CVE ID :CVE-2026-105786 Published : Oct. 6, 2026, 12:16 a.m. | 1 hour, 11 minutes ago Description :Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior…
CVE-2026-105783 – Joplin Web Clipper pairing allows cross-origin theft of a permanent API token
CVE ID :CVE-2026-105783 Published : Oct. 6, 2026, 12:16 a.m. | 1 hour, 11 minutes ago Description :Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior…
CVE-2026-105763 – Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace member via /metadata GraphQL
CVE ID :CVE-2026-105763 Published : Oct. 6, 2026, 12:16 a.m. | 1 hour, 11 minutes ago Description :Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts…
CVE-2026-105762 – Dify: Unauthenticated Server-Side Request Forgery in /console/api/remote-files/upload endpoint
CVE ID :CVE-2026-105762 Published : Oct. 6, 2026, 12:16 a.m. | 1 hour, 11 minutes ago Description :Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted…
CVE-2026-104852 – GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`
CVE ID :CVE-2026-104852 Published : Oct. 5, 2026, 11:17 p.m. | 2 hours, 11 minutes ago Description :GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 12.0.1, the GraphQL Tools…
CVE-2026-91107 – openSIS Classic 9.3 – Insecure Direct Object Reference (IDOR)
CVE ID :CVE-2026-91107 Published : Oct. 5, 2026, 10:16 p.m. | 1 hour, 11 minutes ago Description :openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff…
CVE-2026-21589 – Atlassian Data Center and Server Arbitrary File Access Vulnerability
CVE ID :CVE-2026-21589 Published : Oct. 5, 2026, 10:16 p.m. | 1 hour, 11 minutes ago Description :h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data…
CVE-2026-77226 – Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint
CVE ID :CVE-2026-77226 Published : Oct. 5, 2026, 9:16 p.m. | 2 hours, 11 minutes ago Description :Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application’s first-run setup endpoint,…
CVE-2026-105740 – Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server
CVE ID :CVE-2026-105740 Published : Oct. 5, 2026, 9:16 p.m. | 2 hours, 11 minutes ago Description :Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated…
CVE-2026-105697 – Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration
CVE ID :CVE-2026-105697 Published : Oct. 5, 2026, 9:16 p.m. | 2 hours, 11 minutes ago Description :Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP…