##
Updated at UTC 2026-05-30T10:53:48.936430
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-10112 | 2.4 | 0.00% | 2 | 0 | 2026-05-30T08:16:16.180000 | A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affec | |
| CVE-2026-10110 | 7.3 | 0.00% | 2 | 1 | 2026-05-30T07:16:27.813000 | A vulnerability was detected in code-projects Student Details Management System | |
| CVE-2026-10044 | 7.5 | 0.05% | 1 | 0 | 2026-05-30T04:17:05.463000 | Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vul | |
| CVE-2026-44724 | 7.8 | 0.05% | 1 | 0 | 2026-05-30T02:16:19.137000 | systeminformation is a System and OS information library for node.js. From 4.17. | |
| CVE-2026-9831 | 6.3 | 0.00% | 2 | 0 | 2026-05-29T22:16:23.980000 | A race condition in the shared Extreme Platform ONE IAM Gateway API-key authenti | |
| CVE-2026-42941 | 8.3 | 0.00% | 2 | 0 | 2026-05-29T21:31:30 | The Danelec MacGregor Voyage Data Recorder device includes a default username a | |
| CVE-2026-9051 | 9.1 | 0.00% | 2 | 0 | 2026-05-29T21:31:24 | There is an authentication bypass vulnerability in the NI SystemLink Enterprise | |
| CVE-2026-49368 | 8.7 | 0.00% | 2 | 0 | 2026-05-29T21:31:23 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification tem | |
| CVE-2026-49374 | 7.6 | 0.00% | 2 | 0 | 2026-05-29T21:31:23 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build con | |
| CVE-2026-49367 | 8.0 | 0.00% | 2 | 0 | 2026-05-29T21:31:22 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via th | |
| CVE-2026-5343 | 7.4 | 0.02% | 1 | 0 | 2026-05-29T21:31:18 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAM | |
| CVE-2026-45663 | 9.9 | 0.00% | 2 | 0 | 2026-05-29T21:16:40.203000 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and ear | |
| CVE-2026-8364 | 9.8 | 0.04% | 1 | 0 | 2026-05-29T20:26:29.583000 | Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) | |
| CVE-2026-8363 | 9.8 | 0.04% | 1 | 0 | 2026-05-29T20:26:29.583000 | A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when p | |
| CVE-2026-45627 | 8.2 | 0.00% | 2 | 0 | 2026-05-29T20:25:00.760000 | Arcane is an interface for managing Docker containers, images, networks, and vol | |
| CVE-2026-45625 | 9.9 | 0.00% | 2 | 0 | 2026-05-29T20:25:00.760000 | Arcane is an interface for managing Docker containers, images, networks, and vol | |
| CVE-2026-45661 | 9.9 | 0.00% | 2 | 0 | 2026-05-29T20:25:00.760000 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and ear | |
| CVE-2026-45633 | 9.9 | 0.00% | 2 | 0 | 2026-05-29T20:25:00.760000 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and ear | |
| CVE-2026-47179 | 7.7 | 0.00% | 2 | 0 | 2026-05-29T20:25:00.760000 | Arcane is an interface for managing Docker containers, images, networks, and vol | |
| CVE-2026-45372 | 9.9 | 0.00% | 2 | 0 | 2026-05-29T20:23:08.683000 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library | |
| CVE-2026-44422 | 7.5 | 0.00% | 2 | 0 | 2026-05-29T20:22:37.383000 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0 | |
| CVE-2026-44420 | 8.8 | 0.00% | 2 | 0 | 2026-05-29T20:22:37.383000 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0 | |
| CVE-2026-48557 | 8.8 | 0.00% | 2 | 0 | 2026-05-29T20:21:38.773000 | Spatie Laravel Media Library before version 11.23.0 contains a file upload restr | |
| CVE-2026-9998 | 8.3 | 0.03% | 1 | 0 | 2026-05-29T20:18:44.250000 | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remo | |
| CVE-2026-44648 | 7.5 | 0.00% | 2 | 1 | 2026-05-29T20:17:38.110000 | SillyTavern is a locally installed user interface that allows users to interact | |
| CVE-2026-0257 | 9.1 | 0.07% | 6 | 4 | 2026-05-29T20:16:21.803000 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of | |
| CVE-2026-49366 | 7.8 | 0.00% | 2 | 0 | 2026-05-29T20:11:15.977000 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via fi | |
| CVE-2026-49372 | 7.5 | 0.00% | 2 | 0 | 2026-05-29T20:11:15.977000 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build st | |
| CVE-2026-45321 | 9.6 | 15.09% | 3 | 12 | 2026-05-29T19:41:37.437000 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions | |
| CVE-2026-42929 | 8.3 | 0.00% | 2 | 0 | 2026-05-29T19:16:23.830000 | Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded | |
| CVE-2026-46834 | 7.5 | 0.04% | 1 | 0 | 2026-05-29T18:32:27 | Vulnerability in the Net Service component of Oracle Database Server. Supported | |
| CVE-2026-5386 | 9.1 | 0.00% | 2 | 0 | 2026-05-29T18:31:42 | The affected KMW CCTV Security Cameras are vulnerable to a critical unauthentica | |
| CVE-2026-7786 | 9.8 | 0.00% | 2 | 0 | 2026-05-29T18:31:42 | Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Con | |
| CVE-2026-6824 | 8.4 | 0.00% | 2 | 0 | 2026-05-29T18:31:42 | A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series | |
| CVE-2026-32905 | 8.3 | 0.00% | 2 | 0 | 2026-05-29T18:31:42 | OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the b | |
| CVE-2026-44962 | 9.9 | 0.00% | 2 | 0 | 2026-05-29T18:31:42 | Plesk contains an XPath injection vulnerability in the APS Application Catalog s | |
| CVE-2026-10066 | 8.8 | 0.00% | 2 | 0 | 2026-05-29T18:31:41 | A security vulnerability has been detected in Shibby Tomato up to 1.28. This iss | |
| CVE-2026-10065 | 8.8 | 0.00% | 2 | 0 | 2026-05-29T18:31:41 | A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects | |
| CVE-2026-46821 | 7.7 | 0.03% | 1 | 0 | 2026-05-29T18:31:20 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Busine | |
| CVE-2026-46840 | 10.0 | 0.04% | 1 | 1 | 2026-05-29T18:31:20 | Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). S | |
| CVE-2026-46837 | 8.8 | 0.04% | 1 | 0 | 2026-05-29T18:31:20 | Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suit | |
| CVE-2026-9999 | 8.8 | 0.04% | 1 | 1 | 2026-05-29T18:17:18.940000 | Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.777 | |
| CVE-2026-5768 | 8.8 | 0.00% | 2 | 0 | 2026-05-29T18:17:12.997000 | The Frontier X2 device allows unauthenticated BLE read/write access to critical | |
| CVE-2026-45615 | 8.2 | 0.00% | 1 | 0 | 2026-05-29T18:17:10.163000 | mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulne | |
| CVE-2026-44973 | 8.1 | 0.05% | 1 | 0 | 2026-05-29T16:32:14.400000 | Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple pa | |
| CVE-2026-35674 | 8.8 | 0.00% | 2 | 0 | 2026-05-29T16:29:34.540000 | OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway c | |
| CVE-2026-35630 | 8.0 | 0.00% | 2 | 0 | 2026-05-29T16:29:34.540000 | OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBo | |
| CVE-2026-10067 | 8.8 | 0.00% | 2 | 0 | 2026-05-29T16:29:11.350000 | A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub | |
| CVE-2026-45104 | 7.5 | 0.04% | 1 | 0 | 2026-05-29T16:25:57.843000 | MapServer is a system for developing web-based GIS applications. From 6.4.0 to b | |
| CVE-2026-32847 | 7.5 | 0.08% | 1 | 0 | 2026-05-29T16:19:35.753000 | DeepCode through commit c991dc2 contains a path traversal vulnerability in the S | |
| CVE-2026-46839 | 9.9 | 0.04% | 1 | 0 | 2026-05-29T16:16:30.780000 | Vulnerability in Oracle REST Data Services (component: Core). Supported version | |
| CVE-2026-46835 | 7.5 | 0.04% | 1 | 0 | 2026-05-29T16:16:30.520000 | Vulnerability in the Net Service component of Oracle Database Server. Supported | |
| CVE-2026-9739 | 0 | 0.02% | 1 | 0 | 2026-05-29T15:42:56.873000 | Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During | |
| CVE-2026-32999 | 9.0 | 0.05% | 1 | 0 | 2026-05-29T15:39:34.620000 | Insufficient character filtering in backup agent signing module on Comet Backup | |
| CVE-2026-44887 | 9.8 | 0.21% | 1 | 0 | 2026-05-29T15:29:42.387000 | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to | |
| CVE-2026-45083 | 9.8 | 0.04% | 1 | 0 | 2026-05-29T15:29:42.387000 | The Goobi viewer is a web application that allows digitised material to be displ | |
| CVE-2026-45578 | 8.8 | 0.00% | 1 | 0 | 2026-05-29T15:06:44.207000 | WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cl | |
| CVE-2026-44850 | 8.5 | 0.03% | 1 | 0 | 2026-05-29T15:06:44.207000 | Portainer Community Edition is a lightweight service delivery platform for conta | |
| CVE-2026-7480 | 0 | 0.01% | 1 | 0 | 2026-05-29T14:46:09.837000 | An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS S | |
| CVE-2026-46510 | 8.2 | 0.00% | 1 | 0 | 2026-05-29T14:16:31.807000 | form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-obje | |
| CVE-2026-35675 | 8.2 | 0.11% | 1 | 0 | 2026-05-29T14:16:26.403000 | phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the pas | |
| CVE-2026-38703 | 9.8 | 0.27% | 1 | 0 | 2026-05-29T14:09:03.913000 | A command injection vulnerability exists in the ZeroTier VPN feature of InHand N | |
| CVE-2026-38707 | 9.8 | 0.27% | 1 | 0 | 2026-05-29T14:08:41.327000 | A command injection vulnerability exists in the IPSec VPN feature of InHand Netw | |
| CVE-2026-49127 | 8.6 | 0.06% | 1 | 0 | 2026-05-29T14:07:47.980000 | Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflo | |
| CVE-2026-3655 | 9.8 | 0.26% | 1 | 0 | 2026-05-29T13:09:05.450000 | The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulner | |
| CVE-2026-8732 | 9.8 | 0.07% | 1 | 1 | 2026-05-29T07:20:15 | The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via A | |
| CVE-2026-8070 | None | 0.01% | 1 | 0 | 2026-05-29T03:31:14 | Incorrect permission assignment for a critical resource in Armoury Crate allows | |
| CVE-2026-46833 | 9.0 | 0.04% | 1 | 0 | 2026-05-29T02:47:03.023000 | Vulnerability in the Net Service component of Oracle Database Server. Supported | |
| CVE-2026-47333 | 7.8 | 0.01% | 1 | 0 | 2026-05-29T02:45:36.283000 | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentia | |
| CVE-2026-49128 | 7.5 | 0.11% | 1 | 0 | 2026-05-29T00:39:36 | Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulne | |
| CVE-2026-8809 | 9.8 | 0.19% | 1 | 0 | 2026-05-29T00:38:45 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privi | |
| CVE-2026-39929 | 7.5 | 0.11% | 1 | 0 | 2026-05-28T22:16:58.693000 | Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5. | |
| CVE-2026-9645 | 9.9 | 0.05% | 1 | 0 | 2026-05-28T21:32:17 | Exposed methods allow authenticated users to create and execute arbitrary JavaSc | |
| CVE-2026-47331 | 7.8 | 0.01% | 1 | 0 | 2026-05-28T21:32:10 | Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock wh | |
| CVE-2026-4944 | 8.8 | 0.09% | 1 | 0 | 2026-05-28T21:32:10 | vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remot | |
| CVE-2026-43898 | 10.0 | 0.05% | 1 | 0 | 2026-05-28T20:16:23.810000 | SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined fu | |
| CVE-2026-47759 | 8.7 | 0.03% | 1 | 0 | 2026-05-28T19:19:37.803000 | TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, t | |
| CVE-2026-47760 | 8.7 | 0.03% | 1 | 0 | 2026-05-28T19:19:03.740000 | TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE | |
| CVE-2026-46509 | 8.2 | 0.04% | 1 | 0 | 2026-05-28T19:16:39.280000 | deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, pr | |
| CVE-2026-46414 | 8.8 | 0.04% | 2 | 0 | 2026-05-28T18:56:36.823000 | Microsoft UFO open-source framework for intelligent automation across devices an | |
| CVE-2026-45322 | 7.8 | 0.06% | 1 | 0 | 2026-05-28T18:56:36.823000 | Microsoft UFO open-source framework for intelligent automation across devices an | |
| CVE-2026-45311 | 9.6 | 0.04% | 1 | 0 | 2026-05-28T18:40:37.990000 | CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, t | |
| CVE-2026-38702 | 9.8 | 0.27% | 1 | 0 | 2026-05-28T18:30:39 | A command injection vulnerability exists in the Admin Access feature of InHand N | |
| CVE-2026-9095 | 8.1 | 0.04% | 1 | 0 | 2026-05-28T18:30:39 | Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions withou | |
| CVE-2026-38704 | 9.8 | 0.27% | 1 | 0 | 2026-05-28T18:30:39 | A command injection vulnerability exists in the WireGuard VPN feature of InHand | |
| CVE-2026-49238 | 8.4 | 0.02% | 1 | 0 | 2026-05-28T18:00:33.730000 | An issue was discovered in Canonical Multipass before version 1.16.3. The host-s | |
| CVE-2026-44326 | 9.4 | 0.04% | 1 | 0 | 2026-05-28T16:25:38.687000 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, | |
| CVE-2026-48151 | 7.5 | 0.03% | 1 | 0 | 2026-05-28T16:16:28.793000 | Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schem | |
| CVE-2026-35671 | 8.8 | 0.04% | 1 | 0 | 2026-05-28T14:19:43 | ### Summary An Insecure Direct Object Reference (IDOR) vulnerability in phpMyFAQ | |
| CVE-2026-44711 | 7.9 | 0.02% | 1 | 0 | 2026-05-28T14:16:21.263000 | pam_usb provides hardware authentication for Linux using ordinary removable medi | |
| CVE-2026-44635 | 7.5 | 0.05% | 1 | 0 | 2026-05-28T14:16:20.450000 | Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, Defa | |
| CVE-2026-44709 | 7.8 | 0.02% | 1 | 0 | 2026-05-28T13:57:25.390000 | pam_usb provides hardware authentication for Linux using ordinary removable medi | |
| CVE-2026-9227 | 8.8 | 0.14% | 1 | 0 | 2026-05-28T13:45:25.260000 | The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary | |
| CVE-2026-9009 | 8.8 | 0.24% | 2 | 0 | 2026-05-28T13:45:25.260000 | The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnera | |
| CVE-2026-8915 | 8.8 | 0.02% | 2 | 0 | 2026-05-28T13:44:54.327000 | Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflo | |
| CVE-2026-7862 | 8.6 | 0.04% | 1 | 0 | 2026-05-28T12:33:02 | The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not proper | |
| CVE-2026-4408 | 9.0 | 0.23% | 2 | 0 | 2026-05-28T09:31:27 | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in S | |
| CVE-2026-6455 | 8.1 | 0.04% | 1 | 0 | 2026-05-28T09:31:26 | The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Sit | |
| CVE-2026-7802 | 8.8 | 0.06% | 1 | 0 | 2026-05-28T06:31:16 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authoriza | |
| CVE-2026-9789 | None | 0.02% | 1 | 0 | 2026-05-28T03:31:21 | A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense softwar | |
| CVE-2026-9208 | 8.8 | 0.07% | 1 | 0 | 2026-05-28T00:30:35 | Tanium addressed an unauthorized code execution vulnerability in Connect. | |
| CVE-2026-45332 | 7.5 | 0.04% | 1 | 0 | 2026-05-27T21:32:32 | ### Summary A Broken Access Control vulnerability allows an unauthenticated at | |
| CVE-2026-8359 | 7.5 | 0.05% | 1 | 0 | 2026-05-27T21:31:33 | When processing a request with a URL path starting with /status or /sysinfo, WOS | |
| CVE-2026-8362 | 9.8 | 0.04% | 1 | 0 | 2026-05-27T21:31:32 | A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when | |
| CVE-2026-8361 | 7.5 | 0.04% | 1 | 0 | 2026-05-27T21:31:32 | A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processin | |
| CVE-2026-8360 | 7.5 | 0.04% | 1 | 0 | 2026-05-27T21:31:32 | Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DL | |
| CVE-2026-48027 | 9.8 | 26.85% | 3 | 0 | 2026-05-27T20:34:24.850000 | Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious ver | |
| CVE-2026-45716 | 8.8 | 0.03% | 1 | 0 | 2026-05-27T20:16:39.200000 | Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/glo | |
| CVE-2026-45108 | 8.4 | 0.07% | 1 | 0 | 2026-05-27T20:16:38.550000 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. | |
| CVE-2026-48153 | 8.5 | 0.03% | 1 | 0 | 2026-05-27T19:44:35.987000 | Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the | |
| CVE-2026-45659 | 8.8 | 0.62% | 1 | 2 | 2026-05-27T18:32:54.337000 | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho | |
| CVE-2015-2808 | 10.0 | 23.36% | 1 | 0 | 2026-05-27T18:32:34 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not proper | |
| CVE-2025-14713 | 7.5 | 0.03% | 1 | 0 | 2026-05-27T14:54:20.160000 | An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Ed | |
| CVE-2026-46372 | 8.5 | 0.00% | 2 | 0 | template | 2026-05-27T06:01:20 | ## Resolution SillyTavern 1.18.0 added a generic server-side request filter (Pr |
