## Updated at UTC 2026-05-30T10:53:48.936430

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-10112 2.4 0.00% 2 0 2026-05-30T08:16:16.180000 A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affec
CVE-2026-10110 7.3 0.00% 2 1 2026-05-30T07:16:27.813000 A vulnerability was detected in code-projects Student Details Management System
CVE-2026-10044 7.5 0.05% 1 0 2026-05-30T04:17:05.463000 Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vul
CVE-2026-44724 7.8 0.05% 1 0 2026-05-30T02:16:19.137000 systeminformation is a System and OS information library for node.js. From 4.17.
CVE-2026-9831 6.3 0.00% 2 0 2026-05-29T22:16:23.980000 A race condition in the shared Extreme Platform ONE IAM Gateway API-key authenti
CVE-2026-42941 8.3 0.00% 2 0 2026-05-29T21:31:30 The Danelec MacGregor Voyage Data Recorder device includes a default username a
CVE-2026-9051 9.1 0.00% 2 0 2026-05-29T21:31:24 There is an authentication bypass vulnerability in the NI SystemLink Enterprise
CVE-2026-49368 8.7 0.00% 2 0 2026-05-29T21:31:23 In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification tem
CVE-2026-49374 7.6 0.00% 2 0 2026-05-29T21:31:23 In JetBrains TeamCity before 2026.1 improper permission checks exposed build con
CVE-2026-49367 8.0 0.00% 2 0 2026-05-29T21:31:22 In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via th
CVE-2026-5343 7.4 0.02% 1 0 2026-05-29T21:31:18 Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAM
CVE-2026-45663 9.9 0.00% 2 0 2026-05-29T21:16:40.203000 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and ear
CVE-2026-8364 9.8 0.04% 1 0 2026-05-29T20:26:29.583000 Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe)
CVE-2026-8363 9.8 0.04% 1 0 2026-05-29T20:26:29.583000 A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when p
CVE-2026-45627 8.2 0.00% 2 0 2026-05-29T20:25:00.760000 Arcane is an interface for managing Docker containers, images, networks, and vol
CVE-2026-45625 9.9 0.00% 2 0 2026-05-29T20:25:00.760000 Arcane is an interface for managing Docker containers, images, networks, and vol
CVE-2026-45661 9.9 0.00% 2 0 2026-05-29T20:25:00.760000 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and ear
CVE-2026-45633 9.9 0.00% 2 0 2026-05-29T20:25:00.760000 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and ear
CVE-2026-47179 7.7 0.00% 2 0 2026-05-29T20:25:00.760000 Arcane is an interface for managing Docker containers, images, networks, and vol
CVE-2026-45372 9.9 0.00% 2 0 2026-05-29T20:23:08.683000 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library
CVE-2026-44422 7.5 0.00% 2 0 2026-05-29T20:22:37.383000 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0
CVE-2026-44420 8.8 0.00% 2 0 2026-05-29T20:22:37.383000 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0
CVE-2026-48557 8.8 0.00% 2 0 2026-05-29T20:21:38.773000 Spatie Laravel Media Library before version 11.23.0 contains a file upload restr
CVE-2026-9998 8.3 0.03% 1 0 2026-05-29T20:18:44.250000 Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remo
CVE-2026-44648 7.5 0.00% 2 1 2026-05-29T20:17:38.110000 SillyTavern is a locally installed user interface that allows users to interact
CVE-2026-0257 9.1 0.07% 6 4 2026-05-29T20:16:21.803000 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of
CVE-2026-49366 7.8 0.00% 2 0 2026-05-29T20:11:15.977000 In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via fi
CVE-2026-49372 7.5 0.00% 2 0 2026-05-29T20:11:15.977000 In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build st
CVE-2026-45321 9.6 15.09% 3 12 2026-05-29T19:41:37.437000 On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions
CVE-2026-42929 8.3 0.00% 2 0 2026-05-29T19:16:23.830000 Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded
CVE-2026-46834 7.5 0.04% 1 0 2026-05-29T18:32:27 Vulnerability in the Net Service component of Oracle Database Server. Supported
CVE-2026-5386 9.1 0.00% 2 0 2026-05-29T18:31:42 The affected KMW CCTV Security Cameras are vulnerable to a critical unauthentica
CVE-2026-7786 9.8 0.00% 2 0 2026-05-29T18:31:42 Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Con
CVE-2026-6824 8.4 0.00% 2 0 2026-05-29T18:31:42 A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series
CVE-2026-32905 8.3 0.00% 2 0 2026-05-29T18:31:42 OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the b
CVE-2026-44962 9.9 0.00% 2 0 2026-05-29T18:31:42 Plesk contains an XPath injection vulnerability in the APS Application Catalog s
