CVE ID :CVE-2026-61599 Published : Sept. 16, 2026, 11:16 p.m. | 2 hours, 13 minutes ago Description :djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the…
CVE-2026-92599 – Joi before 17.13.7 and 18.2.6 ReDoS via isoDate
CVE ID :CVE-2026-92599 Published : Sept. 16, 2026, 10:18 p.m. | 1 hour, 11 minutes ago Description :joi (npm package `joi`, hapi.js) versions >=17.2.0 =18.0.0 Severity: 8.7 | HIGH Visit the link for more…
CVE-2026-92598 – Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass
CVE ID :CVE-2026-92598 Published : Sept. 16, 2026, 10:18 p.m. | 1 hour, 11 minutes ago Description :Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver…
CVE-2026-92597 – Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment
CVE ID :CVE-2026-92597 Published : Sept. 16, 2026, 10:18 p.m. | 1 hour, 11 minutes ago Description :Nodemailer versions >= 6.9.16 and Severity: 8.3 | HIGH Visit the link for more details, such as…
CVE-2026-92596 – Nodemailer before 9.1.0 Denial of Service via addressparser
CVE ID :CVE-2026-92596 Published : Sept. 16, 2026, 10:18 p.m. | 1 hour, 11 minutes ago Description :Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers…
CVE-2026-92594 – Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL
CVE ID :CVE-2026-92594 Published : Sept. 16, 2026, 10:18 p.m. | 1 hour, 11 minutes ago Description :Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of…
CVE-2026-15640 – Authentication Bypass via SAML Response Manipulation
CVE ID :CVE-2026-15640 Published : Sept. 16, 2026, 12:17 a.m. | 1 hour, 8 minutes ago Description :Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user….
CVE-2026-15639 – Reflected Cross-Site Scripting
CVE ID :CVE-2026-15639 Published : Sept. 16, 2026, 12:17 a.m. | 1 hour, 8 minutes ago Description :An attacker can craft a malicious link that, if used by a legitimate user, may cause the…
CVE-2026-15638 – Cryptographic Padding Oracle
CVE ID :CVE-2026-15638 Published : Sept. 16, 2026, 12:17 a.m. | 1 hour, 8 minutes ago Description :An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt…
CVE-2026-85893 – Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE ID :CVE-2026-85893 Published : Sept. 15, 2026, 10:44 p.m. | 40 minutes ago Description :None Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline,…