CVE-2026-72911 - ERPNext: Possibility of server-side template injection due to missing validation
Autor Aug 11, 2026 0 1
CVE-2026-72910 - ERPNext: Unauthorised modification of master data due to missing validation
Autor Aug 11, 2026 0 1
CVE-2026-72909 - ERPNext: Broken Access Control on certain endpoints
Autor Aug 11, 2026 0 1
CVE-2026-73035 - npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences
Autor Aug 11, 2026 0 2
CVE-2026-73033 - Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php
Autor Aug 11, 2026 0 1
CVE-2026-73030 - unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape
Autor Aug 11, 2026 0 1
CVE-2026-72913 - Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequences
Autor Aug 11, 2026 0 2
CVE-2026-72912 - CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malfor...
Autor Aug 11, 2026 0 1
CVE-2025-32736 - PingFederate Administrative Console CSRF weaknesses
Autor Aug 11, 2026 0 1
CVE-2026-72916 - Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
Autor Aug 11, 2026 0 1
CVE-2026-6426 - Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access
Autor Aug 11, 2026 0 1
CVE-2026-72919 - Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public C...
Autor Aug 11, 2026 0 1
CVE-2026-72918 - Rocket.Chat: Insecure implementation of websocket notifications
Autor Aug 11, 2026 0 1
CVE-2026-72917 - AnythingLLM: Password recovery accepts one recovery code twice after whitespace normalization
Autor Aug 11, 2026 0 2
CVE-2026-72915 - Mastodon: Personally-identifying information disclosure due to incorrect access control validation
Autor Aug 11, 2026 0 1