CVE-2026-10066 8.8 0.00% 2 0 2026-05-29T18:31:41 A security vulnerability has been detected in Shibby Tomato up to 1.28. This iss
CVE-2026-10065 8.8 0.00% 2 0 2026-05-29T18:31:41 A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects
CVE-2026-46821 7.7 0.03% 1 0 2026-05-29T18:31:20 Vulnerability in the Oracle Financials Common Modules product of Oracle E-Busine
CVE-2026-46840 10.0 0.04% 1 1 2026-05-29T18:31:20 Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). S
CVE-2026-46837 8.8 0.04% 1 0 2026-05-29T18:31:20 Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suit
CVE-2026-9999 8.8 0.04% 1 1 2026-05-29T18:17:18.940000 Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.777
CVE-2026-5768 8.8 0.00% 2 0 2026-05-29T18:17:12.997000 The Frontier X2 device allows unauthenticated BLE read/write access to critical
CVE-2026-45615 8.2 0.00% 1 0 2026-05-29T18:17:10.163000 mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulne
CVE-2026-44973 8.1 0.05% 1 0 2026-05-29T16:32:14.400000 Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple pa
CVE-2026-35674 8.8 0.00% 2 0 2026-05-29T16:29:34.540000 OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway c
CVE-2026-35630 8.0 0.00% 2 0 2026-05-29T16:29:34.540000 OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBo
CVE-2026-10067 8.8 0.00% 2 0 2026-05-29T16:29:11.350000 A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub
CVE-2026-45104 7.5 0.04% 1 0 2026-05-29T16:25:57.843000 MapServer is a system for developing web-based GIS applications. From 6.4.0 to b
CVE-2026-32847 7.5 0.08% 1 0 2026-05-29T16:19:35.753000 DeepCode through commit c991dc2 contains a path traversal vulnerability in the S
CVE-2026-46839 9.9 0.04% 1 0 2026-05-29T16:16:30.780000 Vulnerability in Oracle REST Data Services (component: Core). Supported version
CVE-2026-46835 7.5 0.04% 1 0 2026-05-29T16:16:30.520000 Vulnerability in the Net Service component of Oracle Database Server. Supported
CVE-2026-9739 0 0.02% 1 0 2026-05-29T15:42:56.873000 Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During
CVE-2026-32999 9.0 0.05% 1 0 2026-05-29T15:39:34.620000 Insufficient character filtering in backup agent signing module on Comet Backup
CVE-2026-44887 9.8 0.21% 1 0 2026-05-29T15:29:42.387000 Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to
CVE-2026-45083 9.8 0.04% 1 0 2026-05-29T15:29:42.387000 The Goobi viewer is a web application that allows digitised material to be displ
CVE-2026-45578 8.8 0.00% 1 0 2026-05-29T15:06:44.207000 WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cl
CVE-2026-44850 8.5 0.03% 1 0 2026-05-29T15:06:44.207000 Portainer Community Edition is a lightweight service delivery platform for conta
CVE-2026-7480 0 0.01% 1 0 2026-05-29T14:46:09.837000 An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS S
CVE-2026-46510 8.2 0.00% 1 0 2026-05-29T14:16:31.807000 form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-obje
CVE-2026-35675 8.2 0.11% 1 0 2026-05-29T14:16:26.403000 phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the pas
CVE-2026-38703 9.8 0.27% 1 0 2026-05-29T14:09:03.913000 A command injection vulnerability exists in the ZeroTier VPN feature of InHand N
CVE-2026-38707 9.8 0.27% 1 0 2026-05-29T14:08:41.327000 A command injection vulnerability exists in the IPSec VPN feature of InHand Netw
CVE-2026-49127 8.6 0.06% 1 0 2026-05-29T14:07:47.980000 Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflo
CVE-2026-3655 9.8 0.26% 1 0 2026-05-29T13:09:05.450000 The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulner
CVE-2026-8732 9.8 0.07% 1 1 2026-05-29T07:20:15 The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via A
CVE-2026-8070 None 0.01% 1 0 2026-05-29T03:31:14 Incorrect permission assignment for a critical resource in Armoury Crate allows
CVE-2026-46833 9.0 0.04% 1 0 2026-05-29T02:47:03.023000 Vulnerability in the Net Service component of Oracle Database Server. Supported
CVE-2026-47333 7.8 0.01% 1 0 2026-05-29T02:45:36.283000 Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentia
CVE-2026-49128 7.5 0.11% 1 0 2026-05-29T00:39:36 Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulne
CVE-2026-8809 9.8 0.19% 1 0 2026-05-29T00:38:45 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privi
CVE-2026-39929 7.5 0.11% 1 0 2026-05-28T22:16:58.693000 Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.
