6.1
CVE-2026-30162 - TimoΒ 2.0.3 CrossβSite Scripting via Title Field Links
Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field.
6.2
CVE-2026-29976 - hcxpcapngtool: hcxtools: ZerBea hcxpcapngtool: Information disclosure via buffer overflow in getradβ¦
Buffer Overflow vulnerability in ZerBea hcxpcapngtool v. 7.0.1-43-g2ee308e allows a local attacker to obtain sensitive information via the getradiotapfield() function
9.8
CVE-2026-30457 -
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
6.1
CVE-2026-29969 -
A cross-site scripting (XSS) vulnerability in the wff_cols_pref.css.aspx endpoint of staffwiki v7.0.1.19219 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted HTTP request.
6.5
CVE-2026-29905 - Persistent Denial of Service via Malformed Image Upload in Kirby CMS
Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image upload. The application fails to properly validate the return value of the PHP getimagesize() function. When the system attempts to process this file foβ¦
6.1
CVE-2026-29934 - Reflected XSS in LightCMS Admin Menus via Modified Referer
A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referer value in the request header.
7.7
CVE-2026-30463 - SQL Injection via Login Controller in FuelCMS 1.5.2
Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.
0.0
CVE-2026-23396 - wifi: mac80211: fix NULL deref in mesh_matches_local()
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL deref in mesh_matches_local() mesh_matches_local() unconditionally dereferences ie->mesh_config to compare mesh configuration parameters. When called from mesh_rx_csa_frame(), the parsed action-frame elemβ¦
9.1
CVE-2026-30458 -
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.
6.2
CVE-2026-23398 - icmp: fix NULL pointer dereference in icmp_tag_validation()
In the Linux kernel, the following vulnerability has been resolved: icmp: fix NULL pointer dereference in icmp_tag_validation() icmp_tag_validation() unconditionally dereferences the result of rcu_dereference(inet_protos[proto]) without checking for NULL. The inet_protos[] array is sparse -- onlyβ¦