Skip to content

Menu
  • Home
Menu

CVE-2026-65956 – KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF

Posted on August 27, 2026

CVE ID :CVE-2026-65956 Published : Aug. 26, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration…

CVE-2026-47665 – Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML

Posted on August 27, 2026

CVE ID :CVE-2026-47665 Published : Aug. 26, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is…

CVE-2026-77317 – SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwrite

Posted on August 27, 2026

CVE ID :CVE-2026-77317 Published : Aug. 26, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the…

CVE-2026-77298 – SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy

Posted on August 27, 2026

CVE ID :CVE-2026-77298 Published : Aug. 26, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3…

CVE-2026-65647 – Plesk Improper Symlink Resolution Arbitrary Code Execution

Posted on August 27, 2026

CVE ID :CVE-2026-65647 Published : Aug. 26, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as…

CVE-2026-80202 – Kimai before 2.56.0 Authorization Bypass via TimesheetVoter

Posted on August 26, 2026

CVE ID :CVE-2026-80202 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or…

CVE-2026-80198 – Kimai before 2.56.0 Information Disclosure via config() Twig Function

Posted on August 26, 2026

CVE ID :CVE-2026-80198 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates,…

CVE-2026-80197 – Kimai before 2.57.0 Improper Authorization via Favorite Endpoints

Posted on August 26, 2026

CVE ID :CVE-2026-80197 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that…

CVE-2026-80196 – Kimai before 2.58.0 Authentication Bypass via Password Reset Link

Posted on August 26, 2026

CVE ID :CVE-2026-80196 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes…

CVE-2026-80195 – Kimai before 2.63.0 Team Membership Removal via API

Posted on August 26, 2026

CVE ID :CVE-2026-80195 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint…

Posts pagination

1 2 … 135 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme