Aggregator
CVE-2026-27879 | Grafana up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 Resample Query denial of service
1 week ago
A vulnerability was found in Grafana up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 and classified as problematic. This affects an unknown part of the component Resample Query Handler. Executing a manipulation can lead to denial of service.
This vulnerability appears as CVE-2026-27879. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-28375 | Grafana up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 testdata data-source denial of service
1 week ago
A vulnerability has been found in Grafana up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 and classified as problematic. Affected by this issue is some unknown functionality of the component testdata data-source Handler. Performing a manipulation results in denial of service.
This vulnerability is reported as CVE-2026-28375. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2025-61190 | DSpace JSPUI 6.5 Parameter filter_type_1 cross site scripting
1 week ago
A vulnerability, which was classified as problematic, was found in DSpace JSPUI 6.5. Affected by this vulnerability is an unknown functionality of the component Parameter Handler. Such manipulation of the argument filter_type_1 leads to cross site scripting.
This vulnerability is documented as CVE-2025-61190. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-33206 | kovidgoyal calibre up to 9.5.x path traversal
1 week ago
A vulnerability, which was classified as problematic, has been found in kovidgoyal calibre up to 9.5.x. Affected is an unknown function. This manipulation causes relative path traversal.
This vulnerability is registered as CVE-2026-33206. The attack needs to be launched locally. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-69988 | BS Producten Petcam 33.1.0.0818 Network Interface access control
1 week ago
A vulnerability classified as critical was found in BS Producten Petcam 33.1.0.0818. This impacts an unknown function of the component Network Interface Handler. The manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2025-69988. An attack on the physical device is feasible. There is no exploit available.
vuldb.com
CVE-2026-33758 | OpenBao up to 2.5.1 OIDC/JWT callback_mode error_description cross site scripting
1 week ago
A vulnerability classified as problematic has been found in OpenBao up to 2.5.1. This affects the function callback_mode of the component OIDC/JWT. The manipulation of the argument error_description leads to cross site scripting.
This vulnerability is listed as CVE-2026-33758. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
FreeBSD security advisory (AV26-291)
1 week ago
Canadian Centre for Cyber Security
CVE-2026-4984 | botpress MediaUrlN missing encryption
1 week ago
A vulnerability described as problematic has been identified in botpress. The impacted element is an unknown function. Executing a manipulation of the argument MediaUrlN can lead to missing encryption of sensitive data.
This vulnerability is tracked as CVE-2026-4984. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-33750 | juliangruber brace-expansion up to 1.1.12/2.0.2/3.0.1/5.0.4 expand step resource consumption
1 week ago
A vulnerability marked as problematic has been reported in juliangruber brace-expansion up to 1.1.12/2.0.2/3.0.1/5.0.4. The affected element is the function expand. Performing a manipulation of the argument step results in resource consumption.
This vulnerability is identified as CVE-2026-33750. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-27876 | Grafana Enterprise up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 Expressions Feature privilege escalation
1 week ago
A vulnerability labeled as problematic has been found in Grafana Enterprise up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1. Impacted is an unknown function of the component Expressions Feature. Such manipulation leads to privilege escalation.
This vulnerability is referenced as CVE-2026-27876. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-5022 | langflow-ai langflow Image /api/v1/files/images/ flow_id/file_name authorization
1 week ago
A vulnerability identified as problematic has been detected in langflow-ai langflow. This issue affects some unknown processing of the file /api/v1/files/images/ of the component Image Handler. This manipulation of the argument flow_id/file_name causes missing authorization.
The identification of this vulnerability is CVE-2026-5022. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-33755 | Intermesh GroupOffice up to 6.8.157/25.0.91/26.0.16 Contact/query sql injection
1 week ago
A vulnerability categorized as critical has been discovered in Intermesh GroupOffice up to 6.8.157/25.0.91/26.0.16. This vulnerability affects unknown code of the file Contact/query. The manipulation results in sql injection.
This vulnerability was named CVE-2026-33755. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-33433 | Traefik up to 2.11.41/3.6.10 authentication spoofing
1 week ago
A vulnerability was found in Traefik up to 2.11.41/3.6.10. It has been rated as critical. This affects an unknown part. The manipulation leads to authentication bypass by spoofing.
This vulnerability is uniquely identified as CVE-2026-33433. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-33757 | OpenBao up to 2.5.1 JWT/OIDC callback_mode session fixiation
1 week ago
A vulnerability was found in OpenBao up to 2.5.1. It has been declared as critical. Affected by this issue is the function callback_mode of the component JWT/OIDC. Executing a manipulation can lead to session fixiation.
This vulnerability is handled as CVE-2026-33757. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-33284 | globaleaks globaleaks-whistleblowing-software up to 5.0.88 /api/support input validation
1 week ago
A vulnerability was found in globaleaks globaleaks-whistleblowing-software up to 5.0.88. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the file /api/support. Performing a manipulation results in improper input validation.
This vulnerability is known as CVE-2026-33284. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-33766 | WWBN AVideo up to 26.0 HTTP Redirect isSSRFSafeURL server-side request forgery
1 week ago
A vulnerability was found in WWBN AVideo up to 26.0 and classified as critical. Affected is the function isSSRFSafeURL of the component HTTP Redirect Handler. Such manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-33766. The attack may be launched remotely. There is no exploit available.
It is advisable to implement a patch to correct this issue.
vuldb.com
CVE-2026-33748 | moby buildkit up to 0.28.0 path traversal
1 week ago
A vulnerability has been found in moby buildkit up to 0.28.0 and classified as critical. This impacts an unknown function. This manipulation causes path traversal.
This vulnerability appears as CVE-2026-33748. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-30637 | OTCMS up to 7.66 /admin/read.php AnnounContent server-side request forgery
1 week ago
A vulnerability, which was classified as critical, was found in OTCMS up to 7.66. This affects the function AnnounContent of the file /admin/read.php. The manipulation results in server-side request forgery.
This vulnerability is reported as CVE-2026-30637. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-33764 | WWBN AVideo up to 26.0 save.json.php ID authorization
1 week ago
A vulnerability, which was classified as problematic, has been found in WWBN AVideo up to 26.0. The impacted element is an unknown function of the file save.json.php. The manipulation of the argument ID leads to authorization bypass.
This vulnerability is documented as CVE-2026-33764. The attack can be initiated remotely. There is not any exploit available.
It is suggested to install a patch to address this issue.
vuldb.com