counts. RIGHT ...

CVE-2026-107223

Oct 7, 2026 22:05:27 UTC

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, flatCols expands file-loaded column ranges without validating Min and Max against the worksheet column limit. SetColWidth reaches ...

CVE-2026-89322

Oct 7, 2026 22:01:37 UTC

Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypass an explicit deny restriction and access...

CVE-2026-105820

Oct 7, 2026 21:48:08 UTC

Vault's ACL policy cache allowed namespace traversal when policy names contained path traversal constructs. This may allow a token assigned specially crafted policy names to use the capabilities of policies defined in other namespaces, incl...

CVE-2026-105389

Oct 7, 2026 21:45:38 UTC

A security vulnerability has been detected in feelec-yishu feelcrm-os 1.0.0. This issue affects some unknown processing of the file App/Feelcrm/Crm/Controller/UploadController.class.php of the component UploadTicketFile Endpoint. Such manip...

CVE-2026-105678

Oct 7, 2026 21:44:35 UTC

Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. T...

CVE-2026-104029

Oct 7, 2026 21:43:46 UTC

A flaw was found in SSSD. A local attacker can exploit this vulnerability by sending a specially crafted request to the autofs responder UNIX socket. Due to improper buffer offset calculation during request parsing, the service performs an ...

CVE-2026-105651

Oct 7, 2026 21:43:14 UTC

Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, includin...

CVE-2024-1394

Oct 7, 2026 21:43:00 UTC

A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.g...

CVE-2026-105646

Oct 7, 2026 21:41:48 UTC

Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed i...

CVE-2026-105641

Oct 7, 2026 21:40:29 UTC

Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when op...