Common Vulnerabilities and Exposures (CVE)

CVE-2026-108580

Oct 10, 2026 15:57:49 UTC

AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler that allows unauthenticated attackers to guess passwords without throttling. Attackers can enumerate...

CVE-2026-108579

Oct 10, 2026 15:57:48 UTC

OpenPanel through 2.3.0 contains a CSV formula injection vulnerability that allows unauthenticated attackers to embed spreadsheet formulas by supplying crafted profile IDs to the /track endpoint. Attackers can send tracking events with prof...

CVE-2025-8511

Oct 10, 2026 15:56:33 UTC

A vulnerability was found in Portabilis i-Diario 1.5.0. Impacted is an unknown function of the file /diario-de-observacoes/ of the component Observações. Performing a manipulation of the argument Descrição results in cross site scripting. I...

CVE-2026-108555

Oct 10, 2026 14:49:39 UTC

PairDrop through 1.11.2 contains an IP spoofing vulnerability in Peer._setIP that allows remote attackers to join other networks' discovery rooms by supplying a forged cf-connecting-ip header. Attackers who know a victim's public IP can app...

CVE-2026-108554

Oct 10, 2026 14:49:39 UTC

PDFMathTranslate (pdf2zh) through 1.9.11 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the server fetch arbitrary URLs via the Link input. The translate_file handler passes user URLs to d...

CVE-2026-108553

Oct 10, 2026 14:49:38 UTC

OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET...

CVE-2026-108551

Oct 10, 2026 14:35:05 UTC

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Atta...

CVE-2026-108550

Oct 10, 2026 14:35:04 UTC

SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the mer...

CVE-2026-108549

Oct 10, 2026 14:35:04 UTC

cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching th...

CVE-2026-108548

Oct 10, 2026 14:35:03 UTC

AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that accepts any Bearer token without validation. Unauthenticated attackers can send arbitrary Bearer values to reach /api/r...

CVE-2026-108547

Oct 10, 2026 14:35:03 UTC

AstronRPA through 1.1.6 contains a missing tenant authorization check in robot-service that allows authenticated users to read other tenants' shared variables via the get-batch-shared-var endpoint. Attackers can enumerate sequential shared ...

CVE-2026-108546

Oct 10, 2026 14:15:52 UTC

Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet ...

CVE-2026-108545

Oct 10, 2026 14:15:52 UTC

SillyTavern 1.12.13 through 1.19.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust resources because body-parser middleware runs before authentication and whitelist checks. Attackers can se...

CVE-2026-108115

Oct 10, 2026 14:15:51 UTC

Kortix Suna 0.10.7 before 0.13.52 contains a server-side request forgery vulnerability that allows project managers to bypass the isPrivateIp guard by supplying IPv6 6to4 or Teredo addresses that embed private IPv4 destinations. Attackers h...

CVE-2026-108114

Oct 10, 2026 14:15:50 UTC

Strapi 5.47.0 through 5.57.0 contains an improper authorization vulnerability that allows admin API tokens to retain all-field Content Manager access after the owner's role is field-restricted. Because reconcileTokenPermissionsToUserCeiling...