cve.li

Recent

CVE-2026-63431CWE-862

Horilla: Missing Authorization on Payroll Component Views Exposes Employee Salary Structures and Personal Loan Records (IDOR)

Published 2026-09-25 by GitHub_M

CVE-2026-88003CWE-863

InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade

Published 2026-09-25 by GitHub_M

CVE-2026-92842CWE-122CWE-125

OOB read / info leak in convert.* stream filters when line-break-chars contains NUL

Published 2026-09-25 by php

CVE-2026-91768CWE-1023

IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes)

Published 2026-09-25 by php

CVE-2026-100383CWE-79

Stored i18n XSS in WikiLambda's VisualEditor integration

Published 2026-09-25 by wikimedia-foundation

CVE-2026-100382CWE-78

Unauthenticated remote code execution through wikitext in ExternalData

Published 2026-09-25 by wikimedia-foundation

CVE-2026-100381CWE-79

UploadWizard Flickr collection and set titles allow DOM XSS

Published 2026-09-25 by wikimedia-foundation

CVE-2026-91769CWE-297

TLS Hostname Verification Falls Back to CN After SAN Mismatch

Published 2026-09-25 by php

CVE-2026-100380CWE-79

Reflected XSS in Wikibase Special:SetLabel language validation

Published 2026-09-25 by wikimedia-foundation

CVE-2026-100379CWE-200

Cross-request disclosure of CentralAuth cookies in Wikipedia Android App

Published 2026-09-25 by wikimedia-foundation

Load more ↓