cve.li

Recent

CVE-2026-15980CWE-289

MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token

Published 2026-08-30 by Wordfence

CVE-2026-82478CWE-121CWE-119

NASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflow

Published 2026-08-30 by VulDB

CVE-2026-77846CWE-943

JSON path injection via unescaped get_path segments in AshSqlite

Published 2026-08-30 by EEF

CVE-2026-75759CWE-347

Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc

Published 2026-08-30 by EEF

CVE-2026-77831CWE-407

Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking

Published 2026-08-30 by EEF

CVE-2026-77970CWE-312

Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions

Published 2026-08-30 by EEF

CVE-2026-75847CWE-312

Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail

Published 2026-08-30 by EEF

CVE-2026-82562CWE-770

qs.parse does not enforce arrayLimit on comma groups under bracket-push keys when throwOnLimitExceeded is set (incomplete fix for CVE-2026-2391)

Published 2026-08-29 by harborist

CVE-2026-82417CWE-248CWE-703

qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property

Published 2026-08-29 by harborist

CVE-2026-82424CWE-89CWE-74

PHPGurukul Student Information System student_edit1.php sql injection

Published 2026-08-29 by VulDB

Load more ↓