Common Vulnerabilities and Exposures (CVE)

CVE-2026-40550

Sep 30, 2026 11:18:10 UTC

Multiple BinSoft products are vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the application. An attacker with access to any running application instance connected to the backend server ...

CVE-2026-102374

Sep 30, 2026 11:15:14 UTC

GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitor...

CVE-2026-102373

Sep 30, 2026 11:15:13 UTC

GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' ticke...

CVE-2026-102372

Sep 30, 2026 11:15:13 UTC

GestSup versions before 3.2.61 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthenticated attackers to store arbitrary JavaScript in ticket descriptions and replies. Attackers can send emails to the mo...

CVE-2026-100389

Sep 30, 2026 11:15:12 UTC

GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to mon...

CVE-2026-103114

Sep 30, 2026 11:15:08 UTC

A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment Management Endpoint. The manipulation of the a...

CVE-2026-76992

Sep 30, 2026 11:07:45 UTC

The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger ex...

CVE-2026-13720

Sep 30, 2026 11:06:38 UTC

An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authoriz...

CVE-2026-13719

Sep 30, 2026 11:06:38 UTC

An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rul...

CVE-2026-100747

Sep 30, 2026 11:04:23 UTC

Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.

CVE-2026-96342

Sep 30, 2026 11:00:18 UTC

Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83.

CVE-2026-100749

Sep 30, 2026 10:54:26 UTC

Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted.

CVE-2026-97165

Sep 30, 2026 10:49:12 UTC

Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated.

CVE-2026-15442

Sep 30, 2026 10:48:05 UTC

In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a partial wolfSSL_read() which is...

CVE-2025-6170

Sep 30, 2026 10:39:51 UTC

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue m...