CVE ID :CVE-2026-96795 Published : Sept. 25, 2026, 11:16 p.m. | 57 minutes ago Description :Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user’s columns…
CVE-2026-71483 – Horilla: Reflected Cross-Site Scripting (XSS) in Employee Filter View
CVE ID :CVE-2026-71483 Published : Sept. 25, 2026, 10:18 p.m. | 1 hour, 55 minutes ago Description :Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected…
CVE-2026-100501 – Flame through 2.4.0 Brute-Force Attack via Login Endpoint
CVE ID :CVE-2026-100501 Published : Sept. 25, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login…
CVE-2026-100382 – Unauthenticated remote code execution through wikitext in ExternalData
CVE ID :CVE-2026-100382 Published : Sept. 25, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability in Wikimedia Foundation…
CVE-2026-100391 – MediaFlow Proxy through 2.4.9 Server-Side Request Forgery via Incomplete Validation
CVE ID :CVE-2026-100391 Published : Sept. 25, 2026, 9:17 p.m. | 2 hours, 56 minutes ago Description :MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing…
CVE-2026-85082 – Maple Media Root Browser Classic 3.3.0 – OS command injection through crafted SQLite filenames
CVE ID :CVE-2026-85082 Published : Sept. 24, 2026, 11:48 p.m. | 19 minutes ago Description :Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely…
CVE-2026-87722 – Regular Expression Denial of Service (ReDoS) in Search Query Predicates and REST Filter Endpoints in Gerrit Code Review
CVE ID :CVE-2026-87722 Published : Sept. 24, 2026, 10:17 p.m. | 1 hour, 50 minutes ago Description :Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, RegexRefPredicate, RegexPathPredicate, and…
CVE-2026-87721 – Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code Review
CVE ID :CVE-2026-87721 Published : Sept. 24, 2026, 10:17 p.m. | 1 hour, 50 minutes ago Description :Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in…
CVE-2026-95699 – MrSteam iSteamX Improper Isolation or Compartmentalization
CVE ID :CVE-2026-95699 Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 49 minutes ago Description :Prior to 9/18/2026, the iSteamX mobile application’s AWS policy could grant authenticated users access to wildcard MQTT…
CVE-2026-81630 – Botslab G980H Dashcams Insufficient Verification of Data Authenticity
CVE ID :CVE-2026-81630 Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 49 minutes ago Description :The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update…