cve.li

Recent

CVE-2026-61852CWE-89

Chartbrew: SQL Injection via row_limit Parameter in AI runQuery Tool

Published 2026-09-21 by GitHub_M

CVE-2026-61743CWE-350

Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation

Published 2026-09-21 by GitHub_M

CVE-2026-94536CWE-639

lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/visible/resource

Published 2026-09-21 by VulnCheck

CVE-2026-94535CWE-639

lamp-cloud through 5.10.0 Unauthorized Notification Deletion

Published 2026-09-21 by VulnCheck

CVE-2026-94534CWE-639

lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints

Published 2026-09-21 by VulnCheck

CVE-2026-94533CWE-639

lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file

Published 2026-09-21 by VulnCheck

CVE-2026-94532CWE-639

lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById

Published 2026-09-21 by VulnCheck

CVE-2026-93340CWE-640

Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password Endpoint

Published 2026-09-21 by VulnCheck

CVE-2026-61541CWE-770

Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service

Published 2026-09-21 by GitHub_M

CVE-2026-59830CWE-79

Discourse: Stored XSS via unescaped actor name in post actions

Published 2026-09-21 by GitHub_M

Load more ↓