| CVE-2026-5426 | 9.1 | 0.07% | 2 | 1 | 2026-05-26T19:16:29.123000 | Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver de | |
| CVE-2026-43284 | 7.8 | 25.56% | 1 | 33 | 2026-05-26T18:32:39 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: | |
| CVE-2026-47125 | 8.8 | 0.00% | 2 | 0 | 2026-05-23T00:16:58 | ## Summary The `PUT /api/environments/{id}/templates/variables` endpoint, which | |
| CVE-2026-41091 | 7.8 | 6.98% | 1 | 2 | 2026-05-20T19:06:36.850000 | Improper link resolution before file access ('link following') in Microsoft Defe | |
| CVE-2026-45498 | 4.0 | 4.11% | 1 | 1 | 2026-05-20T18:31:35 | Microsoft Defender Denial of Service Vulnerability | |
| CVE-2026-45137 | 8.2 | 0.04% | 1 | 0 | 2026-05-19T16:08:42 | ### Summary An logic error causes anchor programs to accept any program id when | |
| CVE-2026-31431 | 7.8 | 2.23% | 5 | 100 | 2026-05-18T18:32:28 | In the Linux kernel, the following vulnerability has been resolved: crypto: alg | |
| CVE-2026-45707 | 8.1 | 0.00% | 1 | 0 | 2026-05-18T17:41:42 | ## Summary When `ENABLE_MULTI_TENANT=true`, the HTTP transport documents that t | |
| CVE-2026-45697 | 9.8 | 0.00% | 2 | 0 | 2026-05-18T17:23:40 | ### Impact - Unauthenticated users could submit crafted values into Hidden field | |
| CVE-2026-43500 | 7.8 | 27.00% | 1 | 15 | 2026-05-17T16:16:16.740000 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also | |
| CVE-2026-8398 | 9.8 | 14.39% | 2 | 0 | 2026-05-15T09:31:43 | A supply chain attack compromised the official installation packages of DAEMON T | |
| CVE-2026-45374 | 9.6 | 0.04% | 1 | 0 | 2026-05-14T20:29:53 | ### Summary The `task_create` tool spawns durable sub-agents that inherit two i | |
| CVE-2026-45348 | 8.7 | 0.03% | 1 | 0 | 2026-05-14T20:23:52 | ## Summary The `packages.js` template at `src/pyload/webui/app/themes/modern/te | |
| CVE-2026-20182 | 10.0 | 77.32% | 1 | 3 | template | 2026-05-14T18:33:03 | May 2026: This security advisory provides the details and fix information for a |
| CVE-2026-40369 | 7.8 | 0.01% | 2 | 3 | 2026-05-14T17:52:50.143000 | Untrusted pointer dereference in Windows Kernel allows an authorized attacker to | |
| CVE-2026-44882 | 8.1 | 0.04% | 1 | 0 | 2026-05-14T16:24:31 | ## Summary Portainer proxies requests to Kubernetes clusters through a middlewa | |
| CVE-2026-45152 | 7.8 | 0.03% | 1 | 0 | 2026-05-13T15:33:13 | I discovered a command injection vulnerability in uniget that allows arbitrary c | |
| CVE-2026-28910 | 3.3 | 0.01% | 1 | 0 | 2026-05-13T14:02:20.380000 | This issue was addressed with improved permissions checking. This issue is fixed | |
| CVE-2026-44650 | 9.1 | 0.00% | 2 | 0 | 2026-05-12T22:23:47 | ## Summary `POST /api/extensions/delete` endpoint accepts `extensionName: "."` | |
| CVE-2026-44649 | 9.8 | 0.00% | 2 | 0 | 2026-05-12T22:23:33 | ## Resolution SillyTavern 1.18.0 now includes a configuration option to limit w | |
| CVE-2026-45088 | 7.5 | 0.03% | 1 | 0 | 2026-05-12T15:08:14 | ## Summary When dalfox is run in REST API server mode, the `custom-payload-file | |
| CVE-2026-26980 | 9.4 | 56.66% | 1 | 5 | template | 2026-05-12T13:31:01 | ### Impact A SQL injection vulnerability existed in Ghost's Content API that al |
| CVE-2026-45047 | 7.5 | 0.08% | 1 | 0 | 2026-05-11T16:17:49 | ### Summary The `apiHandler` (and similarly `webHandlerTelegramBot`) processes u | |
| CVE-2026-44483 | 8.2 | 0.04% | 1 | 0 | 2026-05-11T16:09:41 | ## Summary `setPath` in `@rvf/set-get` (used by `@rvf/core` to flatten incoming | |
| CVE-2026-44327 | 10.0 | 0.04% | 1 | 0 | 2026-05-08T22:59:24 | ### Summary free5GC's NEF mounts the `nnef-oam` route group without inbound OAut | |
| CVE-2026-39987 | 9.8 | 82.17% | 2 | 11 | template | 2026-04-23T20:15:29.690000 | marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE |
| CVE-2026-3172 | 8.1 | 0.06% | 2 | 0 | 2026-04-15T00:35:42.020000 | Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 all | |
| CVE-2024-8310 | 9.8 | 0.04% | 1 | 0 | 2026-04-15T00:35:42.020000 | OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass auth | |
| CVE-2024-55884 | 9.0 | 0.80% | 1 | 0 | 2026-04-15T00:35:42.020000 | In the Mullvad VPN client 2024.6 (Desktop), 2024.8 (iOS), and 2024.8-beta1 (Andr | |
| CVE-2026-35616 | 9.8 | 41.17% | 2 | 8 | template | 2026-04-06T18:12:57.863000 | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through |
| CVE-2024-49611 | 10.0 | 0.63% | 1 | 0 | 2026-04-01T18:32:06 | Unrestricted Upload of File with Dangerous Type vulnerability in Paxman Product | |
| CVE-2026-4565 | 8.8 | 0.09% | 1 | 2 | 2026-03-23T03:31:45 | A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function | |
| CVE-2025-10158 | 4.3 | 0.05% | 1 | 0 | 2025-11-18T15:30:54 | A malicious client acting as the receiver of an rsync file transfer can trigger | |
| CVE-2019-1385 | 7.8 | 0.49% | 2 | 0 | 2025-10-29T14:34:16.610000 | An elevation of privilege vulnerability exists when the Windows AppX Deployment | |
| CVE-2016-10156 | 7.8 | 0.71% | 1 | 0 | 2025-04-20T03:32:27 | A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files | |
| CVE-2025-0066 | 9.9 | 0.09% | 1 | 0 | 2025-01-14T03:31:48 | Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet C | |
| CVE-2021-4229 | 5.0 | 0.86% | 1 | 1 | 2024-11-21T06:37:11.567000 | A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated | |
| CVE-2017-16054 | 7.5 | 0.26% | 1 | 0 | 2024-11-21T03:15:44.050000 | `nodefabric` was a malicious module published with the intent to hijack environm | |
| CVE-2024-45694 | 9.8 | 2.49% | 1 | 0 | 2024-09-17T18:40:07.243000 | The web service of certain models of D-Link wireless routers contains a Stack-ba | |
| CVE-2024-7261 | 9.8 | 27.88% | 1 | 0 | 2024-09-13T19:39:40.570000 | The improper neutralization of special elements in the parameter "host" in the C | |
| CVE-2024-42395 | 9.8 | 0.27% | 2 | 0 | 2024-08-12T18:23:57.077000 | There is a vulnerability in the AP Certificate Management Service which could al | |
| CVE-2023-25136 | 9.8 | 88.33% | 1 | 11 | 2024-03-07T05:10:04 | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options. | |
| CVE-2021-24084 | 5.5 | 3.49% | 2 | 2 | 2024-01-07T05:05:26 | Windows Mobile Device Management Information Disclosure Vulnerability | |
| CVE-2025-60486 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2025-60485 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-45632 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-45631 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-45630 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-47740 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-44421 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-44285 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-47123 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-47744 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2025-55664 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-48710 | 0 | 0.03% | 4 | 3 | N/A | ||
| CVE-2025-60481 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2025-60483 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-48778 | 0 | 0.00% | 1 | 1 | N/A | ||
| CVE-2026-48800 | 0 | 0.00% | 1 | 1 | N/A | ||
| CVE-2025-60495 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-45662 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2025-60477 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-44698 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-45555 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-45344 | 0 | 0.16% | 1 | 0 | N/A | ||
| CVE-2026-48116 | 0 | 0.05% | 1 | 0 | N/A | ||
| CVE-2026-45039 | 0 | 0.04% | 1 | 0 | N/A | ||
| CVE-2026-45296 | 0 | 0.03% | 1 | 0 | N/A | ||
| CVE-2026-45323 | 0 | 0.04% | 1 | 0 | N/A | ||
| CVE-2026-47761 | 0 | 0.03% | 1 | 0 | N/A | ||
| CVE-2026-42197 | 0 | 0.03% | 1 | 0 | N/A | ||
| CVE-2026-27771 | 0 | 0.00% | 1 | 2 | N/A | ||
| CVE-2026-48095 | 0 | 0.00% | 2 | 1 | N/A | ||
| CVE-2026-46402 | 0 | 0.06% | 2 | 0 | N/A | ||
| CVE-2026-44590 | 0 | 0.85% | 1 | 1 | N/A | ||
| CVE-2026-45102 | 0 | 0.06% | 1 | 0 | N/A | ||
| CVE-2026-44888 | 0 | 0.05% | 1 | 0 | N/A | ||
| CVE-2026-48064 | 0 | 0.06% | 1 | 0 | N/A | ||
| CVE-2026-44713 | 0 | 0.02% | 1 | 0 | N/A | ||
| CVE-2026-44712 | 0 | 0.02% | 1 | 0 | N/A | ||
| CVE-2026-46425 | 0 | 0.04% | 1 | 0 | N/A | ||
| CVE-2026-48152 | 0 | 0.04% | 1 | 0 | N/A | ||
| CVE-2026-48150 | 0 | 0.05% | 1 | 0 | N/A | ||
| CVE-2026-48149 | 0 | 0.03% | 1 | 0 | N/A |
updated 2026-05-30T08:16:16.180000
2 posts
⚠️ XSS vuln (MEDIUM, CVSS 4.8) in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0 — CVE-2026-10112. 'Name' param on Dashboard Page unsanitized, allowing script injection. No patch yet — use input validation/output encoding. https://radar.offseq.com/threat/cve-2026-10112-cross-site-scripting-in-sambitraj-s-ee88cf56 #OffSeq #XSS #AppSec #Vulnerability
##⚠️ XSS vuln (MEDIUM, CVSS 4.8) in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0 — CVE-2026-10112. 'Name' param on Dashboard Page unsanitized, allowing script injection. No patch yet — use input validation/output encoding. https://radar.offseq.com/threat/cve-2026-10112-cross-site-scripting-in-sambitraj-s-ee88cf56 #OffSeq #XSS #AppSec #Vulnerability
##updated 2026-05-30T07:16:27.813000
2 posts
1 repos
⚠️ CVE-2026-10110: MEDIUM severity SQL injection in code-projects Student Details Management System 1.0 (/index.php, roll parameter). Public exploit available — remote attack possible. Monitor and restrict access. https://radar.offseq.com/threat/cve-2026-10110-sql-injection-in-code-projects-stud-7112fd7e #OffSeq #SQLInjection #Vuln
##⚠️ CVE-2026-10110: MEDIUM severity SQL injection in code-projects Student Details Management System 1.0 (/index.php, roll parameter). Public exploit available — remote attack possible. Monitor and restrict access. https://radar.offseq.com/threat/cve-2026-10110-sql-injection-in-code-projects-stud-7112fd7e #OffSeq #SQLInjection #Vuln
##updated 2026-05-30T04:17:05.463000
1 posts
🟠 CVE-2026-10044 - High (7.5)
Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying absolut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10044/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-30T02:16:19.137000
1 posts
🟠 CVE-2026-44724 - High (7.8)
systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44724/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T22:16:23.980000
2 posts
🚩 CVE-2026-9831: Medium severity race condition in Extreme Networks Extreme Platform ONE IAM Gateway. High-concurrency API key use may cause data leak across tenants. No patch yet — monitor advisories. Details: https://radar.offseq.com/threat/cve-2026-9831-cwe-362-concurrent-execution-using-s-84a029a5 #OffSeq #ExtremeNetworks #CloudSec #CVE2026_9831
##🚩 CVE-2026-9831: Medium severity race condition in Extreme Networks Extreme Platform ONE IAM Gateway. High-concurrency API key use may cause data leak across tenants. No patch yet — monitor advisories. Details: https://radar.offseq.com/threat/cve-2026-9831-cwe-362-concurrent-execution-using-s-84a029a5 #OffSeq #ExtremeNetworks #CloudSec #CVE2026_9831
##updated 2026-05-29T21:31:30
2 posts
🟠 CVE-2026-42941 - High (8.3)
The Danelec MacGregor Voyage Data Recorder
device includes a default username and password, with no enforced password change.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42941/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-42941 - High (8.3)
The Danelec MacGregor Voyage Data Recorder
device includes a default username and password, with no enforced password change.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42941/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T21:31:24
2 posts
🔴 CVE-2026-9051 - Critical (9.1)
There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9051/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-9051 - Critical (9.1)
There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9051/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T21:31:23
2 posts
🟠 CVE-2026-49368 - High (8.7)
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49368/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49368 - High (8.7)
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49368/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T21:31:23
2 posts
🟠 CVE-2026-49374 - High (7.6)
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49374/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49374 - High (7.6)
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49374/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T21:31:22
2 posts
🟠 CVE-2026-49367 - High (8)
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49367/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49367 - High (8)
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49367/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T21:31:18
1 posts
⚠️ HIGH severity: CVE-2026-5343 in Drupal SAML SSO - Service Provider (pre-3.1.4) allows privilege escalation via improper exception checks. No patch or exploits yet. Monitor advisories for updates. https://radar.offseq.com/threat/cve-2026-5343-cwe-754-improper-check-for-unusual-o-7182465d #OffSeq #Drupal #Vuln #SAML
##updated 2026-05-29T21:16:40.203000
2 posts
🔴 CVE-2026-45663 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45663/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45663 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45663/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:26:29.583000
1 posts
🔴 CVE-2026-8364 - Critical (9.8)
Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8364/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:26:29.583000
1 posts
🔴 CVE-2026-8363 - Critical (9.8)
A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8363/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:25:00.760000
2 posts
🟠 CVE-2026-45627 - High (8.2)
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via string...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-45627 - High (8.2)
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via string...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:25:00.760000
2 posts
🔴 CVE-2026-45625 - Critical (9.9)
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps sou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45625/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45625 - Critical (9.9)
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps sou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45625/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:25:00.760000
2 posts
🔴 CVE-2026-45661 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45661/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45661 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45661/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:25:00.760000
2 posts
🔴 CVE-2026-45633 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are dire...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45633/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45633 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are dire...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45633/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:25:00.760000
2 posts
🟠 CVE-2026-47179 - High (7.7)
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project's compose file before an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47179/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47179 - High (7.7)
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project's compose file before an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47179/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:23:08.683000
2 posts
🔴 CVE-2026-45372 - Critical (9.9)
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity ch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45372/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45372 - Critical (9.9)
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity ch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45372/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:22:37.383000
2 posts
🟠 CVE-2026-44422 - High (7.5)
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ow...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44422/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44422 - High (7.5)
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ow...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44422/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:22:37.383000
2 posts
🟠 CVE-2026-44420 - High (8.8)
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44420/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44420 - High (8.8)
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44420/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:21:38.773000
2 posts
🟠 CVE-2026-48557 - High (8.8)
Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48557/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48557 - High (8.8)
Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48557/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:18:44.250000
1 posts
🛡️ HIGH severity: Chrome <148.0.7778.216 has an integer overflow (CVE-2026-9998) in Skia. Potential sandbox escape if renderer is compromised. Patch ASAP! More info: https://radar.offseq.com/threat/cve-2026-9998-integer-overflow-in-google-chrome-20eb53d9 #OffSeq #Chrome #Vuln #Infosec
##updated 2026-05-29T20:17:38.110000
2 posts
1 repos
🟠 CVE-2026-44648 - High (7.5)
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session for authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44648/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44648 - High (7.5)
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session for authen...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44648/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:16:21.803000
6 posts
4 repos
https://github.com/0xBlackash/CVE-2026-0257
https://github.com/sfewer-r7/CVE-2026-0257
Palo Alto Networks Warns of Active Exploitation of GlobalProtect Flaw
Palo Alto Networks has issued a warning about a critical GlobalProtect flaw, CVE-2026-0257, that is being actively exploited, allowing attackers to bypass security restrictions and establish unauthorized VPN connections. This vulnerability affects specific PAN-OS and Prisma Access deployments with certain…
#PaloAltoNetworks #Globalprotect #Cve20260257 #VpnExploitation #AuthenticationBypass
##🏛️ Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
📝 CISA added CVE-2026-0257 to its KEV Catalog due to active exploitation, posing risks to...
📰 Alerts
##CVE ID: CVE-2026-0257
Vendor: Palo Alto Networks
Product: PAN-OS
Date Added: 2026-05-29
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0257
CVE-2026-0257 exploits a missing signature verification in GlobalProtect's cookie validation. Attackers forge authentication cookies using the /usr/local/bin/gpsvc binary's RSA private keys, gaining VPN access without...
##🏛️ Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
📝 CISA added CVE-2026-0257 to its KEV Catalog due to active exploitation, posing risks to...
📰 Alerts
##CVE ID: CVE-2026-0257
Vendor: Palo Alto Networks
Product: PAN-OS
Date Added: 2026-05-29
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-0257
updated 2026-05-29T20:11:15.977000
2 posts
🟠 CVE-2026-49366 - High (7.8)
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49366/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49366 - High (7.8)
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49366/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T20:11:15.977000
2 posts
🟠 CVE-2026-49372 - High (7.5)
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49372/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-49372 - High (7.5)
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49372/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T19:41:37.437000
3 posts
12 repos
https://github.com/nkopylov/tanscript-exploit-check
https://github.com/Intrudify/mini-shai-hulud-scanner
https://github.com/qi-scape/scan-shai-hulud
https://github.com/Yomisana/are-you-get-tanstack-attack
https://github.com/digi4care/shai-scan
https://github.com/Caixa-git/tanstack-shield
https://github.com/fabriziosalmi/tanstack-compromise-checker
https://github.com/shayr1/shai-hulud-scan
https://github.com/Breakingcircuitsllc/teampcp_shai_hulud.yar
https://github.com/ry-allan/tanstack-compromise-checker
https://github.com/renewablehacking/CVE-2026-45321-Tanstack
https://github.com/prashanthnataraj/mini-shai-hulud-detector
CVE-2026-45321 - Changed to Known Ransomware Status
TanStack Unspecified VulnerabilityVendor: TanStackProduct: TanStackTanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: May 28, 2026 at 18:00:35 UTCDate Added to KEV: https://nvd.nist.gov/vuln/detail/CVE-2026-45321
##🚨 [CISA-2026:0527] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0527)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-45321 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45321)
- Name: TanStack Unspecified Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TanStack
- Product: TanStack
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx ; https://nvd.nist.gov/vuln/detail/CVE-2026-45321
⚠️ CVE-2026-48027 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48027)
- Name: Nx Console Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Nx
- Product: Nx Console
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027
⚠️ CVE-2026-8398 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8398)
- Name: Daemon Tools Lite Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Daemon
- Product: Daemon Tools Lite
- Notes: https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398
#SecDB #InfoSec #CVE #CISA_KEV #cisa_20260527 #cisa20260527 #cve_2026_45321 #cve_2026_48027 #cve_2026_8398 #cve202645321 #cve202648027 #cve20268398
##CVE ID: CVE-2026-45321
Vendor: TanStack
Product: TanStack
Date Added: 2026-05-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45321
updated 2026-05-29T19:16:23.830000
2 posts
🟠 CVE-2026-42929 - High (8.3)
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42929/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-42929 - High (8.3)
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42929/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:32:27
1 posts
🟠 CVE-2026-46834 - High (7.5)
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46834/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:31:42
2 posts
🔴 CVE-2026-5386 - Critical (9.1)
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5386/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-5386 - Critical (9.1)
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the ca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5386/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:31:42
2 posts
🔴 CVE-2026-7786 - Critical (9.8)
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can be extracted through firmware analysis and u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7786/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-7786 - Critical (9.8)
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can be extracted through firmware analysis and u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7786/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:31:42
2 posts
🟠 CVE-2026-6824 - High (8.4)
A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6824/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-6824 - High (8.4)
A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6824/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:31:42
2 posts
🟠 CVE-2026-32905 - High (8.3)
OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32905/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-32905 - High (8.3)
OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32905/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:31:42
2 posts
🔴 CVE-2026-44962 - Critical (9.9)
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to exe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44962/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-44962 - Critical (9.9)
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to exe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44962/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:31:41
2 posts
🟠 CVE-2026-10066 - High (8.8)
A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. The attack can be initi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10066/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-10066 - High (8.8)
A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. The attack can be initi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10066/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:31:41
2 posts
🟠 CVE-2026-10065 - High (8.8)
A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack-based buffer overflow. It is possible to launch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10065/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-10065 - High (8.8)
A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack-based buffer overflow. It is possible to launch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10065/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:31:20
1 posts
🟠 CVE-2026-46821 - High (7.7)
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46821/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:31:20
1 posts
1 repos
🔴 CVE-2026-46840 - Critical (10)
Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Ora...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46840/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:31:20
1 posts
🟠 CVE-2026-46837 - High (8.8)
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46837/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:17:18.940000
1 posts
1 repos
CVE-2026-9999: HIGH severity flaw in Chrome (Mac, <148.0.7778.216) allows remote code execution in the sandbox via crafted HTML. No exploits in the wild. Patch to 148.0.7778.216+ now! https://radar.offseq.com/threat/cve-2026-9999-inappropriate-implementation-in-goog-790503e9 #OffSeq #Chrome #Mac #Vuln #Security
##updated 2026-05-29T18:17:12.997000
2 posts
🟠 CVE-2026-5768 - High (8.8)
The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-5768 - High (8.8)
The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5768/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T18:17:10.163000
1 posts
🟠 CVE-2026-45615 - High (8.2)
mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsing a maliciously crafted, zero-length OER payload...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45615/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T16:32:14.400000
1 posts
🟠 CVE-2026-44973 - High (8.1)
Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44973/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T16:29:34.540000
2 posts
🟠 CVE-2026-35674 - High (8.8)
OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35674/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-35674 - High (8.8)
OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35674/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T16:29:34.540000
2 posts
🟠 CVE-2026-35630 - High (8)
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35630/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-35630 - High (8)
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35630/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T16:29:11.350000
2 posts
🟠 CVE-2026-10067 - High (8.8)
A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. This project is superseded by FreshTomato...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10067/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-10067 - High (8.8)
A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. This project is superseded by FreshTomato...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10067/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T16:25:57.843000
1 posts
🟠 CVE-2026-45104 - High (7.5)
MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any carrying — it assumes msSLDParseRule added one class. When the rule ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45104/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T16:19:35.753000
1 posts
🟠 CVE-2026-32847 - High (7.5)
DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32847/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T16:16:30.780000
1 posts
🔴 CVE-2026-46839 - Critical (9.9)
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Ser...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46839/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T16:16:30.520000
1 posts
🟠 CVE-2026-46835 - High (7.5)
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46835/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T15:42:56.873000
1 posts
🚨 CRITICAL: CVE-2026-9739 in Google MCP Toolbox for Databases (CVSS 9.4) allows DNS rebinding via a permissive cross-domain policy in SSE. No patch yet — restrict untrusted domains & monitor advisories. https://radar.offseq.com/threat/cve-2026-9739-cwe-942-permissive-cross-domain-poli-e5d6e88a #OffSeq #CVE #Infosec #Google
##updated 2026-05-29T15:39:34.620000
1 posts
🔴 CVE-2026-32999 - Critical (9)
Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-32999/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T15:29:42.387000
1 posts
🔴 CVE-2026-44887 - Critical (9.8)
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be injected into pialert.conf. Since the background scan daemon loads this file ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44887/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T15:29:42.387000
1 posts
🔴 CVE-2026-45083 - Critical (9.8)
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted an arbitrary Solr streaming expression from unau...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45083/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T15:06:44.207000
1 posts
🟠 CVE-2026-45578 - High (8.8)
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45578/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T15:06:44.207000
1 posts
🟠 CVE-2026-44850 - High (8.5)
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer offers an ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44850/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T14:46:09.837000
1 posts
ASUS System Control Interface (≤3.1.59.0) hit by HIGH-severity vuln (CVE-2026-7480): local attackers can escalate to SYSTEM via crafted RPC calls. No patch yet — restrict local access & monitor advisories. https://radar.offseq.com/threat/cve-2026-7480-cwe-732-incorrect-permission-assignm-d09dc8d7 #OffSeq #Vuln #ASUS #Infosec
##updated 2026-05-29T14:16:31.807000
1 posts
🟠 CVE-2026-46510 - High (8.2)
form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, or prototype. A single HTTP form field whose nam...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T14:16:26.403000
1 posts
🟠 CVE-2026-35675 - High (8.2)
phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35675/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T14:09:03.913000
1 posts
🔴 CVE-2026-38703 - Critical (9.8)
A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerabil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38703/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T14:08:41.327000
1 posts
Anyone know anything about these router vulns? I'm especially interested in CVE-2026-38704, a command injection in the Wireguard function, and CVE-2026-38707, a command injection in the IPSEC function.
https://www.inhand.com/wp-content/uploads/InHand-PSA-2026-05_EN.pdf
##updated 2026-05-29T14:07:47.980000
1 posts
🟠 CVE-2026-49127 - High (8.6)
Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49127/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T13:09:05.450000
1 posts
CVE-2026-3655 (CRITICAL, CVSS 9.8): glboy OTP Login plugin (v1.8.50 – 1.8.60) suffers from improper authentication via Firebase OTP. Attackers can log in as any user/admin. Patch now! https://radar.offseq.com/threat/cve-2026-3655-cwe-287-improper-authentication-in-g-98c0dba0 #OffSeq #WordPress #Infosec #Vulnerability
##updated 2026-05-29T07:20:15
1 posts
1 repos
🚨 CVE-2026-8732: WP Maps Pro ≤6.1.0 has a CRITICAL flaw (CVSS 9.8). Unauthenticated attackers can create admin accounts via an AJAX action protected only by a public nonce. Full site takeover risk. Disable or remove plugin until patched. https://radar.offseq.com/threat/cve-2026-8732-cwe-306-missing-authentication-for-c-c3324188 #OffSeq #WordPress #Vuln
##updated 2026-05-29T03:31:14
1 posts
🔒 CVE-2026-8070 (HIGH): ASUS Armoury Crate lets local attackers bypass driver validation for physical memory access. Patch pending — restrict local access and monitor for abuse. Details: https://radar.offseq.com/threat/cve-2026-8070-cwe-732-incorrect-permission-assignm-933cba46 #OffSeq #Vulnerability #ASUS #InfoSec
##updated 2026-05-29T02:47:03.023000
1 posts
🔴 CVE-2026-46833 - Critical (9)
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Servic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46833/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T02:45:36.283000
1 posts
🟠 CVE-2026-47333 - High (7.8)
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unpri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T00:39:36
1 posts
🟠 CVE-2026-49128 - High (7.5)
Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 within the local storage plugin, where the on-disk path is constructed by joining the storage root wit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49128/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-29T00:38:45
1 posts
🔴 CVE-2026-8809 - Critical (9.8)
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditiona...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8809/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T22:16:58.693000
1 posts
🟠 CVE-2026-39929 - High (7.5)
Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39929/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T21:32:17
1 posts
🔴 CVE-2026-9645 - Critical (9.9)
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9645/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T21:32:10
1 posts
🟠 CVE-2026-47331 - High (7.8)
Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code exec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47331/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T21:32:10
1 posts
🟠 CVE-2026-4944 - High (8.8)
vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and `vllm/model_executor/models/kimi_k25.py`). This ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4944/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T20:16:23.810000
1 posts
🔴 CVE-2026-43898 - Critical (10)
SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That callback can then be invoked with attacker-control...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43898/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T19:19:37.803000
1 posts
🟠 CVE-2026-47759 - High (8.7)
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values tha...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47759/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T19:19:03.740000
1 posts
🟠 CVE-2026-47760 - High (8.7)
TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitizati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47760/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T19:16:39.280000
1 posts
🟠 CVE-2026-46509 - High (8.2)
deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not be exposed as user input. This vulnerability is f...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46509/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T18:56:36.823000
2 posts
🛡️ CVE-2026-46414 (HIGH): Auth bypass in Microsoft UFO 3.0.1-4-ge2626659. Attackers can spoof roles & hijack device tasks via WebSocket. No patch yet — restrict server token & trusted client access. More: https://radar.offseq.com/threat/cve-2026-46414-cwe-290-authentication-bypass-by-sp-c8a9e703 #OffSeq #CVE202646414 #MicrosoftUFO #Vuln
##🟠 CVE-2026-46414 - High (8.8)
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fields in task messages. A client connection can re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46414/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T18:56:36.823000
1 posts
🟠 CVE-2026-45322 - High (7.8)
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in the shell action replay path. In affected releas...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45322/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T18:40:37.990000
1 posts
🔴 CVE-2026-45311 - Critical (9.6)
CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user approval prompt. cargo test compiles and execut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45311/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T18:30:39
1 posts
🔴 CVE-2026-38702 - Critical (9.8)
A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerabil...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38702/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T18:30:39
1 posts
🟠 CVE-2026-9095 - High (8.1)
Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9095/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T18:30:39
1 posts
Anyone know anything about these router vulns? I'm especially interested in CVE-2026-38704, a command injection in the Wireguard function, and CVE-2026-38707, a command injection in the IPSEC function.
https://www.inhand.com/wp-content/uploads/InHand-PSA-2026-05_EN.pdf
##updated 2026-05-28T18:00:33.730000
1 posts
🟠 CVE-2026-49238 - High (8.4)
An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path fu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49238/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T16:25:38.687000
1 posts
🔴 CVE-2026-44326 - Critical (9.4)
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, rea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44326/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T16:16:28.793000
1 posts
🟠 CVE-2026-48151 - High (7.5)
Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for all paths matching /api/webhooks/schema. As a r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48151/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T14:19:43
1 posts
🟠 CVE-2026-35671 - High (8.8)
phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with lo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35671/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T14:16:21.263000
1 posts
🟠 CVE-2026-44711 - High (7.9)
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption. This vulnerability is fixed in 0.8.7.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44711/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T14:16:20.450000
1 posts
🟠 CVE-2026-44635 - High (7.5)
Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlled input flows into eb.ref(col, '->$').key(input)...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T13:57:25.390000
1 posts
🟠 CVE-2026-44709 - High (7.8)
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment variable and executes it directly without any validation. Any process that can set envir...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44709/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T13:45:25.260000
1 posts
🟠 CVE-2026-9227 - High (8.8)
The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only veri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9227/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T13:45:25.260000
2 posts
⚠️ CVE-2026-9009 (HIGH): Crawlomatic Multipage Scraper Post Generator for WordPress lets author+ users trigger arbitrary PHP code via unsafe shortcodes. No patch yet — restrict author access & consider disabling plugin. Details: https://radar.offseq.com/threat/cve-2026-9009-cwe-434-unrestricted-upload-of-file--9027f144 #OffSeq #WordPress #Vuln
##🟠 CVE-2026-9009 - High (8.8)
The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due to passing the attacker-supplied 'callback_raw' s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9009/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T13:44:54.327000
2 posts
🟠 CVE-2026-8915 - High (8.8)
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8915/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔔 CVE-2026-8915 (HIGH): Out-of-bounds write in Samsung Open Source Escargot (commit 36f5fb58...) enables buffer overflow risks — system compromise possible. No patch yet; monitor advisories & restrict access. https://radar.offseq.com/threat/cve-2026-8915-cwe-787-out-of-bounds-write-in-samsu-8e102c1a #OffSeq #Vulnerability #Escargot
##updated 2026-05-28T12:33:02
1 posts
🟠 CVE-2026-7862 - High (8.6)
The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7862/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T09:31:27
2 posts
🔴 CVE-2026-4408 - Critical (9)
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the cli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4408/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🚨 CRITICAL: CVE-2026-4408 in Red Hat Enterprise Linux 10 via Samba misconfig enables remote command execution if "check password script" uses %u. Audit your configs now! Details: https://radar.offseq.com/threat/cve-2026-4408-improper-neutralization-of-special-e-ffcecb34 #OffSeq #Linux #Samba #Infosec
##updated 2026-05-28T09:31:26
1 posts
🟠 CVE-2026-6455 - High (8.1)
The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce ver...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-6455/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T06:31:16
1 posts
🟠 CVE-2026-7802 - High (8.8)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7802/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-28T03:31:21
1 posts
🛡️ CVE-2026-9789 (HIGH, CVSS 8.5): Acer NitroSense V3 (≤3.01.3001) local users can delete arbitrary files via PSAdminAgent's weak pipe ACL. No patch yet — restrict access, monitor activity. More: https://radar.offseq.com/threat/cve-2026-9789-cwe-22-improper-limitation-of-a-path-0de6487d #OffSeq #Vuln #Acer #PrivilegeEscalation
##updated 2026-05-28T00:30:35
1 posts
🟠 CVE-2026-9208 - High (8.8)
Tanium addressed an unauthorized code execution vulnerability in Connect.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9208/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T21:32:32
1 posts
🟠 CVE-2026-45332 - High (7.5)
Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45332/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T21:31:33
1 posts
🟠 CVE-2026-8359 - High (7.5)
When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule function in the dll would be called to set up a "module" object for that mo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8359/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T21:31:32
1 posts
🔴 CVE-2026-8362 - Critical (9.8)
A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8362/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T21:31:32
1 posts
🟠 CVE-2026-8361 - High (7.5)
A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8361/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T21:31:32
1 posts
🟠 CVE-2026-8360 - High (7.5)
Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8360/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T20:34:24.850000
3 posts
CVE-2026-48027 - Changed to Known Ransomware Status
Nx Console Embedded Malicious Code VulnerabilityVendor: NxProduct: Nx ConsoleNx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.Status changed from Unknown to Known for ransomware https://nvd.nist.gov/vuln/detail/CVE-2026-48027
##🚨 [CISA-2026:0527] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0527)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-45321 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45321)
- Name: TanStack Unspecified Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TanStack
- Product: TanStack
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx ; https://nvd.nist.gov/vuln/detail/CVE-2026-45321
⚠️ CVE-2026-48027 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48027)
- Name: Nx Console Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Nx
- Product: Nx Console
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027
⚠️ CVE-2026-8398 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8398)
- Name: Daemon Tools Lite Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Daemon
- Product: Daemon Tools Lite
- Notes: https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398
#SecDB #InfoSec #CVE #CISA_KEV #cisa_20260527 #cisa20260527 #cve_2026_45321 #cve_2026_48027 #cve_2026_8398 #cve202645321 #cve202648027 #cve20268398
##CVE ID: CVE-2026-48027
Vendor: Nx
Product: Nx Console
Date Added: 2026-05-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48027
updated 2026-05-27T20:16:39.200000
1 posts
🟠 CVE-2026-45716 - High (8.8)
Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user with builder permissions to access it. When SMTP email is not configur...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45716/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T20:16:38.550000
1 posts
🟠 CVE-2026-45108 - High (8.4)
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, Himmelblau contained an authentication bypass vulnerability in the Device Authorization Grant (DAG) flow that allowed a user wi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45108/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T19:44:35.987000
1 posts
🟠 CVE-2026-48153 - High (8.5)
Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-supplied URL with plain node-fetch, skipping the blacklist.isBlacklisted check that every other outbound fetch path in the codeba...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48153/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T18:32:54.337000
1 posts
2 repos
https://github.com/HORKimhab/CVE-2026-45659
https://github.com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE
⚪️ Microsoft Fixes RCE Vulnerability in SharePoint
🗨️ Microsoft engineers have released out-of-band patches for an RCE vulnerability in SharePoint Server (CVE-2026-45659). The issue has a CVSS score of 8.8 and affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Exploiting it only requires…
##updated 2026-05-27T18:32:34
1 posts
RE: https://infosec.exchange/@perfect10_bot/116647910574183905
So CVE-2015-2808 (RC4 weaknesses in TLS) got bumped to 10.0 today due to CISA enrichment...
##updated 2026-05-27T14:54:20.160000
1 posts
🟠 CVE-2025-14713 - High (7.5)
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-14713/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T06:01:20
2 posts
🟠 CVE-2026-46372 - High (8.5)
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searxng, which ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46372/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-46372 - High (8.5)
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searxng, which ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46372/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T19:16:29.123000
2 posts
1 repos
KnowledgeDeliver Zero-Day Flaw Exploited to Deploy Web Shells
KnowledgeDeliver LMS installations are being targeted by a zero-day deserialization vulnerability (CVE-2026-5426) caused by hardcoded machine keys, allowing attackers to deploy web shells and Cobalt Strike backdoors.
**If you run Digital Knowledge's KnowledgeDeliver LMS, immediately replace the default ASP.NET machine keys in your web.config with unique, cryptographically strong ones to block these attacks. If possible, restrict portal access to trusted IP ranges, and monitor Windows Application logs for Event ID 1316 (ViewState verification failures).**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/knowledgedeliver-zero-day-flaw-exploited-to-deploy-web-shells-5-x-f-c-n/gD2P6Ple2L
updated 2026-05-26T18:32:39
1 posts
33 repos
https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284
https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284
https://github.com/ryan2929/CVE-2026-43284-
https://github.com/LucasPDiniz/CVE-2026-43284
https://github.com/dixyes/dirtypatch
https://github.com/XRSecCD/202605_dirty_frag
https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC
https://github.com/krisiasty/vcheck
https://github.com/metalx1993/dirtyfrag-patches
https://github.com/haydenjames/dirty-frag-check
https://github.com/FrosterDL/CVE-2026-43284
https://github.com/attaattaatta/CVE-2026-43500
https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284
https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan
https://github.com/0xBlackash/CVE-2026-43284
https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC
https://github.com/ChernStepanov/DirtyFrag-for-dummies
https://github.com/liamromanis101/DirtyFrag-Detector
https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284
https://github.com/AK777177/Dirty-Frag-Analysis
https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4
https://github.com/suominen/CVE-2026-43284
https://github.com/Aiyakami/rust_dirtyfrag
https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag
https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester
https://github.com/Koshmare-Blossom/DirtyFrag-go
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/whosfault/CVE-2026-43284
https://github.com/linnemanlabs/dirtyfrag-arm64
https://github.com/0xlane/pagecache-guard
https://github.com/xd20111/CVE-2026-43284
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
updated 2026-05-23T00:16:58
2 posts
🟠 CVE-2026-47125 - High (8.8)
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file used for variable substitution in eve...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47125/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47125 - High (8.8)
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file used for variable substitution in eve...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47125/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-20T19:06:36.850000
1 posts
2 repos
⚪️ Microsoft patches UnDefend and RedSun 0‑day vulnerabilities
🗨️ Microsoft developers have released out-of-band updates to fix two 0‑day vulnerabilities in Microsoft Defender that are already being used in real-world attacks. These are the bugs CVE-2026-41091 and CVE-2026-45498, known as RedSun and UnDefend. The first issue (7.8 on the…
##updated 2026-05-20T18:31:35
1 posts
1 repos
⚪️ Microsoft patches UnDefend and RedSun 0‑day vulnerabilities
🗨️ Microsoft developers have released out-of-band updates to fix two 0‑day vulnerabilities in Microsoft Defender that are already being used in real-world attacks. These are the bugs CVE-2026-41091 and CVE-2026-45498, known as RedSun and UnDefend. The first issue (7.8 on the…
##updated 2026-05-19T16:08:42
1 posts
🟠 CVE-2026-45137 - High (8.2)
Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, an logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumpti...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45137/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-18T18:32:28
5 posts
100 repos
https://github.com/qi4L/CVE-2026-31431-Container-Escape
https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
https://github.com/bigwario/copy-fail-CVE-2026-31431-C
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/sudoytang/copyfail-arm64
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
https://github.com/AdityaBhatt3010/CVE-2026-31431
https://github.com/bootsareme/copyfail-deconstructed
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/wvverez/CVE-2026-31431-Copy-Fail
https://github.com/xn0kkx/CVE-2026-31431_CopyFail_LinuxKernel_LPE
https://github.com/RoflSecurity/copy_fail
https://github.com/ZephrFish/CopyFail-CVE-2026-31431
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/Boos4721/copyfail-rs
https://github.com/wesmar/CVE-2026-31431
https://github.com/professional-slacker/alg_check
https://github.com/suominen/CVE-2026-31431
https://github.com/sgkdev/ptrace_may_dream
https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite
https://github.com/povzayd/CVE-2026-31431
https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431
https://github.com/philfry/cve-2026-31431-ftrace
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/lonelyor/CVE-2026-31431-exp
https://github.com/MrAriaNet/cPanel-Fix
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC
https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail
https://github.com/rootsecdev/cve_2026_31431
https://github.com/0xBlackash/CVE-2026-31431
https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/guiimoraes/CVE-2026-31431
https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431
https://github.com/adysec/cve-2026-31431
https://github.com/abdullaabdullazade/CVE-2026-31431
https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit
https://github.com/sgkdev/page_inject
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://github.com/MartinPham/copy-fail-CVE-2026-31431-php
https://github.com/JuanBindez/CVE-2026-31431
https://github.com/insomnisec/Detections-CVE-2026-31431
https://github.com/ExploitEoom/CVE-2026-31431
https://github.com/xeloxa/copyfail-exploit
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC
https://github.com/tgies/copy-fail-c
https://github.com/0xShe/CVE-2026-31431
https://github.com/novysodope/copy-fail-CVE-2026-31431-C
https://github.com/luotian2/CVE-2026-31431
https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit
https://github.com/wgnet/wg.copyfail.patch
https://github.com/Dabbleam/CVE-2026-31431-mitigation
https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection
https://github.com/gbonacini/CVE-2026-31431
https://github.com/Huchangzhi/autorootlinux
https://github.com/aestechno/cve-2026-31431-ansible
https://github.com/darioomatos/cve-2026-31431-copyfail
https://github.com/yxdm02/CVE-2026-31431
https://github.com/Koshmare-Blossom/Copyfail-sh
https://github.com/rvizx/CVE-2026-31431
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/cozystack/copy-fail-blocker
https://github.com/Aurillium/RootRemover
https://github.com/badsectorlabs/copyfail-go
https://github.com/ErdemOzgen/copy-fail-cve-2026-31431
https://github.com/Alfredooe/CVE-2026-31431
https://github.com/cyber-joker/copy-fail-python
https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/samanzamani/copy-fail-checker
https://github.com/SeanRickerd/cve-2026-31431
https://github.com/Smarttfoxx/copyfail
https://github.com/XsanFlip/CVE-2026-31431-Patch
https://github.com/desultory/CVE-2026-31431
https://github.com/wuwu001/CVE-2026-31431-exploit
https://github.com/b5null/CVE-2026-31431-C
https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431
https://github.com/kadir/copy-fail-CVE-2026-31431-IOC
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/diemoeve/copyfail-rs
https://github.com/ncmprbll/copy-fail-rs
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/krisiasty/vcheck
https://github.com/atgreen/block-copyfail
https://github.com/Xerxes-2/CVE-2026-31431-rs
https://github.com/toxy4ny/copy-fail-exploit-on-c-redteam
https://github.com/malwarekid/CVE-2026-31431
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/yuspring/cve-2026-31431-poc
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/4xura/CVE-2026-31431-Copy-Fail
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/jbnetwork-git/copy-fail-check
https://github.com/H1d3r/copy-fail_LPE_Interactive
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/mrunalp/block-copyfail
Mitigating CVE-2026-31431 ("Copy Fail") in Docker Engine #devopsish https://www.docker.com/blog/mitigating-cve-2026-31431-copy-fail-in-docker-engine/
##CVE-2026-31431 “Copy Fail” Exposes Linux Kernel to Active Exploitation as CISA Flags Real-World Attacks and BlackSuit-Linked Intrusions Expand
Critical Linux Kernel Flaw Turns Into a Real-World Exploitation Tool Across Enterprise Environments CVE-2026-31431, internally tracked and now widely referred to as “Copy Fail,” has rapidly escalated from a technical kernel bug into a confirmed, actively exploited security crisis affecting Linux-based infrastructure worldwide.…
##Mitigating CVE-2026-31431 ("Copy Fail") in Docker Engine #devopsish https://www.docker.com/blog/mitigating-cve-2026-31431-copy-fail-in-docker-engine/
###Docker Releases Mitigation for Copy Fail (CVE-2026-31431)
##updated 2026-05-18T17:41:42
1 posts
🟠 CVE-2026-45707 - High (8.1)
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that the target n8n instance is selected per-request fr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45707/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-18T17:23:40
2 posts
🔴 CVE-2026-45697 - Critical (9.8)
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45697/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45697 - Critical (9.8)
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could l...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45697/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-17T16:16:16.740000
1 posts
15 repos
https://github.com/haydenjames/dirty-frag-check
https://github.com/Koshmare-Blossom/DirtyFrag-go
https://github.com/attaattaatta/CVE-2026-43500
https://github.com/vorkampfer/dirty_frag_mitigation
https://github.com/linnemanlabs/dirtyfrag-arm64
https://github.com/liamromanis101/DirtyFrag-Detector
https://github.com/0xlane/pagecache-guard
https://github.com/AK777177/Dirty-Frag-Analysis
https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4
https://github.com/XRSecCD/202605_dirty_frag
https://github.com/krisiasty/vcheck
https://github.com/metalx1993/dirtyfrag-patches
https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag
updated 2026-05-15T09:31:43
2 posts
🚨 [CISA-2026:0527] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0527)
CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-45321 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45321)
- Name: TanStack Unspecified Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TanStack
- Product: TanStack
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx ; https://nvd.nist.gov/vuln/detail/CVE-2026-45321
⚠️ CVE-2026-48027 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48027)
- Name: Nx Console Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Nx
- Product: Nx Console
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027
⚠️ CVE-2026-8398 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8398)
- Name: Daemon Tools Lite Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Daemon
- Product: Daemon Tools Lite
- Notes: https://blog.daemon-tools.cc/post/security-incident ; https://nvd.nist.gov/vuln/detail/CVE-2026-8398
#SecDB #InfoSec #CVE #CISA_KEV #cisa_20260527 #cisa20260527 #cve_2026_45321 #cve_2026_48027 #cve_2026_8398 #cve202645321 #cve202648027 #cve20268398
##CVE ID: CVE-2026-8398
Vendor: Daemon
Product: Daemon Tools Lite
Date Added: 2026-05-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8398
updated 2026-05-14T20:29:53
1 posts
🔴 CVE-2026-45374 - Critical (9.6)
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:1499: self.allow_shell.unwrap_or(true)) and auto_a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45374/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-14T20:23:52
1 posts
🟠 CVE-2026-45348 - High (8.7)
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/templates/js/packages.js:172 interpolates a stored link URL into a template literal inside...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45348/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-14T18:33:03
1 posts
3 repos
https://github.com/portbuster1337/CVE-2026-20182
Cisco, posted yesterday:
CRITICAL: CVE-2026-20182: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW @TalosSecurity #Cisco #vulnerability #infosec
##updated 2026-05-14T17:52:50.143000
2 posts
3 repos
https://github.com/ercihan/CVE-2026-40369
CVE-2026-40369 seems fun...
##CVE-2026-40369 seems fun...
##updated 2026-05-14T16:24:31
1 posts
🟠 CVE-2026-44882 - High (8.1)
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33., Portainer proxies requests to Kubernetes ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44882/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-13T15:33:13
1 posts
🟠 CVE-2026-45152 - High (7.8)
uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution of the check field from metadata files using /bin/bash -c. Because the check field is lo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45152/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-13T14:02:20.380000
1 posts
We had lengthy discussions explaining the bug to Apple. It was clear to us the bug was new to Apple Product Security. After 5 months, they informed us that the report was treated as a duplicate and it was addressed.
We just got this update for CVE-2026-28910: No bounty
You can read the full blog post (aka charity work for a 4-trillion-dollar company) highlighting this bug here:
##updated 2026-05-12T22:23:47
2 posts
🔴 CVE-2026-44650 - Critical (9.1)
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint accepts ex...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-44650 - Critical (9.1)
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint accepts ex...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-12T22:23:33
2 posts
🔴 CVE-2026-44649 - Critical (9.8)
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44649/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-44649 - Critical (9.8)
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44649/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-12T15:08:14
1 posts
🟠 CVE-2026-45088 - High (7.5)
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-file field in model.Options is JSON-tagged and deserialized directly from the attacker'...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45088/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-12T13:31:01
1 posts
5 repos
https://github.com/vognik/CVE-2026-26980
https://github.com/Kulik-Labs-Development/Ghost-CMS-Code-Injection-Audit-CVE-2026-26980
https://github.com/EQSTLab/CVE-2026-26980
Plus de 700 sites piratés : la faille critique de Ghost CMS qui sème la terreur sur le web https://goodtech.info/ghost-cms-faille-critique-cve-2026-26980-clickfix-piratage/ #Développement #Applications #Sécurité #Àlaune
##updated 2026-05-11T16:17:49
1 posts
🟠 CVE-2026-45047 - High (7.5)
bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read si...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45047/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-11T16:09:41
1 posts
🟠 CVE-2026-44483 - High (8.2)
RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @Rvf/set-get (used by @Rvf/core to flatten incoming form data into a nested object) does not block t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44483/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-08T22:59:24
1 posts
🔴 CVE-2026-44327 - Critical (10)
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44327/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-04-23T20:15:29.690000
2 posts
11 repos
https://github.com/fevar54/marimo_CVE-2026-39987_RCE_PoC
https://github.com/HORKimhab/CVE-2026-39987
https://github.com/0xdeadroot/CVE-2026-39987-marimo-rce
https://github.com/M3PH1569/CVE-2026-39987-POC
https://github.com/h3raklez/CVE-2026-39987
https://github.com/mki9/CVE-2026-39987_exploit
https://github.com/rootdirective-sec/CVE-2026-39987-Lab
https://github.com/keraattin/CVE-2026-39987
https://github.com/Nxploited/CVE-2026-39987
https://github.com/0xBlackash/CVE-2026-39987
https://github.com/Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab
LLM Agent Enables Rapid Post-Exploitation in Marimo Networks
On May 10, 2026, a savvy attacker used a large language model agent to rapidly exploit a vulnerable Marimo instance, leveraging CVE-2026-39987 to spark a swift and damaging breach. This critical vulnerability allowed the attacker to execute arbitrary system commands, paving the way for cloud credential…
#MarimoNetworkExploitation #LargeLanguageModelAgent #Cve202639987 #Postexploitation #RemoteCodeExecution
##updated 2026-04-15T00:35:42.020000
2 posts
other databases.
- **Rust ecosystem updates**: Rust 1.96 release, async runtime discussions, idiomatic error handling, GitHub migration, and no-AI policy adoption.
- **Open-source security incidents**: GitHub "Megalodon" attack (5,500+ repos compromised), malicious npm packages (e.g., Laravel Lang, AntV), and supply chain risks.
- **PostgreSQL updates**: PGConf.EU 2026 Call for Papers, security patches (CVE-2026-3172), pgvector fixes, and pgBackRest funding.
- **Vibe coding [2/3]
Blip blop, I'm a #mastobot.
Here is a summary (in beta) of the latest posts in #programmingAtKukei https://masto.kukei.eu/browse/programming category:
- **PGConf.EU 2026 Call for Papers** deadline: June 1, Valencia (October 20–23).
- **AI coding tools controversies**: GitHub Copilot, Claude Code, Cursor, AI-generated code quality/security risks (e.g., symlink RCE, hidden "delete all code" prompts).
- **PostgreSQL updates**: PGConf.EU 2026, security patches (CVE-2026-3172), pgvector fixes, [1/2]
updated 2026-04-15T00:35:42.020000
1 posts
CVE-2024-8310 - Critical auth bypass in OPW Fuel Management SiteSentinel. Full admin access. CVSS 9.8. No patch available. Isolate systems immediately. #CVE #infosec #OTsecurity
##updated 2026-04-15T00:35:42.020000
1 posts
CVE-2024-55884 - Critical OOB access in Mullvad VPN. Heap-based write via exception stack exhaustion. CVSS 9.0. Code execution possible. No patch available yet. Monitor for updates. #CVE #Mullvad #infosec
##updated 2026-04-06T18:12:57.863000
2 posts
8 repos
https://github.com/fevar54/CVE-2026-35616-detector.py
https://github.com/fevar54/forticlient_ems_cve_2026_35616_poc.py
https://github.com/wa6n3r/CVE-2026-35616
https://github.com/keraattin/CVE-2026-35616
https://github.com/HORKimhab/CVE-2026-35616
https://github.com/BishopFox/CVE-2026-35616-check
🔵 THREAT INTELLIGENCE
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
Vulnerability | CRITICAL
CVEs: CVE-2026-35616
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an...
Full analysis:
https://www.yazoul.net/news/article/threat-actors-exploit-critical-forticlient-ems-flaw-to-deploy-credential-stealer
The activity, observed by the cybersecurity company in May 2026, involves the exploitation of CVE-2026-35616 (CVSS score: 9.1), a critical pre-authentication API access bypass leading to privilege escalation. https://thehackernews.com/2026/05/threat-actors-exploit-critical.html
##updated 2026-04-01T18:32:06
1 posts
CVE-2024-49611 - Critical arbitrary file upload in Paxman Product Website Showcase. CVSS 10. Allows web shell upload. No patch available. Disable plugin immediately. #CVE #infosec #WordPress
##updated 2026-03-23T03:31:45
1 posts
2 repos
https://github.com/HORKimhab/CVE-2026-45659
https://github.com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE
⚪️ Microsoft Fixes RCE Vulnerability in SharePoint
🗨️ Microsoft engineers have released out-of-band patches for an RCE vulnerability in SharePoint Server (CVE-2026-45659). The issue has a CVSS score of 8.8 and affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Exploiting it only requires…
##updated 2025-11-18T15:30:54
1 posts
So here's one of the cool things you can do with Gentoo. You're not forced to stick to the latest version of a package, multiple stable versions might be available simultaneously. So in this case you can mask rsync-3.4.3 to avoid the slop-induced bugs and the package manager will automatically fall back to rsync-3.4.1-r2. See that '-r2' suffix? That's important, it means that it's the base 3.4.1 version plus a set of patches added by the Gentoo maintainers. In this particular case those patches address CVE-2025-10158, so you get the important security fix but avoid the slop issues introduced in the next stable release. Naturally, while the technical brilliance of this system is remarkable, what really shines it the will of Gentoo maintainers to go above and beyond to solve users' issues. Thanks (and donations) should go to them.
https://mastodon.gamedev.place/@JeremiahFieldhaven/116654345332213390
##updated 2025-10-29T14:34:16.610000
2 posts
RE: https://c.im/@cdarwin/116660769695837565
One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.
Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.
On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.
For the record, I think @GossiTheDog called it that this person was a former MS employee.
##RE: https://c.im/@cdarwin/116660769695837565
One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.
Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.
On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.
For the record, I think @GossiTheDog called it that this person was a former MS employee.
##updated 2025-04-20T03:32:27
1 posts
my approach to finding security bugs:
me in 2017: "hmm the directory is world-writable, and the sticky bit looks ugly in my colorized ls, I'll send a patch"
someone on IRC a week later: "hey you're named in CVE-2016-10156"
me in 2023: "ugh OpenSSH crashes when I'm connecting from my retro Win98 VM"
someone on IRC a week later: "hey did you know you're in CVE-2023-25136"
updated 2025-01-14T03:31:48
1 posts
CVE-2025-0066 — Critical supply chain attack in SAP NetWeaver AS for ABAP. Weak access controls allow info disclosure, impacting confidentiality, integrity, and availability. CVSS 9.9. Unpatched. Act now to mitigate risk. #CVE #SAP #infosec
##updated 2024-11-21T06:37:11.567000
1 posts
1 repos
@GossiTheDog Yes, since 2017ish, for example
##updated 2024-11-21T03:15:44.050000
1 posts
@GossiTheDog Yes, since 2017ish, for example
##updated 2024-09-17T18:40:07.243000
1 posts
CVE-2024-45694 - Critical unpatched stack buffer overflow in D-Link routers. CVSS 9.8. Unauthenticated RCE possible. No patch available. Isolate affected devices immediately. #CVE #DLink #infosec
##updated 2024-09-13T19:39:40.570000
1 posts
CVE-2024-7261 - Critical OS Command Injection in Zyxel devices. Unauthenticated RCE via crafted cookie. CVSS 9.8. No patch available yet. Isolate affected devices immediately. #CVE #Zyxel #cybersecurity
##updated 2024-08-12T18:23:57.077000
2 posts
CVE-2024-42395 - Critical RCE in AP Certificate Management Service. Unauthenticated RCE, CVSS 9.8. Exploitation leads to full system compromise. Patch status unknown, monitor for updates urgently. #CVE #infosec #cybersecurity
##CVE-2024-42395 - Critical RCE in AP Certificate Management Service. Unauthenticated RCE, CVSS 9.8. Exploitation leads to full system compromise. Patch status unknown, monitor for updates urgently. #CVE #infosec #cybersecurity
##updated 2024-03-07T05:10:04
1 posts
11 repos
https://github.com/ticofookfook/CVE-2023-25136
https://github.com/malvika-thakur/CVE-2023-25136
https://github.com/Business1sg00d/CVE-2023-25136
https://github.com/nhakobyan685/CVE-2023-25136
https://github.com/Lane0218/CVE-2023-25136-PoC
https://github.com/mrmtwoj/CVE-2023-25136
https://github.com/jfrog/jfrog-CVE-2023-25136-OpenSSH_Double-Free
https://github.com/axylisdead/CVE-2023-25136_POC
https://github.com/adhikara13/CVE-2023-25136
my approach to finding security bugs:
me in 2017: "hmm the directory is world-writable, and the sticky bit looks ugly in my colorized ls, I'll send a patch"
someone on IRC a week later: "hey you're named in CVE-2016-10156"
me in 2023: "ugh OpenSSH crashes when I'm connecting from my retro Win98 VM"
someone on IRC a week later: "hey did you know you're in CVE-2023-25136"
updated 2024-01-07T05:05:26
2 posts
2 repos
RE: https://c.im/@cdarwin/116660769695837565
One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.
Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.
On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.
For the record, I think @GossiTheDog called it that this person was a former MS employee.
##RE: https://c.im/@cdarwin/116660769695837565
One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.
Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.
On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.
For the record, I think @GossiTheDog called it that this person was a former MS employee.
##Security Advisory: CVE-2025-60486 - Use-After-Free in GPAC/MP4Box
Processing a crafted MPEG-2 Transport Stream file with corrupted PMT descriptors triggers a heap use-after-free in `dasher_process`, causing MP4Box to crash and potentially enabling arbitrary code execution.
Summary:
The `dasher_configure_pid` function in `filters/dasher.c` frees a PID context structure at line 976 when reconfiguring a stream. The freed pointer is not cleared, and `dasher_process` subsequently accesses the same memory at line 9445 during the next processing cycle. A crafted MPEG-2 TS file with repeated sync marker violations, broken PMT descriptors, and conflicting PIDs triggers this reconfiguration sequence, leading to a READ of 4 bytes into freed heap memory.
CWE:
CWE-416 - Use After Free
Affected Component:
```
filters/dasher.c:9445
Function: dasher_process()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1665-g3f20eb0cd-master; commit `3f20eb0cd22116367c036e6ffe6ace299b38d686`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a crafted MPEG-2 TS file containing missing sync markers, corrupted PMT descriptor sizes, and conflicting PID assignments. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers PID reconfiguration in the dasher module.
Impact:
The use-after-free (READ of size 4 at 316 bytes into a freed 1096-byte heap region) causes process termination, resulting in Denial of Service. Code execution cannot be ruled out; use-after-free vulnerabilities can allow an attacker to control freed memory contents and redirect execution flow.
Fix / mitigation status:
The fix ensures the stale PID context pointer in `dasher_configure_pid` is cleared after the region is freed so that `dasher_process` cannot access it. Users should upgrade to the release containing commit `e6d01820d7bf3967d931fedb379ee5f209bc133b` or apply that patch directly.
References
- Issue: https://github.com/gpac/gpac/issues/3314
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/53/53_dasher_process_filters_dasher_c_9445
- Fix: https://github.com/gpac/gpac/commit/e6d01820d7bf3967d931fedb379ee5f209bc133b
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##Security Advisory: CVE-2025-60486 - Use-After-Free in GPAC/MP4Box
Processing a crafted MPEG-2 Transport Stream file with corrupted PMT descriptors triggers a heap use-after-free in `dasher_process`, causing MP4Box to crash and potentially enabling arbitrary code execution.
Summary:
The `dasher_configure_pid` function in `filters/dasher.c` frees a PID context structure at line 976 when reconfiguring a stream. The freed pointer is not cleared, and `dasher_process` subsequently accesses the same memory at line 9445 during the next processing cycle. A crafted MPEG-2 TS file with repeated sync marker violations, broken PMT descriptors, and conflicting PIDs triggers this reconfiguration sequence, leading to a READ of 4 bytes into freed heap memory.
CWE:
CWE-416 - Use After Free
Affected Component:
```
filters/dasher.c:9445
Function: dasher_process()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1665-g3f20eb0cd-master; commit `3f20eb0cd22116367c036e6ffe6ace299b38d686`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a crafted MPEG-2 TS file containing missing sync markers, corrupted PMT descriptor sizes, and conflicting PID assignments. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers PID reconfiguration in the dasher module.
Impact:
The use-after-free (READ of size 4 at 316 bytes into a freed 1096-byte heap region) causes process termination, resulting in Denial of Service. Code execution cannot be ruled out; use-after-free vulnerabilities can allow an attacker to control freed memory contents and redirect execution flow.
Fix / mitigation status:
The fix ensures the stale PID context pointer in `dasher_configure_pid` is cleared after the region is freed so that `dasher_process` cannot access it. Users should upgrade to the release containing commit `e6d01820d7bf3967d931fedb379ee5f209bc133b` or apply that patch directly.
References
- Issue: https://github.com/gpac/gpac/issues/3314
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/53/53_dasher_process_filters_dasher_c_9445
- Fix: https://github.com/gpac/gpac/commit/e6d01820d7bf3967d931fedb379ee5f209bc133b
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##Security Advisory: CVE-2025-60485 - NULL Pointer Dereference in GPAC/MP4Box
Processing a crafted MP4 file with corrupted `esds` boxes and incomplete box structures triggers a NULL pointer dereference in `gf_isom_apple_set_tag_ex`, causing MP4Box to crash.
Summary:
The `gf_isom_apple_set_tag_ex` function in `isomedia/isom_write.c` is called during muxer tag setup to write Apple metadata tags into the output file. When the input MP4 contains an invalid `esds` descriptor (tag 3, truncated size) and an incomplete box structure, the function receives an unvalidated NULL pointer and dereferences it (READ at address 0x0) without a prior NULL check, terminating the process with SIGSEGV.
CWE:
CWE-476 - NULL Pointer Dereference
Affected Component:
```
isomedia/isom_write.c:6309
Function: gf_isom_apple_set_tag_ex()
filters/mux_isom.c:841
Function: mp4_mux_set_tags()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1687-ge44a4e2b0-master; commit `e44a4e2b0d193566619ada71599e70255699da94`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a crafted MP4 file containing a corrupted `esds` box (invalid descriptor sizes) and incomplete box structures. Local access is required; the victim must invoke `MP4Box -add <crafted_file>` or any equivalent MP4Box operation that triggers the muxer PID setup and tag-writing path.
Impact:
The NULL pointer dereference (READ at address 0x000000000000) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a NULL read that is not exploitable for control-flow hijacking.
Fix / mitigation status:
The fix adds a NULL check for the tag pointer before dereferencing it in `gf_isom_apple_set_tag_ex`. Users should upgrade to the release containing commit `4860a1a6f128ccc9ae37b4b738d22029f9672457` or apply that patch directly.
References
- Issue: https://github.com/gpac/gpac/issues/3323
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/52/52_gf_isom_apple_set_tag_ex_isomedia_isom_write_c_6309
- Fix: https://github.com/gpac/gpac/commit/4860a1a6f128ccc9ae37b4b738d22029f9672457
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##Security Advisory: CVE-2025-60485 - NULL Pointer Dereference in GPAC/MP4Box
Processing a crafted MP4 file with corrupted `esds` boxes and incomplete box structures triggers a NULL pointer dereference in `gf_isom_apple_set_tag_ex`, causing MP4Box to crash.
Summary:
The `gf_isom_apple_set_tag_ex` function in `isomedia/isom_write.c` is called during muxer tag setup to write Apple metadata tags into the output file. When the input MP4 contains an invalid `esds` descriptor (tag 3, truncated size) and an incomplete box structure, the function receives an unvalidated NULL pointer and dereferences it (READ at address 0x0) without a prior NULL check, terminating the process with SIGSEGV.
CWE:
CWE-476 - NULL Pointer Dereference
Affected Component:
```
isomedia/isom_write.c:6309
Function: gf_isom_apple_set_tag_ex()
filters/mux_isom.c:841
Function: mp4_mux_set_tags()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1687-ge44a4e2b0-master; commit `e44a4e2b0d193566619ada71599e70255699da94`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a crafted MP4 file containing a corrupted `esds` box (invalid descriptor sizes) and incomplete box structures. Local access is required; the victim must invoke `MP4Box -add <crafted_file>` or any equivalent MP4Box operation that triggers the muxer PID setup and tag-writing path.
Impact:
The NULL pointer dereference (READ at address 0x000000000000) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a NULL read that is not exploitable for control-flow hijacking.
Fix / mitigation status:
The fix adds a NULL check for the tag pointer before dereferencing it in `gf_isom_apple_set_tag_ex`. Users should upgrade to the release containing commit `4860a1a6f128ccc9ae37b4b738d22029f9672457` or apply that patch directly.
References
- Issue: https://github.com/gpac/gpac/issues/3323
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/52/52_gf_isom_apple_set_tag_ex_isomedia_isom_write_c_6309
- Fix: https://github.com/gpac/gpac/commit/4860a1a6f128ccc9ae37b4b738d22029f9672457
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##🔴 CVE-2026-45632 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belonging to othe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45632/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45632 - Critical (9.9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belonging to othe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45632/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45631 - Critical (10)
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger auto-sign...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45631/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45631 - Critical (10)
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger auto-sign...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45631/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45630 - Critical (9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45630/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45630 - Critical (9)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45630/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47740 - High (8.1)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47740/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47740 - High (8.1)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47740/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44421 - High (8.8)
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44421/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44421 - High (8.8)
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44421/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44285 - High (7.7)
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44285 - High (7.7)
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44285/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47123 - High (7.5)
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command has two code paths for identifying agent (user) replies based on In-Reply-To / Re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47123/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47123 - High (7.5)
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command has two code paths for identifying agent (user) replies based on In-Reply-To / Re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47123/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-47744 - Critical (9.9)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenti...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47744/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-47744 - Critical (9.9)
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenti...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47744/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Security Advisory: CVE-2025-55664 - Heap-based Buffer Overflow in GPAC/MP4Box
Processing a crafted MPEG-2 Transport Stream file with corrupted packet structures triggers a heap buffer overflow in `m2tsdmx_send_packet`, causing MP4Box to crash and potentially enabling arbitrary code execution.
Summary:
The `m2tsdmx_send_packet` function in `filters/dmx_m2ts.c` performs a `memcpy` whose size argument is derived from stream-controlled data without validation. A crafted MPEG-2 TS file with missing sync markers, corrupted PMT descriptors, and PID conflicts can cause the size to wrap to 4294967295 (0xFFFFFFFF), triggering a `memcpy` that reads and writes 4 GB of heap memory starting one byte past the end of a 183-byte allocated region.
CWE:
CWE-122 - Heap-based Buffer Overflow
Affected Component
```
filters/dmx_m2ts.c:916
Function: m2tsdmx_send_packet()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1644-g8e3b5e1dd-master; commit `8e3b5e1dde7b9ea041dbdc14456a5bb74a9851ea`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a specially crafted MPEG-2 TS file containing missing sync markers (0x47), corrupted PMT descriptor sizes, and conflicting PID assignments. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the MPEG-2 TS demuxer processing path.
Impact:
The heap buffer overflow (READ of size 4294967295, 1 byte past end of a 183-byte heap region) results in process termination, causing Denial of Service. Due to the write-capable nature of the oversized `memcpy`, arbitrary code execution cannot be ruled out.
Fix / mitigation status:
The fix adds size validation before the `memcpy` call in `m2tsdmx_send_packet` to reject stream-supplied sizes that exceed the allocated buffer. Users should upgrade to the release containing commit `9bd6a72c9efc0513dfd33b87498afc7658dabd26` or apply that patch directly.
References
- Issue: https://github.com/gpac/gpac/issues/3310
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/51/51_m2tsdmx_send_packet_filters_dmx_m2ts_c_916
- Fix: https://github.com/gpac/gpac/commit/9bd6a72c9efc0513dfd33b87498afc7658dabd26
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##Security Advisory: CVE-2025-55664 - Heap-based Buffer Overflow in GPAC/MP4Box
Processing a crafted MPEG-2 Transport Stream file with corrupted packet structures triggers a heap buffer overflow in `m2tsdmx_send_packet`, causing MP4Box to crash and potentially enabling arbitrary code execution.
Summary:
The `m2tsdmx_send_packet` function in `filters/dmx_m2ts.c` performs a `memcpy` whose size argument is derived from stream-controlled data without validation. A crafted MPEG-2 TS file with missing sync markers, corrupted PMT descriptors, and PID conflicts can cause the size to wrap to 4294967295 (0xFFFFFFFF), triggering a `memcpy` that reads and writes 4 GB of heap memory starting one byte past the end of a 183-byte allocated region.
CWE:
CWE-122 - Heap-based Buffer Overflow
Affected Component
```
filters/dmx_m2ts.c:916
Function: m2tsdmx_send_packet()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1644-g8e3b5e1dd-master; commit `8e3b5e1dde7b9ea041dbdc14456a5bb74a9851ea`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a specially crafted MPEG-2 TS file containing missing sync markers (0x47), corrupted PMT descriptor sizes, and conflicting PID assignments. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the MPEG-2 TS demuxer processing path.
Impact:
The heap buffer overflow (READ of size 4294967295, 1 byte past end of a 183-byte heap region) results in process termination, causing Denial of Service. Due to the write-capable nature of the oversized `memcpy`, arbitrary code execution cannot be ruled out.
Fix / mitigation status:
The fix adds size validation before the `memcpy` call in `m2tsdmx_send_packet` to reject stream-supplied sizes that exceed the allocated buffer. Users should upgrade to the release containing commit `9bd6a72c9efc0513dfd33b87498afc7658dabd26` or apply that patch directly.
References
- Issue: https://github.com/gpac/gpac/issues/3310
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/51/51_m2tsdmx_send_packet_filters_dmx_m2ts_c_916
- Fix: https://github.com/gpac/gpac/commit/9bd6a72c9efc0513dfd33b87498afc7658dabd26
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##4 posts
3 repos
https://github.com/xtremebeing/starlette-host-header-lab
https://github.com/eris-ths/supply-chain-guard
https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit
CVE-2026-48710: A Maintainer's Perspective https://lobste.rs/s/xvdvko #python #security
https://marcelotryle.com/blog/2026/05/28/cve-2026-48710-a-maintainers-perspective/
CVE-2026-48710: A Maintainer's Perspective https://lobste.rs/s/xvdvko #python #security
https://marcelotryle.com/blog/2026/05/28/cve-2026-48710-a-maintainers-perspective/
There's an update for the Starlette issue: We've scanned thousands of hosts for CVE-2026-48710 and found something important: Being behind a proxy or CloudFlare isn't always a protection unlike previously stated!
When a reverse proxy or CDN (including Cloudflare) sits in front of the target and rejects malformed Host headers, the X-Forwarded-Host header can sometimes be used to bypass the protection! If the backend middleware reads X-Forwarded-Host and updates the ASGI scope, the malicious value can reach the ASGI and Starlette. #badhost
⚪️ BadHost vulnerability in the Starlette framework poses a threat to AI agents
🗨️ Researchers are warning about a critical vulnerability, CVE-2026-48710, discovered in the open-source Starlette framework and dubbed BadHost. Since Starlette underpins FastAPI and many popular AI tools, the issue creates risks for millions of servers and AI agents, and exploiting the…
##Security Advisory: CVE-2025-60481 - Out-of-Bounds Read in GPAC/MP4Box
Processing a crafted AC-4 stream with an invalid `frame_rate_index` triggers an out-of-bounds read in `gf_odf_ac4_cfg_dsi_v1`, causing MP4Box to crash.
Summary:
The `gf_odf_ac4_cfg_dsi_v1` function in `odf/descriptors.c` uses a stream-supplied `frame_rate_index` to index into fixed-size lookup tables (`AC4_SAMPLE_DELTA_TABLE_48`, `AC4_MEDIA_TIMESCALE_48`). The function does not validate that the index is within bounds before performing the table lookup. A crafted AC-4 file carrying an out-of-range index (e.g., 15) causes an out-of-bounds read, ultimately resulting in a NULL dereference and process crash.
CWE:
CWE-125 - Out-of-bounds Read
Affected Component:
```
odf/descriptors.c:2179
Function: gf_odf_ac4_cfg_dsi_v1()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1617-g856674b22-master; commit `856674b226d6cbe28a941ad223be38194cbf7d37`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a specially crafted AC-4 stream file containing an invalid `frame_rate_index` value. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the AC-4 configuration descriptor parsing path.
Impact:
The out-of-bounds read leads to an immediate process crash (SEGV READ at address 0x000000000000), resulting in Denial of Service. No evidence of arbitrary code execution was observed.
Fix / mitigation status:
The fix adds bounds validation for `frame_rate_index` before the fixed-size table lookups in `gf_odf_ac4_cfg_dsi_v1`. Users should upgrade to the release containing commit `13eb5b76560aaf7813b865a2ad433258478e2695` or apply that patch directly.
References
- Issue: https://github.com/gpac/gpac/issues/3303
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/50/50_gf_odf_ac4_cfg_dsi_v1_odf_descriptors_c_2179
- Fix: https://github.com/gpac/gpac/commit/13eb5b76560aaf7813b865a2ad433258478e2695
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##Security Advisory: CVE-2025-60481 - Out-of-Bounds Read in GPAC/MP4Box
Processing a crafted AC-4 stream with an invalid `frame_rate_index` triggers an out-of-bounds read in `gf_odf_ac4_cfg_dsi_v1`, causing MP4Box to crash.
Summary:
The `gf_odf_ac4_cfg_dsi_v1` function in `odf/descriptors.c` uses a stream-supplied `frame_rate_index` to index into fixed-size lookup tables (`AC4_SAMPLE_DELTA_TABLE_48`, `AC4_MEDIA_TIMESCALE_48`). The function does not validate that the index is within bounds before performing the table lookup. A crafted AC-4 file carrying an out-of-range index (e.g., 15) causes an out-of-bounds read, ultimately resulting in a NULL dereference and process crash.
CWE:
CWE-125 - Out-of-bounds Read
Affected Component:
```
odf/descriptors.c:2179
Function: gf_odf_ac4_cfg_dsi_v1()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1617-g856674b22-master; commit `856674b226d6cbe28a941ad223be38194cbf7d37`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a specially crafted AC-4 stream file containing an invalid `frame_rate_index` value. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the AC-4 configuration descriptor parsing path.
Impact:
The out-of-bounds read leads to an immediate process crash (SEGV READ at address 0x000000000000), resulting in Denial of Service. No evidence of arbitrary code execution was observed.
Fix / mitigation status:
The fix adds bounds validation for `frame_rate_index` before the fixed-size table lookups in `gf_odf_ac4_cfg_dsi_v1`. Users should upgrade to the release containing commit `13eb5b76560aaf7813b865a2ad433258478e2695` or apply that patch directly.
References
- Issue: https://github.com/gpac/gpac/issues/3303
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/50/50_gf_odf_ac4_cfg_dsi_v1_odf_descriptors_c_2179
- Fix: https://github.com/gpac/gpac/commit/13eb5b76560aaf7813b865a2ad433258478e2695
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##Security Advisory: CVE-2025-60483 - NULL Pointer Dereference in GPAC/MP4Box
Processing a crafted AC-4 stream triggers a NULL pointer dereference in `gf_ac4_pres_b_4_back_channels_present` when accessing presentation data with an invalid substream group index, causing MP4Box to crash.
Summary:
The `gf_ac4_pres_b_4_back_channels_present` function in `media_tools/av_parsers.c` accesses `pres->substream_groups` using an index derived from the stream. When a crafted AC-4 file specifies an invalid group index (e.g., group 4 that does not exist for presentation 0), the parser dereferences a NULL or near-NULL pointer at address 0x48 (72-byte struct offset) without first validating the pointer or the group index bounds. The process terminates with SIGSEGV.
CWE:
CWE-476 - NULL Pointer Dereference
Affected Component
```
media_tools/av_parsers.c:15703
Function: gf_ac4_pres_b_4_back_channels_present()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1617-g856674b22-master; commit `856674b226d6cbe28a941ad223be38194cbf7d37`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a specially crafted AC-4 stream file containing an invalid substream group reference. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the AC-4 demuxer and presentation parsing path.
Impact:
The near-NULL pointer dereference (READ at address 0x000000000048) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a near-NULL read that is not exploitable for control-flow hijacking.
Fix / mitigation status:
The fix adds bounds validation for the substream group index and a NULL check for the presentation pointer in `gf_ac4_pres_b_4_back_channels_present`. Users should upgrade to the release containing commit `13eb5b76560aaf7813b865a2ad433258478e2695` or apply that patch directly.
References
- Issue: https://github.com/gpac/gpac/issues/3302
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/49/49_gf_ac4_pres_b_4_back_channels_present_media_tools_av_parsers_c_15703
- Fix: https://github.com/gpac/gpac/commit/13eb5b76560aaf7813b865a2ad433258478e2695
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##Security Advisory: CVE-2025-60483 - NULL Pointer Dereference in GPAC/MP4Box
Processing a crafted AC-4 stream triggers a NULL pointer dereference in `gf_ac4_pres_b_4_back_channels_present` when accessing presentation data with an invalid substream group index, causing MP4Box to crash.
Summary:
The `gf_ac4_pres_b_4_back_channels_present` function in `media_tools/av_parsers.c` accesses `pres->substream_groups` using an index derived from the stream. When a crafted AC-4 file specifies an invalid group index (e.g., group 4 that does not exist for presentation 0), the parser dereferences a NULL or near-NULL pointer at address 0x48 (72-byte struct offset) without first validating the pointer or the group index bounds. The process terminates with SIGSEGV.
CWE:
CWE-476 - NULL Pointer Dereference
Affected Component
```
media_tools/av_parsers.c:15703
Function: gf_ac4_pres_b_4_back_channels_present()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1617-g856674b22-master; commit `856674b226d6cbe28a941ad223be38194cbf7d37`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a specially crafted AC-4 stream file containing an invalid substream group reference. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the AC-4 demuxer and presentation parsing path.
Impact:
The near-NULL pointer dereference (READ at address 0x000000000048) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a near-NULL read that is not exploitable for control-flow hijacking.
Fix / mitigation status:
The fix adds bounds validation for the substream group index and a NULL check for the presentation pointer in `gf_ac4_pres_b_4_back_channels_present`. Users should upgrade to the release containing commit `13eb5b76560aaf7813b865a2ad433258478e2695` or apply that patch directly.
References
- Issue: https://github.com/gpac/gpac/issues/3302
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/49/49_gf_ac4_pres_b_4_back_channels_present_media_tools_av_parsers_c_15703
- Fix: https://github.com/gpac/gpac/commit/13eb5b76560aaf7813b865a2ad433258478e2695
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##Two RCE vulnerabilities in Notepad++ (CVE-2026-48778, CVE-2026-48800)
Notepad++ v8.9.5에서 XML 설정 파일(config.xml, shortcuts.xml)을 통해 Windows ShellExecute API를 검증 없이 호출하는 두 건의 원격 코드 실행(RCE) 취약점(CVE-2026-48778, CVE-2026-48800)이 발견되었다. 공격자는 동일 사용자 권한으로 설정 파일을 조작해 임의 명령어 실행이 가능하며, -settingsDir 옵션을 통한 은밀한 공격도 가능하다. 취약점은 v8.9.6.1에서 패치되었으며, Semgrep 기반 정적 분석과 수동 검증을 통해 확인되었다. 이 취약점은 Windo...
##Two RCE vulnerabilities in Notepad++ (CVE-2026-48778, CVE-2026-48800)
Notepad++ v8.9.5에서 XML 설정 파일(config.xml, shortcuts.xml)을 통해 Windows ShellExecute API를 검증 없이 호출하는 두 건의 원격 코드 실행(RCE) 취약점(CVE-2026-48778, CVE-2026-48800)이 발견되었다. 공격자는 동일 사용자 권한으로 설정 파일을 조작해 임의 명령어 실행이 가능하며, -settingsDir 옵션을 통한 은밀한 공격도 가능하다. 취약점은 v8.9.6.1에서 패치되었으며, Semgrep 기반 정적 분석과 수동 검증을 통해 확인되었다. 이 취약점은 Windo...
##Security Advisory: CVE-2025-60495 - NULL Pointer Dereference in GPAC/MP4Box
Processing a crafted MP4 file with an inconsistent video sample entry triggers a NULL pointer dereference in `gf_media_get_color_info`, causing MP4Box to crash.
Summary:
The `gf_media_get_color_info` function in `media_tools/isom_tools.c` inspects codec-specific boxes nested inside a video sample entry. When a sample entry type (e.g., `v210`) unexpectedly contains an unrelated box (e.g., an `avcC` AVC Decoder Configuration Box), the function dereferences a near-NULL pointer (READ at address 0x000000000008). No NULL-check is performed before the dereference, and the process terminates with SIGSEGV.
CWE:
CWE-476 - NULL Pointer Dereference
Affected Component
```
media_tools/isom_tools.c:979
Function: gf_media_get_color_info()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1780-g50b5741f2-master; commit `50b5741f291126b610c59db433fc02e8a17f0c5d`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a specially crafted MP4 file containing a video sample entry whose type (e.g., `v210`) holds an incompatible child box (e.g., `avcC`). Local access is required; the victim must process the file with `MP4Box -split-size 8000 <crafted_file>` or any equivalent MP4Box operation that triggers muxer PID setup.
Impact:
The NULL pointer dereference (READ at address 0x8) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a near-NULL read that is not exploitable for control-flow hijacking.
Fix / mitigation status:
The fix adds the missing NULL check in `gf_media_get_color_info` before dereferencing the color-info pointer. Users should upgrade to the release containing commit `9beed3c0a2f38505c745e5376234e7ed66e8e0b1` or apply that patch directly.
References
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/66/66_gf_media_get_color_info_media_tools_isom_tools_c_979
- Issue: https://github.com/gpac/gpac/issues/3335
- Fix: https://github.com/gpac/gpac/commit/9beed3c0a2f38505c745e5376234e7ed66e8e0b1
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##Security Advisory: CVE-2025-60495 - NULL Pointer Dereference in GPAC/MP4Box
Processing a crafted MP4 file with an inconsistent video sample entry triggers a NULL pointer dereference in `gf_media_get_color_info`, causing MP4Box to crash.
Summary:
The `gf_media_get_color_info` function in `media_tools/isom_tools.c` inspects codec-specific boxes nested inside a video sample entry. When a sample entry type (e.g., `v210`) unexpectedly contains an unrelated box (e.g., an `avcC` AVC Decoder Configuration Box), the function dereferences a near-NULL pointer (READ at address 0x000000000008). No NULL-check is performed before the dereference, and the process terminates with SIGSEGV.
CWE:
CWE-476 - NULL Pointer Dereference
Affected Component
```
media_tools/isom_tools.c:979
Function: gf_media_get_color_info()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected Version:
2.5-DEV-rev1780-g50b5741f2-master; commit `50b5741f291126b610c59db433fc02e8a17f0c5d`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a specially crafted MP4 file containing a video sample entry whose type (e.g., `v210`) holds an incompatible child box (e.g., `avcC`). Local access is required; the victim must process the file with `MP4Box -split-size 8000 <crafted_file>` or any equivalent MP4Box operation that triggers muxer PID setup.
Impact:
The NULL pointer dereference (READ at address 0x8) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a near-NULL read that is not exploitable for control-flow hijacking.
Fix / mitigation status:
The fix adds the missing NULL check in `gf_media_get_color_info` before dereferencing the color-info pointer. Users should upgrade to the release containing commit `9beed3c0a2f38505c745e5376234e7ed66e8e0b1` or apply that patch directly.
References
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/66/66_gf_media_get_color_info_media_tools_isom_tools_c_979
- Issue: https://github.com/gpac/gpac/issues/3335
- Fix: https://github.com/gpac/gpac/commit/9beed3c0a2f38505c745e5376234e7ed66e8e0b1
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##🟠 CVE-2026-45662 - High (8.8)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45662/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-45662 - High (8.8)
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45662/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Security Advisory: CVE-2025-60477 - NULL Pointer Dereference in GPAC/MP4Box
Processing a crafted MP4 file containing specially crafted metadata with special characters triggers a NULL pointer dereference in `gf_filter_pid_resolve_file_template_ex`, causing MP4Box to crash during DASH segmentation.
Summary:
The `gf_filter_pid_resolve_file_template_ex` function in `filter_core/filter_pid.c` resolves output file name templates during DASH packaging. When input file metadata contains excessively long URLs or HTML-like special characters, the function reaches a `strncmp()` call without verifying that one of its arguments is non-NULL. The resulting dereference of a NULL pointer (READ at address 0x0) terminates the process immediately.
CWE:
CWE-476 - NULL Pointer Dereference
Affected component:
```
filter_core/filter_pid.c:9045
Function: gf_filter_pid_resolve_file_template_ex()
```
Affected Product:
MP4Box (GPAC Multimedia Open Source Project)
Affected version:
2.5-DEV-rev1617-g856674b22-master; commit `856674b226d6cbe28a941ad223be38194cbf7d37`. Any codebase equivalent to this commit that has not applied the fix commit is affected.
Attack Conditions:
An attacker supplies a specially crafted MP4 file whose metadata contains long URLs or HTML-like tags as embedded strings. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers `dasher_setup_sources` and the subsequent template resolution path.
Impact:
The NULL pointer dereference (READ at address 0x000000000000) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a NULL read that is not exploitable for control-flow hijacking.
Fix / mitigation status:
The fix adds the missing NULL check before the `strncmp()` call in `gf_filter_pid_resolve_file_template_ex`. Users should upgrade to the release containing commit `13eb5b76560aaf7813b865a2ad433258478e2695` or apply that patch directly.
References:
- Issue:https://github.com/gpac/gpac/issues/3301
- Fix: https://github.com/gpac/gpac/commit/13eb5b76560aaf7813b865a2ad433258478e2695
- PoC: https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/48/48_gf_filter_pid_resolve_file_template_ex_filter_core_filter_pid_c_9045
Credit
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##🟠 CVE-2026-44698 - High (8.3)
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app Web...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-45555 - High (7.8)
Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAnalyzer assemblies referenced by the target solut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45555/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-45344 - High (8.1)
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on uninitialized LinkAce instances accepts attacker-controlled database credential fields and writes them back into .env without escap...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45344/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48116 - High (7.5)
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-controlled pattern parameter to ripgrep as a positi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48116/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45039 - Critical (9.8)
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a shared secret. The function that produces this secret, get_shared_secret(...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45039/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-45296 - High (7.7)
OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey routes that trust a caller-provided projectKey after validating only that the API key itself is valid and that the target project...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45296/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45323 - Critical (9.6)
MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect (repeated) radio range to execute arbitrary java...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45323/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-47761 - High (8.7)
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47761/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-42197 - High (8.7)
RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execute arbitrary JavaScript in an administrator's bro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##A security vulnerability labelled CVE-2026-27771 affecting Forgejo and Gitea is being widely reported recently.
Packages in Forgejo are visible to unauthenticated users if they are published under a public owner, as designed. It is not a security vulnerability, but a misunderstanding about the permissions and a good opportunity for users to review that they are not in a misconfigured state.
Please see the statement issued by the security team here for more details: https://codeberg.org/forgejo/website/issues/839#issuecomment-15980039
##🔒 7-Zip ha corretto una falla critica, ma chi non aggiorna resta esposto: verifica la versione e installa subito l’ultima release. #Cybersecurity #7Zip
🔗 https://www.tomshw.it/hardware/7-zip-falla-cve-2026-48095-esecuzione-codice
##Critical 7-Zip Vulnerability Allows Remote Code Execution via NTFS Handler
7-Zip version 26.00 and earlier contain a critical heap buffer overflow (CVE-2026-48095) in the NTFS handler that allows attackers to execute arbitrary code via a crafted archive. The flaw is extension-agnostic and can be triggered simply by opening a malicious file.
**If you use 7-Zip, update to version 26.01 or later immediately. Versions 26.00 and earlier let attackers take over your system just by opening a malicious archive. Until you've updated, do not open any archive or disk image files from untrusted or unexpected sources, regardless of the file extension.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/critical-7-zip-vulnerability-allows-remote-code-execution-via-ntfs-handler-2-b-s-s-0/gD2P6Ple2L
⚠️ HIGH severity: Microsoft UFO 3.0.1-4-ge2626659 has a path traversal vuln (CVE-2026-46402). Authenticated users can write files outside logs/. No patch yet — restrict access & monitor input. https://radar.offseq.com/threat/cve-2026-46402-cwe-22-improper-limitation-of-a-pat-6437f7ab #OffSeq #Microsoft #PathTraversal #CVE202646402
##🟠 CVE-2026-46402 - High (8.1)
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can sup...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46402/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-44590 - Critical (9.3)
Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can ex...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44590/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-45102 - Critical (9.9)
OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm module as an isolation primitive. This API was not designed for that and can be escaped via error objects and infinite recursion. T...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45102/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-44888 - Critical (9.8)
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplied numeric config values (e.g., SMTP_PORT) directly into
pialert.conf without validation. Since pia...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44888/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48064 - High (8.1)
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is configured with deny_remote=false in pam_usb (commonly done for display managers such as gdm-password or lightdm to bypass pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48064/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44713 - High (8.8)
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the user's $TMUX environment variable, splits it on commas, and interpolates the socket-path component directly into a shell comman...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44713/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44712 - High (8.2)
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the config causes root RCE when pamusb-conf --reset-pads is run. A USB device with a crafted filesystem UUI...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44712/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-46425 - Critical (9.9)
Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCIM router: requireSCIM (checks the Enterprise feature flag and SCIM config) and doInScimContext (se...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46425/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48152 - High (8.1)
Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by generic TABLE READ, not by Builder/Admin permission or datasource-specific ownership/resource checks. The built-in Basic app use...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48152/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-48150 - Critical (9)
Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAdmin middleware, which passes any user who is a builder for the app id in the x-budibase-app-id header. That check admits both g...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48150/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-48149 - High (8.1)
Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text component renders markdown by assigning marked.parse(markdown) straight to innerHTML with no sanitizer (packages/bbui/src/Markdown/MarkdownViewer.svelte:22). Any colu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48149/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##