CVE ID :CVE-2026-65956 Published : Aug. 26, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration…
CVE-2026-47665 – Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML
CVE ID :CVE-2026-47665 Published : Aug. 26, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is…
CVE-2026-77317 – SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwrite
CVE ID :CVE-2026-77317 Published : Aug. 26, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the…
CVE-2026-77298 – SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy
CVE ID :CVE-2026-77298 Published : Aug. 26, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3…
CVE-2026-65647 – Plesk Improper Symlink Resolution Arbitrary Code Execution
CVE ID :CVE-2026-65647 Published : Aug. 26, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as…
CVE-2026-80202 – Kimai before 2.56.0 Authorization Bypass via TimesheetVoter
CVE ID :CVE-2026-80202 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or…
CVE-2026-80198 – Kimai before 2.56.0 Information Disclosure via config() Twig Function
CVE ID :CVE-2026-80198 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates,…
CVE-2026-80197 – Kimai before 2.57.0 Improper Authorization via Favorite Endpoints
CVE ID :CVE-2026-80197 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that…
CVE-2026-80196 – Kimai before 2.58.0 Authentication Bypass via Password Reset Link
CVE ID :CVE-2026-80196 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes…
CVE-2026-80195 – Kimai before 2.63.0 Team Membership Removal via API
CVE ID :CVE-2026-80195 Published : Aug. 25, 2026, 11:19 p.m. | 1 hour, 16 minutes ago Description :Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint…