CVE ID :CVE-2026-87931 Published : Sept. 10, 2026, 12:17 a.m. | 42 minutes ago Description :A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is…
CVE-2026-88069 – Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis
CVE ID :CVE-2026-88069 Published : Sept. 9, 2026, 10:18 p.m. | 2 hours, 41 minutes ago Description :Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive…
CVE-2026-87995 – Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
CVE ID :CVE-2026-87995 Published : Sept. 9, 2026, 10:18 p.m. | 2 hours, 41 minutes ago Description :Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered…
CVE-2026-87016 – Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
CVE ID :CVE-2026-87016 Published : Sept. 9, 2026, 10:18 p.m. | 2 hours, 41 minutes ago Description :Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and…
CVE-2026-87911 – Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server
CVE ID :CVE-2026-87911 Published : Sept. 9, 2026, 8:21 p.m. | 4 hours, 39 minutes ago Description :An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs…
CVE-2026-53939 – OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption
CVE ID :CVE-2026-53939 Published : Sept. 9, 2026, 12:17 a.m. | 41 minutes ago Description :OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5,…
CVE-2026-53938 – OpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW)
CVE ID :CVE-2026-53938 Published : Sept. 9, 2026, 12:17 a.m. | 41 minutes ago Description :OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose’s…
CVE-2026-55250 – Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Tagged Caches
CVE ID :CVE-2026-55250 Published : Sept. 8, 2026, 11:17 p.m. | 1 hour, 41 minutes ago Description :Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay…
CVE-2026-53581 – ntp: write path traversal
CVE ID :CVE-2026-53581 Published : Sept. 8, 2026, 11:17 p.m. | 1 hour, 41 minutes ago Description :OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version…
CVE-2026-86076 – n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution
CVE ID :CVE-2026-86076 Published : Sept. 8, 2026, 10:19 p.m. | 2 hours, 39 minutes ago Description :n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler…