Common Vulnerabilities and Exposures (CVE)

CVE-2026-104478

Oct 2, 2026 23:28:48 UTC

Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded back...

CVE-2026-104477

Oct 2, 2026 23:28:47 UTC

Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links o...

CVE-2026-104476

Oct 2, 2026 23:28:46 UTC

Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives genera...

CVE-2026-104475

Oct 2, 2026 23:28:46 UTC

IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or set...

CVE-2026-104474

Oct 2, 2026 23:28:45 UTC

OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the...

CVE-2026-104433

Oct 2, 2026 23:28:44 UTC

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attacker...

CVE-2026-76504

Oct 2, 2026 23:23:29 UTC

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due...

CVE-2026-20273

Oct 2, 2026 23:23:27 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that ad...

CVE-2026-20272

Oct 2, 2026 23:23:22 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-20269

Oct 2, 2026 23:23:12 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-20271

Oct 2, 2026 23:23:02 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-20270

Oct 2, 2026 23:22:51 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-20267

Oct 2, 2026 23:22:41 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-20268

Oct 2, 2026 23:22:31 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...

CVE-2026-105051

Oct 2, 2026 22:59:56 UTC

Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).