CVE-2025-1218 The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL … cve.org/CVERecord?id=CVE-202…
CVE-2026-100376 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extens… cve.org/CVERecord?id=CVE-202…
CVE-2026-10758 Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflo… cve.org/CVERecord?id=CVE-202…
CVE-2026-100378 Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs.
This i… cve.org/CVERecord?id=CVE-202…
CVE-2026-91767 php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name w… cve.org/CVERecord?id=CVE-202…
CVE-2026-100379 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP … cve.org/CVERecord?id=CVE-202…
CVE-2026-100380 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension all… cve.org/CVERecord?id=CVE-202…
CVE-2026-91769 PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 r… cve.org/CVERecord?id=CVE-202…
CVE-2026-100381 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension… cve.org/CVERecord?id=CVE-202…
CVE-2026-100382 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension … cve.org/CVERecord?id=CVE-202…
CVE-2026-100383 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension a… cve.org/CVERecord?id=CVE-202…
CVE-2026-91768 The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix inste… cve.org/CVERecord?id=CVE-202…
CVE-2026-92842 The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked… cve.org/CVERecord?id=CVE-202…
CVE-2026-88003 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privil… cve.org/CVERecord?id=CVE-202…
CVE-2026-63431 Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view… cve.org/CVERecord?id=CVE-202…
CVE-2026-63432 Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.p… cve.org/CVERecord?id=CVE-202…
CVE-2026-71483 Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employe… cve.org/CVERecord?id=CVE-202…
CVE-2026-100418 Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object with… cve.org/CVERecord?id=CVE-202…
CVE-2026-100419 gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree direct… cve.org/CVERecord?id=CVE-202…
CVE-2026-100501 Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthentic… cve.org/CVERecord?id=CVE-202…