CVE watch

Every disclosure pulled from the NVD feed, filterable by severity.

All Critical High Medium Low Unknown
CVE-2026-72704 MEDIUM

CVE-2026-72704 published: The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by transport. A fixpoint may apply a rewrite along an equality between types to its recursive argument, ...

View full advisory →
CVE-2026-72705 MEDIUM

CVE-2026-72705 published: The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass itself as a higher-order argument to a second fixpoint, which then applies it to a value that is not a subterm of the structural ar...

View full advisory →
CVE-2026-72711 MEDIUM

CVE-2026-72711 published: The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and theorem paths perform, so a value containing a free variable that is absent from the l...

View full advisory →
CVE-2026-72714 MEDIUM

CVE-2026-72714 published: Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local Unset Universe Checking inside a module is expected to last only until the module ends, and the global flag i...

View full advisory →
CVE-2026-75368 UNKNOWN

CVE-2026-75368 published: A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted ECSS TC message.

View full advisory →
CVE-2026-71511 MEDIUM

CVE-2026-71511 published: Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can call the individual...

View full advisory →
CVE-2026-71510 MEDIUM

CVE-2026-71510 published: Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column restricti...

View full advisory →
CVE-2026-63693 MEDIUM

CVE-2026-63693 published: Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write

View full advisory →
CVE-2026-61419 HIGH

CVE-2026-61419 published: Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

View full advisory →
CVE-2020-37268 MEDIUM

CVE-2020-37268 published: Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter, and the inlining d...

View full advisory →
CVE-2026-71507 MEDIUM

CVE-2026-71507 published: Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of an...

View full advisory →
CVE-2026-71508 MEDIUM

CVE-2026-71508 published: Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. At...

View full advisory →
CVE-2026-71509 MEDIUM

CVE-2026-71509 published: Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting approval status and a...

View full advisory →
CVE-2026-71832 UNKNOWN

CVE-2026-71832 published: Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service

View full advisory →
CVE-2026-71503 MEDIUM

CVE-2026-71503 published: Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Pol...

View full advisory →
CVE-2026-71504 HIGH

CVE-2026-71504 published: Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-...

View full advisory →
CVE-2026-71505 HIGH

CVE-2026-71505 published: Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company b...

View full advisory →
CVE-2026-71506 HIGH

CVE-2026-71506 published: Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issu...

View full advisory →
CVE-2026-39975 UNKNOWN

CVE-2026-39975 published: Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write act...

View full advisory →
CVE-2026-40877 HIGH

CVE-2026-40877 published: Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.

View full advisory →