CVE ID :CVE-2026-55652 Published : July 15, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in…
CVE-2026-55576 – MaaAssistantArknights: PR-title expression injection in release-preparation.yml
CVE ID :CVE-2026-55576 Published : July 15, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled…
CVE-2026-55445 – Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication
CVE ID :CVE-2026-55445 Published : July 15, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the…
CVE-2026-55234 – Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule)
CVE ID :CVE-2026-55234 Published : July 15, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in…
CVE-2026-54458 – AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin
CVE ID :CVE-2026-54458 Published : July 15, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site…
CVE-2026-59733 – rclone `serve restic –private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users’ repositories
CVE ID :CVE-2026-59733 Published : July 14, 2026, 10:17 p.m. | 2 hours, 16 minutes ago Description :Rclone is a command-line program to sync files and directories to and from different cloud storage providers….
CVE-2026-50130 – Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`
CVE ID :CVE-2026-50130 Published : July 14, 2026, 10:17 p.m. | 2 hours, 16 minutes ago Description :Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From…
CVE-2026-48334 – Illustrator | Improper Input Validation (CWE-20)
CVE ID :CVE-2026-48334 Published : July 14, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in…
CVE-2026-48290 – CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)
CVE ID :CVE-2026-48290 Published : July 14, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary…
CVE-2026-48275 – Illustrator | Untrusted Search Path (CWE-426)
CVE ID :CVE-2026-48275 Published : July 14, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in…