8.6
CVE-2026-25748 - authentik has a forward authentication bypass with broken cookie
authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik or Caddy as reverse proxy. When a malicious cookiโฆ
9.1
CVE-2026-25227 - authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoโฆ
authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the authentik server containโฆ
8.9
CVE-2026-24895 - FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows execution of โฆ
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHPโs CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split index (for finding .php) on a lowercased copy of the request path but applies that byte index to the oโฆ
8.7
CVE-2026-24894 - FrankenPHP leaks session data between requests in worker mode
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentiaโฆ
9.2
CVE-2026-24044 - ESS Community Helm Chart has a weak server key generation method
Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, alโฆ
0.0
CVE-2019-25348 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
7.1
CVE-2019-25347 - thesystem App 1.0 - 'username' SQL Injection
thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 to the username field to gain unauthorized access to user accounts.
7.1
CVE-2019-25346 - thesystem 1.0 - 'server_name' SQL Injection
TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Attackers can inject malicious SQL code like ' or '1=1 to retrieve unauthorized database records and potentially access sensitive system information.
8.5
CVE-2019-25345 - RTK IIS Codec Service 6.4.10041.133 - 'RtkI2SCodec' Unquote Service Path
Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service configuration to inject malicious executables and escalate privileges on the system.
8.5
CVE-2019-25344 - MobileGo 8.5.0 - Insecure File Permissions
Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application directory. Attackers can replace the original MobileGo.exe with a malicious executable to create a new user account and add it to the Administrators gโฆ