Common Vulnerabilities and Exposures (CVE)

CVE-2026-13201

Jun 25, 2026 23:23:24 UTC

A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-f...

CVE-2026-13218

Jun 25, 2026 23:23:23 UTC

A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink protection. A user with access to the virt-launcher con...

CVE-2026-12993

Jun 25, 2026 23:23:20 UTC

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-write permission can...

CVE-2026-56053

Jun 25, 2026 23:23:16 UTC

Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.

CVE-2026-56014

Jun 25, 2026 23:21:47 UTC

Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.

CVE-2026-54845

Jun 25, 2026 23:21:07 UTC

Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.

CVE-2026-54821

Jun 25, 2026 23:20:16 UTC

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.

CVE-2026-12079

Jun 25, 2026 23:18:52 UTC

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparat...

CVE-2026-40079

Jun 25, 2026 23:17:29 UTC

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is ...

CVE-2026-39899

Jun 25, 2026 23:15:40 UTC

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter in package_import.php. This issue has been fixed in version 1.2.31.

CVE-2026-53766

Jun 25, 2026 23:14:04 UTC

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces workspace roots by checking whether path.resolve(filePath) textua...

CVE-2026-9220

Jun 25, 2026 23:13:41 UTC

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initialization vectors. This allows an attacker to decrypt Setracker2 watc...

CVE-2026-54158

Jun 25, 2026 23:12:30 UTC

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsset. A cell value like...

CVE-2026-55759

Jun 25, 2026 23:10:28 UTC

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Rocket.Chat's Apple Sign-In handler verifies JWT signatures but skips claims validation. Any ...

CVE-2026-9219

Jun 25, 2026 23:10:19 UTC

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain t...