Core vulnerabilities
CVEs whose affected-version data names the Core package (composer, pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
45 CVEsRSS
CVE-2026-102098High· 7.2Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection
Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlyin…
CVE-2026-102096High· 7.2Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed
Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted packa…
CVE-2026-102093High· 7.2Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-man…
Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-man…
CVE-2026-102092High· 8.7Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they p…
Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they p…
CVE-2026-102090Medium· 4.3Kiteworks Core before version 9.5.1 is vulnerable to Content Injection
Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate…
CVE-2026-96450Medium· 5.4Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions.
Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions.
CVE-2026-62998Medium· 4.3PoCREDAXO is a PHP-based content management system
REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortable() registered the requested column. …
CVE-2026-63001Medium· 4.8REDAXO is a PHP-based content management system
REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_manager/lib/media_manager.php inserts a Media Manager type name into raw backend warning HTML without escaping it whe…
CVE-2026-63002Medium· 4.8PoCREDAXO is a PHP-based content management system
REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync page without rex_escape(). An attacker wh…
CVE-2026-63000Medium· 6.4PoCREDAXO is a PHP-based content management system
REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/install/lib/api/api_package_update.php inherits the false default from rex_api_function::requiresCsrfProtection() inste…
CVE-2026-91129Medium· 5.4PoCHome Assistant is open source home automation software focused on local control and privacy
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in homeassistant/components/ip…
CVE-2026-53581Critical· 9.0PoCOPNsense is a FreeBSD based firewall and routing platform
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite a…
CVE-2026-85093Medium· 6.5PoCCheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points
Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conver…
CVE-2026-73419Medium· 6.8NextAuth.js provides authentication for Next.js
NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound t…
CVE-2026-5598High· 7.5Covert timing channel vulnerability in Legion of the Bouncy Castle Inc
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, f…