7.1
CVE-2026-1999 - Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unaut…
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge their own pull request into a repository without having push access by exploiting an authorization bypass in the enable_auto_merge mutation for pull requests. This issue only affect…
6
CVE-2026-1355 - Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository M…
A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another user’s repository migration export due to a missing authorization check in the repository migration upload endpoint. By supplying the migration identif…
7.6
CVE-2026-0573 - Improper Handling of HTTP Redirects vulnerability was identified in GitHub Enterprise Server that a…
An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorization tokens. The repository_pages API insecurely followed HTTP redirects when fetching artifact URLs, preserving the authorization header containing a pr…
6.9
CVE-2026-2668 - Rongzhitong Visual Integrated Command and Dispatch Platform User add access control
A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an unknown function of the file /dm/dispatch/user/add of the component User Handler. The manipulation results in improper access controls. The attack may be launched remotely. The e…
6.9
CVE-2026-2667 - Rongzhitong Visual Integrated Command and Dispatch Platform api access control
A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impacted element is an unknown function of the file /dispatch/api?cmd=userinfo. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has…
5.3
CVE-2025-10256 - Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c)
A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file wi…
3.7
CVE-2026-2708 - libsoup: libsoup: HTTP Request Smuggling via Duplicate Content-Length Headers
No description is available for this CVE.
5.1
CVE-2026-2666 - mingSoft MCMS Template Archive uploadTemplate.do unrestricted upload
A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit…
5.3
CVE-2026-2665 - huanzi-qch base-admin JSP Parser SysFileController.java upload unrestricted upload
A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file SysFileController.java of the component JSP Parser. Performing a manipulation of the argument File results in unrestricted upload. The attack can be init…
9.3
CVE-2026-23491 - InvoicePlane has Unauthenticated Path Traversal in Guest Controller
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get_file` method of the `Guest` module's `Get` controller in InvoicePlane up to and including through 1.6.3. The vulnerability allows unauthenticated att…