Recent
MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token
Published 2026-08-30 by Wordfence
NASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflow
Published 2026-08-30 by VulDB
JSON path injection via unescaped get_path segments in AshSqlite
Published 2026-08-30 by EEF
Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
Published 2026-08-30 by EEF
Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
Published 2026-08-30 by EEF
Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
Published 2026-08-30 by EEF
Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
Published 2026-08-30 by EEF
qs.parse does not enforce arrayLimit on comma groups under bracket-push keys when throwOnLimitExceeded is set (incomplete fix for CVE-2026-2391)
Published 2026-08-29 by harborist
qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property
Published 2026-08-29 by harborist
PHPGurukul Student Information System student_edit1.php sql injection
Published 2026-08-29 by VulDB
Load more ↓