Aggregator
CVE-2026-42350 | akuity kargo up to 1.7.9/1.8.12/1.9.7/1.10.1 UI OIDC Login redirect (GHSA-g7gw-m874-7rmf)
2 months 1 week ago
A vulnerability was found in akuity kargo up to 1.7.9/1.8.12/1.9.7/1.10.1. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component UI OIDC Login. This manipulation causes open redirect.
This vulnerability is registered as CVE-2026-42350. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-42346 | gitroomhq postiz-app up to 2.21.6 isSafePublicHttpsUrl server-side request forgery (GHSA-f7jj-p389-4w45)
2 months 1 week ago
A vulnerability was found in gitroomhq postiz-app up to 2.21.6 and classified as critical. Affected is the function isSafePublicHttpsUrl. The manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-42346. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-41432 | QuantumNous new-api up to 0.12.9 data authenticity (GHSA-xff3-5c9p-2mr4)
2 months 1 week ago
A vulnerability has been found in QuantumNous new-api up to 0.12.9 and classified as problematic. This impacts an unknown function. The manipulation leads to insufficient verification of data authenticity.
This vulnerability is listed as CVE-2026-41432. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-42298 | gitroomhq postiz-app pr-docker-build.yml code injection (GHSA-v975-9h5p-xhm4)
2 months 1 week ago
A vulnerability, which was classified as critical, was found in gitroomhq postiz-app. This affects an unknown function of the file .github/workflows/pr-docker-build.yml. Executing a manipulation can lead to code injection.
This vulnerability is tracked as CVE-2026-42298. The attack can be launched remotely. No exploit exists.
Applying a patch is advised to resolve this issue.
vuldb.com
CVE-2026-45130 | vim up to 9.2.0449 Spell File src/spellfile.c read_compound length heap-based overflow (GHSA-q4jv-r9gj-6cwv / Nessus ID 313607)
2 months 1 week ago
A vulnerability, which was classified as critical, has been found in vim up to 9.2.0449. The impacted element is the function read_compound of the file src/spellfile.c of the component Spell File Handler. Performing a manipulation of the argument length results in heap-based buffer overflow.
This vulnerability is identified as CVE-2026-45130. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-44656 | vim up to 9.2.0434 Command Line os command injection (GHSA-hwg5-3cxw-wvvg / Nessus ID 313602)
2 months 1 week ago
A vulnerability classified as critical was found in vim up to 9.2.0434. The affected element is an unknown function of the component Command Line Handler. Such manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-44656. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-42456 | Mintplex-Labs anything-llm up to 1.12.0 :chatId information disclosure (GHSA-jwqg-jfg3-x5vv)
2 months 1 week ago
A vulnerability classified as problematic has been found in Mintplex-Labs anything-llm up to 1.12.0. Impacted is an unknown function of the file /api/workspace/:slug/tts/:chatId. This manipulation causes information disclosure.
The identification of this vulnerability is CVE-2026-42456. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-42351 | geopython pygeoapi up to 0.23.2 OGC API path traversal (GHSA-f6pr-83pg-ghh6)
2 months 1 week ago
A vulnerability described as critical has been identified in geopython pygeoapi up to 0.23.2. This issue affects some unknown processing of the component OGC API. The manipulation results in path traversal.
This vulnerability was named CVE-2026-42351. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-42451 | grimmory-tools grimmory up to 2.3.0 EPUB File cross site scripting (GHSA-frv6-5wq5-9p24)
2 months 1 week ago
A vulnerability marked as problematic has been reported in grimmory-tools grimmory up to 2.3.0. This vulnerability affects unknown code of the component EPUB File Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-42451. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-6666 | PgBouncer up to 1.25.1 Error Response SQLSTATE null pointer dereference
2 months 1 week ago
A vulnerability labeled as problematic has been found in PgBouncer up to 1.25.1. This affects an unknown part of the component Error Response Handler. Executing a manipulation of the argument SQLSTATE can lead to null pointer dereference.
This vulnerability is handled as CVE-2026-6666. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-42192 | useplunk up to 0.8.x Admin Dashboard Page cross site scripting (GHSA-mjqc-qrv3-24hq)
2 months 1 week ago
A vulnerability identified as problematic has been detected in useplunk plunk up to 0.8.x. Affected by this issue is some unknown functionality of the component Admin Dashboard Page. Performing a manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-42192. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-44313 | Linkwarden up to 2.12.x URL Validation fetchTitleAndHeaders server-side request forgery (GHSA-5qpc-x7rv-hvmp)
2 months 1 week ago
A vulnerability categorized as critical has been discovered in Linkwarden up to 2.12.x. Affected by this vulnerability is the function fetchTitleAndHeaders of the component URL Validation Handler. Such manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-44313. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-42452 | Termix-SSH Termix up to 2.0.x Authenticated Endpoint /users/login temp_token critical step in authentication (GHSA-vx59-rf9w-9jv8)
2 months 1 week ago
A vulnerability was found in Termix-SSH Termix up to 2.0.x. It has been rated as critical. Affected is an unknown function of the file /users/login of the component Authenticated Endpoint. This manipulation of the argument temp_token causes missing critical step in authentication.
This vulnerability appears as CVE-2026-42452. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-41682 | pupnp up to 1.18.4 atoi signed to unsigned conversion error (GHSA-q522-6w45-4j58)
2 months 1 week ago
A vulnerability was found in pupnp up to 1.18.4. It has been declared as critical. This impacts the function atoi. The manipulation results in signed to unsigned conversion error.
This vulnerability is reported as CVE-2026-41682. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-6667 | PgBouncer up to 1.25.1 Administration Console admin_users authorization
2 months 1 week ago
A vulnerability was found in PgBouncer up to 1.25.1. It has been classified as problematic. This affects an unknown function of the component Administration Console. The manipulation of the argument admin_users leads to missing authorization.
This vulnerability is documented as CVE-2026-6667. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-6665 | PgBouncer up to 1.25.1 strlcat stack-based overflow
2 months 1 week ago
A vulnerability was found in PgBouncer up to 1.25.1 and classified as critical. The impacted element is the function strlcat. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability is registered as CVE-2026-6665. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-41705 | Spring AI up to 1.0.6/1.1.5 MilvusVectorStore#doDelete expression language injection
2 months 1 week ago
A vulnerability has been found in Spring AI up to 1.0.6/1.1.5 and classified as critical. The affected element is the function MilvusVectorStore#doDelete. Performing a manipulation results in improper neutralization of special elements used in an expression language statement.
This vulnerability is cataloged as CVE-2026-41705. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-42199 | becheran grid up to 1.0.0 Safe API Grid::expand_rows integer overflow (GHSA-38c5-483c-4qqp)
2 months 1 week ago
A vulnerability, which was classified as problematic, was found in becheran grid up to 1.0.0. Impacted is the function Grid::expand_rows of the component Safe API. Such manipulation leads to integer overflow.
This vulnerability is listed as CVE-2026-42199. The attack must be carried out locally. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-42195 | jgraph drawio up to 29.7.8 Link gitlab redirect (ID 493)
2 months 1 week ago
A vulnerability, which was classified as problematic, has been found in jgraph drawio up to 29.7.8. This issue affects some unknown processing of the component Link Handler. This manipulation of the argument gitlab causes open redirect.
This vulnerability is tracked as CVE-2026-42195. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com