CVE watch

Every disclosure pulled from the NVD feed, filterable by severity.

All Critical High Medium Low Unknown
CVE-2026-71510 MEDIUM

CVE-2026-71510 published: Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column restricti...

View full advisory →
CVE-2026-63693 MEDIUM

CVE-2026-63693 published: Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write

View full advisory →
CVE-2020-37268 MEDIUM

CVE-2020-37268 published: Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter, and the inlining d...

View full advisory →
CVE-2026-71507 MEDIUM

CVE-2026-71507 published: Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of an...

View full advisory →
CVE-2026-71508 MEDIUM

CVE-2026-71508 published: Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. At...

View full advisory →
CVE-2026-71509 MEDIUM

CVE-2026-71509 published: Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting approval status and a...

View full advisory →
CVE-2026-71503 MEDIUM

CVE-2026-71503 published: Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Pol...

View full advisory →
CVE-2026-13213 MEDIUM

CVE-2026-13213 published: The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set unconditionally via BT_CONN_CB_DEFINE, so security_changed() runs for every connection that establishes security even before the application has ...

View full advisory →
CVE-2026-75099 MEDIUM

CVE-2026-75099 published: Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the issue.

View full advisory →
CVE-2026-63621 MEDIUM

CVE-2026-63621 published: Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer in camel-knative maps inbound CloudEvent attributes onto Came...

View full advisory →
CVE-2026-60093 MEDIUM

CVE-2026-60093 published: Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-datalake component can down...

View full advisory →
CVE-2026-59230 MEDIUM

CVE-2026-59230 published: Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-mail component ships a MimeMultipart data format that can unmarshal a ...

View full advisory →
CVE-2026-67204 MEDIUM

CVE-2026-67204 published: BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery...

View full advisory →
CVE-2026-13343 MEDIUM

CVE-2026-13343 published: The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (uint32_t data[4]). The builders make_endpoint_info() and make_function_block_info() populate only the first two words (res.data[0] and re...

View full advisory →
CVE-2026-9728 MEDIUM

CVE-2026-9728 published: The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the original, still-mutable userspace struct mbox_msg...

View full advisory →
CVE-2026-65053 MEDIUM

CVE-2026-65053 published: Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it. In lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of the data part with IMP_Contents::getPartName(), which retur...

View full advisory →
CVE-2026-21755 MEDIUM

CVE-2026-21755 published: HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service.

View full advisory →
CVE-2026-39914 MEDIUM

CVE-2026-39914 published: TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for administrative use only. Attackers can craft and submit u...

View full advisory →
CVE-2026-17033 MEDIUM

CVE-2026-17033 published: An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's Grafan...

View full advisory →
CVE-2025-68833 MEDIUM

CVE-2025-68833 published: HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.

View full advisory →