Common Vulnerabilities and Exposures (CVE)

CVE-2026-19191

Aug 7, 2026 17:36:19 UTC

A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulati...

CVE-2026-37171

Aug 7, 2026 17:33:25 UTC

A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.

CVE-2026-19213

Aug 7, 2026 17:30:39 UTC

A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCore/TraderAdapter.h of the component Pending Order Handler. The manipulation of the argument getUndoneQty leads to enforc...

CVE-2026-68823

Aug 7, 2026 17:30:06 UTC

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

CVE-2026-49163

Aug 7, 2026 17:28:45 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

CVE-2026-71555

Aug 7, 2026 17:26:58 UTC

PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that opens a new browsing ...

CVE-2026-7405

Aug 7, 2026 17:22:51 UTC

A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service

CVE-2026-49391

Aug 7, 2026 17:21:30 UTC

Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, allowing an authenticated importer to persist script content that ex...

CVE-2026-70632

Aug 7, 2026 17:20:24 UTC

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file duri...

CVE-2026-50159

Aug 7, 2026 17:18:23 UTC

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied cla...

CVE-2026-71488

Aug 7, 2026 17:17:05 UTC

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths...

CVE-2026-48084

Aug 7, 2026 17:17:03 UTC

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit unlimited wrong passphrase guesses a...

CVE-2026-48075

Aug 7, 2026 17:15:21 UTC

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any client tunnel without any caller authentic...

CVE-2026-56818

Aug 7, 2026 17:14:02 UTC

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but ...

CVE-2026-47185

Aug 7, 2026 17:13:44 UTC

Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user's ...