Common Vulnerabilities and Exposures (CVE)

CVE-2026-13720

Sep 30, 2026 15:28:07 UTC

An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authoriz...

CVE-2026-76992

Sep 30, 2026 15:28:07 UTC

The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger ex...

CVE-2026-62097

Sep 30, 2026 15:28:07 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6....

CVE-2026-62084

Sep 30, 2026 15:28:07 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted Posts: from n/a through 20260810.

CVE-2026-97259

Sep 30, 2026 15:28:07 UTC

Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pay with Vipps for WooCommerce: from...

CVE-2026-18783

Sep 30, 2026 15:28:07 UTC

Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass. This issue affects Trex MES: through 2026-09-29.

CVE-2026-18782

Sep 30, 2026 15:28:07 UTC

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: ...

CVE-2026-103388

Sep 30, 2026 15:28:06 UTC

MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor priv...

CVE-2026-103389

Sep 30, 2026 15:28:06 UTC

MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpo...

CVE-2026-101042

Sep 30, 2026 15:28:02 UTC

Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo...

CVE-2026-100871

Sep 30, 2026 15:27:27 UTC

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator...

CVE-2026-100867

Sep 30, 2026 15:26:16 UTC

spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. Attackers can embed ANSI/OSC escape sequences in version fields of package manifests to manip...

CVE-2026-70125

Sep 30, 2026 15:25:35 UTC

Microsoft Office Outlook Remote Code Execution Vulnerability

CVE-2026-85887

Sep 30, 2026 15:25:35 UTC

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

CVE-2026-83946

Sep 30, 2026 15:25:34 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.