CVE ID :CVE-2026-73683 Published : Aug. 14, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :Laravel Socialite’s Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC…
CVE-2026-73682 – Semaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling
CVE ID :CVE-2026-73682 Published : Aug. 14, 2026, 9:17 p.m. | 2 hours, 54 minutes ago Description :Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url…
CVE-2026-73680 – Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename
CVE ID :CVE-2026-73680 Published : Aug. 14, 2026, 8:16 p.m. | 3 hours, 55 minutes ago Description :Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated…
CVE-2026-71571 – Joomla Extension – icagenda.com – Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11
CVE ID :CVE-2026-71571 Published : Aug. 14, 2026, 8:16 p.m. | 3 hours, 55 minutes ago Description :Joomla Extension – icagenda.com – Authenticated SQL injection via unescaped numeric filter in iCagenda Severity: 8.6 |…
CVE-2026-67365 – Joomla Extension – icagenda.com – Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11
CVE ID :CVE-2026-67365 Published : Aug. 14, 2026, 8:16 p.m. | 3 hours, 55 minutes ago Description :Joomla Extension – icagenda.com – Unauthenticated SQL injection in iCagenda Severity: 9.2 | CRITICAL Visit the link…
CVE-2026-73843 – OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
CVE ID :CVE-2026-73843 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing…
CVE-2026-73842 – OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
CVE ID :CVE-2026-73842 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed…
CVE-2026-73841 – OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
CVE ID :CVE-2026-73841 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize…
CVE-2026-73667 – OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
CVE ID :CVE-2026-73667 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow…
CVE-2026-73666 – OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/delete
CVE ID :CVE-2026-73666 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend…