NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-80202 Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or othe... 2026-08-26 8.8 NETWORK HIGH NVD
CVE-2026-80201 Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiT... 2026-08-26 2.0 NETWORK LOW NVD
CVE-2026-80200 Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parame... 2026-08-26 4.7 NETWORK MEDIUM NVD
CVE-2026-80199 Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames vi... 2026-08-26 3.7 NETWORK LOW NVD
CVE-2026-80198 Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access ... 2026-08-26 7.5 NETWORK HIGH NVD
CVE-2026-80197 Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated user... 2026-08-26 4.3 NETWORK MEDIUM NVD
CVE-2026-80196 Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLi... 2026-08-26 7.5 NETWORK HIGH NVD
CVE-2026-80195 Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which re... 2026-08-26 5.4 NETWORK MEDIUM NVD
CVE-2026-80194 Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authori... 2026-08-26 4.3 NETWORK MEDIUM NVD
CVE-2026-80193 Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users... 2026-08-26 8.8 NETWORK HIGH NVD
CVE-2026-80192 @better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership fla... 2026-08-26 8.1 NETWORK HIGH NVD
CVE-2026-80191 GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdPar... 2026-08-26 7.5 NETWORK HIGH NVD
CVE-2026-80189 LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write. ZipExtractor.ExtractToDir in internal/importer/zip_extractor.g... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-58092 In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of t... 2026-08-26 8.1 NETWORK HIGH NVD
CVE-2026-58091 The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync gr... 2026-08-26 7.8 LOCAL HIGH NVD