4.8
CVE-2026-1444 - iJason-Liu Books_Manager add_book_check.php cross site scripting
A vulnerability has been found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This affects an unknown part of the file controllers/books_center/add_book_check.php. Such manipulation of the argument mark leads to cross site scripting. The attack can be launched remotely.β¦
9.8
CVE-2026-22709 - vm2 has a Sandbox Escape
vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization can be bypassed. This allows attackers to escape the sandbox and run arbitrary code. In lib/setup-sandbox.js, the callback function of `localPromiseβ¦
9.3
CVE-2026-22696 - dcap-qvl has Missing Verification for QE Identity
dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present in versions prior to 0.3.9 involves a critical gap in the cryptographic verification process within the dcap-qvl. The library fetches QE Identity collateral (including qe_identityβ¦
6.9
CVE-2026-1443 - code-projects Online Music Site AdminDeleteUser.php sql injection
A flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminDeleteUser.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and β¦
4
CVE-2025-9820 - Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the applicβ¦
3.3
CVE-2025-9615 - Networkmanager: networkmanager file access
A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added theβ¦
6.1
CVE-2025-11687 - Gi-docgen: reflected dom xss in gi-docgen
A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page β enabling DOM access, session cookie theft and other client-side attacks β via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).
5.1
CVE-2025-9522 - Blind Server-Side Request Forgery (SSRF) in Omada Controller
Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information.
2.1
CVE-2025-9521 - Password Confirmation Bypass in Omada Controller
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification,Β and change the userβs password without proper confirmation, leading to weakened account security.
8.3
CVE-2025-9520 - IDOR Leading to Owner Account Hijacking in Omada Controller
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.