cve.li

Recent

CVE-2026-108474CWE-89

Published 2026-10-09 by JetBrains

CVE-2026-22061CWE-215

CVE-2026-22061 Debug Log Information Disclosure Vulnerability in Trident

Published 2026-10-09 by netapp

CVE-2026-108269CWE-346

ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session

Published 2026-10-09 by GitHub_M

CVE-2026-108268CWE-346

enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session

Published 2026-10-09 by GitHub_M

CVE-2026-108267CWE-346

Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session

Published 2026-10-09 by GitHub_M

CVE-2026-108266CWE-346

Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS session

Published 2026-10-09 by GitHub_M

CVE-2026-108265CWE-346

enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session

Published 2026-10-09 by GitHub_M

CVE-2026-108264CWE-1336

Wizarr: Authenticated Server-Side Template Injection (SSTI) in wizard step rendering leads to Remote Code Execution (RCE)

Published 2026-10-09 by GitHub_M

CVE-2026-62376CWE-312CWE-916

Vikunja: Plaintext storage of password-reset/email-confirm tokens in database enables account takeover on DB read access

Published 2026-10-09 by GitHub_M

CVE-2026-62367CWE-287CWE-290CWE-345

Vikunja: OIDC email-fallback account linking ignores email_verified, enabling local-account takeover

Published 2026-10-09 by GitHub_M

Load more ↓