cve.li

Recent

CVE-2026-100881CWE-79CWE-94

zhistaredu StarTraining application.yml cross site scripting

Published 2026-09-27 by VulDB

CVE-2026-96281CWE-284

Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes

Published 2026-09-27 by redhat

CVE-2026-100880CWE-79CWE-94

zhistaredu StarTraining Upload Endpoint MimeTypeUtils.java cross site scripting

Published 2026-09-27 by VulDB

CVE-2026-101090CWE-601

Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri

Published 2026-09-27 by VulnCheck

CVE-2026-101089CWE-522

Nezha before 2.2.7 Information Disclosure via /api/v1/profile

Published 2026-09-27 by VulnCheck

CVE-2026-101088CWE-367

Nezha before 2.3.1 Denial of Service via Concurrent Server Delete

Published 2026-09-27 by VulnCheck

CVE-2026-101087CWE-918

Nezha 2.0.10 through 2.3.2 SSRF Denylist Bypass IPv6

Published 2026-09-27 by VulnCheck

CVE-2026-101086CWE-269

Nezha Dashboard before 2.3.5 Task Type Validation Bypass

Published 2026-09-27 by VulnCheck

CVE-2026-101085CWE-197

Nezha before 2.3.8 Denial of Service via Alert Rule

Published 2026-09-27 by VulnCheck

CVE-2026-101084CWE-639

obot before v0.21.1 Authorization Bypass via /mcp-connect

Published 2026-09-27 by VulnCheck

Load more ↓