CVE ID :CVE-2026-55408 Published : July 7, 2026, 10:16 p.m. | 58 minutes ago Description :Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code…
CVE-2026-49229 – Actual: Disabled OpenID users keep access through existing session tokens
CVE ID :CVE-2026-49229 Published : July 7, 2026, 10:16 p.m. | 58 minutes ago Description :Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only…
CVE-2026-49033 – Stack-Based Buffer Overflow in Labcenter Proteus
CVE ID :CVE-2026-49033 Published : July 7, 2026, 10:16 p.m. | 58 minutes ago Description :The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary…
CVE-2026-53645 – FOSSBilling’s missing self-edit prevention in staff permission management allows persistent privilege escalation
CVE ID :CVE-2026-53645 Published : July 6, 2026, 11:16 p.m. | 1 hour, 57 minutes ago Description :FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged…
CVE-2026-53644 – FOSSBilling’s missing order-state validation allows clients to read and reset API key secrets for non-active orders
CVE ID :CVE-2026-53644 Published : July 6, 2026, 11:16 p.m. | 1 hour, 57 minutes ago Description :FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticated clients…
CVE-2026-53643 – FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints
CVE ID :CVE-2026-53643 Published : July 6, 2026, 11:16 p.m. | 1 hour, 57 minutes ago Description :FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff…
CVE-2026-43921 – FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization
CVE ID :CVE-2026-43921 Published : July 6, 2026, 10:16 p.m. | 57 minutes ago Description :FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code…
CVE-2026-43918 – Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows
CVE ID :CVE-2026-43918 Published : July 6, 2026, 10:16 p.m. | 57 minutes ago Description :FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or…
CVE-2026-42204 – Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root
CVE ID :CVE-2026-42204 Published : July 6, 2026, 10:16 p.m. | 57 minutes ago Description :Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a…
CVE-2026-42153 – Coolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution in Container
CVE ID :CVE-2026-42153 Published : July 6, 2026, 10:16 p.m. | 57 minutes ago Description :Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck…