-Infinity
0

SiYuan SiYuanSiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP

Risk 87
Severity
10
First published (updated )

OpenRemote OpenRemoteOpenRemote before 1.26.2 Authentication Bypass via Console Registration

Risk 76
Severity
9.3
First published (updated )

composer/pheditor/pheditor## Summary The forced password-change flow, triggered when the stored password is still the default…

Risk 87
Severity
10
First published (updated )

npm/sm-cryptoWeak RNG

Risk 66
Severity
9.1
First published (updated )

maven/org.openidentityplatform.opendj:opendj-server-legacy### Summary When a SASL PLAIN bind supplies an authorization identity (authzid) that resolves to a *…

Risk 68
Severity
9.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/org.openidentityplatform.opendj:opendj-dsml-servletSSRF

Risk 76
Severity
9.4
First published (updated )

Tycon Systems TPDIN-Monitor-WEB2Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel

Risk 86
Severity
9.3
First published (updated )

npm/@budibase/serverSQL Injection

Risk 80
Severity
9.6
First published (updated )

maven/org.openidentityplatform.openam:openam-coreCode Injection

Risk 86
Severity
9.8
First published (updated )

maven/org.openidentityplatform.openam:openam-coreCode Injection

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

epa4all epa4allepa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau

Risk 66
Severity
9.1
First published (updated )

go/github.com/getkin/kin-openapi### Summary `ValidationHandler.Load()` in `getkin/kin-openapi` silently replaces a nil `Authenticati…

Risk 66
Severity
9.1
First published (updated )

npm/@prompty/coreCode Injection

Risk 87
Severity
10
First published (updated )

npm/velocityjsCode Injection

Risk 86
Severity
9.8
First published (updated )

npm/seroval## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to…

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/seroval## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to…

Risk 86
Severity
9.8
First published (updated )

npm/@better-auth/scimInput Validation

Risk 82
Severity
9.9
First published (updated )

LOYTEC Loytec LINX firmwareLoytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter

Risk 70
Severity
9.2
First published (updated )

SUNNET Corporate Training Management SystemSUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type

Risk 75
Severity
9.3
First published (updated )

Eclipse BaSyx Go ComponentsCWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WordPress Project Management, Bug and Issue Tracking PluginSoftware Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter

Risk 66
Severity
9.1
First published (updated )

Pronetiqs IntraVUEExposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs

Risk 49
Severity
9.2
First published (updated )

Panduit IntraVUE by PronetiqsUnintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs

Risk 87
Severity
10
First published (updated )

9router 9router9router before 0.4.60 Remote Code Execution via default password

Risk 82
Severity
9.4
First published (updated )

npm/calcom/cal.diyCal.com through 4.7.15 Cross-Site Scripting via booking questions

Risk 69
Severity
9.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

calcom/cal.diyCal.com before 5.9.9 Remote Code Execution via RSC

Risk 87
Severity
10
First published (updated )

calcom/cal.diyCal.com through 4.7.15 Cross-Site Scripting via booking questions

Risk 69
Severity
9.3
First published (updated )

MZ Automation LibIEC61850Stack-based Buffer Overflow in MZ Automation libIEC61850

Risk 79
Severity
9.2
First published (updated )

SAML Single Sign On SSO Login plugin for WordPressSAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter

Risk 86
Severity
9.8
First published (updated )

Appriss Insights VINE SQLIAppriss Insights VINE SQLI

Risk 86
Severity
9.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203