CVE-2026-85789
CVE-2026-85789 has been deprecated and is no longer publicly available, so no vulnerability details are disclosed.
View analysisVulnerability intel
Search the latest CVE vulnerabilities with severity scores, CVSS ratings, affected products, impact analysis, and remediation guidance.
No CVEs ingested yet. The scraper will populate this list shortly.
CVE-2026-85789 has been deprecated and is no longer publicly available, so no vulnerability details are disclosed.
View analysisA flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
View analysisAffinity by Canva versions prior to 3.3.0 are vulnerable to a stack-based buffer overflow when parsing Affinity document files. An attacker can craft a malicious file that, when opened, may allow arbitrary code execution on the victim’s machine.
View analysisA DLL hijacking flaw in GeoVision GV-Remote E-Map allows a local user with write access to a directory to drop a malicious DLL that is loaded before the legitimate one. If exploited, the attacker can run arbitrary code in the context of the GV-Remote E-Map process, potentially compromising local data and system integrity.
View analysisCVE-2026-86340 exposes a flaw in the deployment gate logic of protected environments. High‑privileged users can delete the sole approver (user or group) and bypass the required multi‑party approval process, allowing unauthorized deployments.
View analysisCVE‑2026‑86341 is a critical access‑control flaw that allows an attacker to bypass deployment approval checks by disabling strict policies after a deployment object has been altered. The vulnerability can silently enable unapproved code changes to reach production, compromising the integrity of the deployment pipeline.
View analysisA high‑severity buffer overflow in the Unicode conversion wrapper of certain Git hosting platforms allows an authenticated user to upload a crafted Git export file that triggers arbitrary remote code execution during Advanced Search indexing. The flaw can lead to full server compromise if exploited.
View analysisA remote null‑pointer dereference flaw exists in Artifex MuPDF’s PDF Xref loading routine. The bug can crash the application when processing a crafted PDF, leading to a denial‑of‑service condition.
View analysisA flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
View analysis404 Error | Tenable® CVEs Settings Links Tenable Cloud Tenable Community & Support Tenable University Severity CVSS v2 CVSS v3 CVSS v4 Theme Light Dark Auto Help Plugins Overview Plugins Pipeline Newest Updated Search Nessus Families WAS Families NNM Families Tenable OT Security Families Tenable Cloud Security Families Tenable Self-Hosted Container Security Families About Plugin Families Release Notes Audits Overview Newest Updated Search Audit Files Search Items References Authorities Documentation Download All Audit Files Indicators Overview Search Indicators of Attack Indicators of Exposure Release Notes CVEs Overview Newest Updated Search Attack Path Techniques Overview Search Links Tenable Cloud Tenable Community & Support Tenable University Settings Severity CVSS v2 CVSS v3 CVSS v4 Theme Light Dark Auto CVE Deprecated This CVE ID has been deprecated and is no longer publicly available.
View analysisThe LearnPress WordPress plugin (prior to 4.4.7) lacks proper capability checks in an admin template handler, enabling unauthenticated users to read all published quiz questions and perform keyword searches on them. This flaw exposes quiz content that should remain private to site administrators and instructors.
View analysisThe LearnPress WordPress plugin (versions prior to 4.4.7) fails to verify user permissions when processing a REST API request that filters courses by status. This flaw lets an unauthenticated user retrieve a list of courses that are draft, pending, private, scheduled, or trashed, exposing unpublished content.
View analysisNango 0.70.4 does not validate user‑supplied configuration values that are interpolated into provider token and proxy URL templates. An authenticated attacker can inject malicious values to force the server to send requests to internal or cloud metadata endpoints, potentially leaking provider credentials.
View analysisUVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
View analysisphpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification.
View analysisPrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.
View analysisPrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers' private wishlist contents.
View analysisbrowserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files. Attackers can navigate Playwright-driven browsers to file scheme URLs and access files accessible to the container process despite the ALLOW_FILE_PROTOCOL setting defaulting to false.
View analysisdecap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the repository directory name to read, write, or delete files outside the intended repository root.
View analysisMetabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.
View analysisLoading more…
End of results