Common Vulnerabilities and Exposures (CVE)

CVE-2026-80195

Aug 25, 2026 23:19:02 UTC

Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. A...

CVE-2026-80194

Aug 25, 2026 23:19:01 UTC

Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, ...

CVE-2026-80193

Aug 25, 2026 23:19:01 UTC

Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet recor...

CVE-2026-80192

Aug 25, 2026 23:19:00 UTC

@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unveri...

CVE-2026-80191

Aug 25, 2026 23:18:59 UTC

GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition requi...

CVE-2026-80189

Aug 25, 2026 23:18:58 UTC

LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write. ZipExtractor.ExtractToDir in internal/importer/zip_extractor.go opens each entry and copies it to the destination with io.Copy, which runs to the end of...

CVE-2026-57170

Aug 25, 2026 23:18:29 UTC

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse ...

CVE-2026-52776

Aug 25, 2026 23:12:24 UTC

Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request fo...

CVE-2026-78655

Aug 25, 2026 23:07:24 UTC

Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session. The POST handler on challenge_path keeps ...

CVE-2026-78619

Aug 25, 2026 23:07:23 UTC

Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the recovery model for the submitted c...

CVE-2026-54757

Aug 25, 2026 23:02:12 UTC

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to...

CVE-2026-24301

Aug 25, 2026 22:49:23 UTC

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-59131

Aug 25, 2026 22:49:22 UTC

No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.

CVE-2026-59130

Aug 25, 2026 22:49:22 UTC

No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.

CVE-2026-59127

Aug 25, 2026 22:49:21 UTC

Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.