CVE-2026-9645 9.9 0.05% 1 0 2026-05-28T21:32:17 Exposed methods allow authenticated users to create and execute arbitrary JavaSc
CVE-2026-47331 7.8 0.01% 1 0 2026-05-28T21:32:10 Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock wh
CVE-2026-4944 8.8 0.09% 1 0 2026-05-28T21:32:10 vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remot
CVE-2026-43898 10.0 0.05% 1 0 2026-05-28T20:16:23.810000 SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined fu
CVE-2026-47759 8.7 0.03% 1 0 2026-05-28T19:19:37.803000 TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, t
CVE-2026-47760 8.7 0.03% 1 0 2026-05-28T19:19:03.740000 TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE
CVE-2026-46509 8.2 0.04% 1 0 2026-05-28T19:16:39.280000 deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, pr
CVE-2026-46414 8.8 0.04% 2 0 2026-05-28T18:56:36.823000 Microsoft UFO open-source framework for intelligent automation across devices an
CVE-2026-45322 7.8 0.06% 1 0 2026-05-28T18:56:36.823000 Microsoft UFO open-source framework for intelligent automation across devices an
CVE-2026-45311 9.6 0.04% 1 0 2026-05-28T18:40:37.990000 CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, t
CVE-2026-38702 9.8 0.27% 1 0 2026-05-28T18:30:39 A command injection vulnerability exists in the Admin Access feature of InHand N
CVE-2026-9095 8.1 0.04% 1 0 2026-05-28T18:30:39 Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions withou
CVE-2026-38704 9.8 0.27% 1 0 2026-05-28T18:30:39 A command injection vulnerability exists in the WireGuard VPN feature of InHand
CVE-2026-49238 8.4 0.02% 1 0 2026-05-28T18:00:33.730000 An issue was discovered in Canonical Multipass before version 1.16.3. The host-s
CVE-2026-44326 9.4 0.04% 1 0 2026-05-28T16:25:38.687000 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2,
CVE-2026-48151 7.5 0.03% 1 0 2026-05-28T16:16:28.793000 Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schem
CVE-2026-35671 8.8 0.04% 1 0 2026-05-28T14:19:43 ### Summary An Insecure Direct Object Reference (IDOR) vulnerability in phpMyFAQ
CVE-2026-44711 7.9 0.02% 1 0 2026-05-28T14:16:21.263000 pam_usb provides hardware authentication for Linux using ordinary removable medi
CVE-2026-44635 7.5 0.05% 1 0 2026-05-28T14:16:20.450000 Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, Defa
CVE-2026-44709 7.8 0.02% 1 0 2026-05-28T13:57:25.390000 pam_usb provides hardware authentication for Linux using ordinary removable medi
CVE-2026-9227 8.8 0.14% 1 0 2026-05-28T13:45:25.260000 The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary
CVE-2026-9009 8.8 0.24% 2 0 2026-05-28T13:45:25.260000 The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnera
CVE-2026-8915 8.8 0.02% 2 0 2026-05-28T13:44:54.327000 Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflo
CVE-2026-7862 8.6 0.04% 1 0 2026-05-28T12:33:02 The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not proper
CVE-2026-4408 9.0 0.23% 2 0 2026-05-28T09:31:27 A flaw was found in Samba. A remote attacker can exploit a misconfiguration in S
CVE-2026-6455 8.1 0.04% 1 0 2026-05-28T09:31:26 The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Sit
CVE-2026-7802 8.8 0.06% 1 0 2026-05-28T06:31:16 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authoriza
CVE-2026-9789 None 0.02% 1 0 2026-05-28T03:31:21 A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense softwar
CVE-2026-9208 8.8 0.07% 1 0 2026-05-28T00:30:35 Tanium addressed an unauthorized code execution vulnerability in Connect.
CVE-2026-45332 7.5 0.04% 1 0 2026-05-27T21:32:32 ### Summary A Broken Access Control vulnerability allows an unauthenticated at
CVE-2026-8359 7.5 0.05% 1 0 2026-05-27T21:31:33 When processing a request with a URL path starting with /status or /sysinfo, WOS
CVE-2026-8362 9.8 0.04% 1 0 2026-05-27T21:31:32 A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when
CVE-2026-8361 7.5 0.04% 1 0 2026-05-27T21:31:32 A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processin
CVE-2026-8360 7.5 0.04% 1 0 2026-05-27T21:31:32 Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DL
CVE-2026-48027 9.8 26.85% 3 0 2026-05-27T20:34:24.850000 Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious ver
CVE-2026-45716 8.8 0.03% 1 0 2026-05-27T20:16:39.200000 Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/glo
CVE-2026-45108 8.4 0.07% 1 0 2026-05-27T20:16:38.550000 Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune.
CVE-2026-48153 8.5 0.03% 1 0 2026-05-27T19:44:35.987000 Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the
CVE-2026-45659 8.8 0.62% 1 2 2026-05-27T18:32:54.337000 Deserialization of untrusted data in Microsoft Office SharePoint allows an autho
CVE-2015-2808 10.0 23.36% 1 0 2026-05-27T18:32:34 The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not proper
CVE-2025-14713 7.5 0.03% 1 0 2026-05-27T14:54:20.160000 An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Ed
CVE-2026-46372 8.5 0.00% 2 0 template 2026-05-27T06:01:20 ## Resolution SillyTavern 1.18.0 added a generic server-side request filter (Pr
CVE-2026-5426 9.1 0.07% 2 1 2026-05-26T19:16:29.123000 Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver de
CVE-2026-43284 7.8 25.56% 1 33 2026-05-26T18:32:39 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp:
CVE-2026-47125 8.8 0.00% 2 0 2026-05-23T00:16:58 ## Summary The `PUT /api/environments/{id}/templates/variables` endpoint, which
CVE-2026-41091 7.8 6.98% 1 2 2026-05-20T19:06:36.850000 Improper link resolution before file access ('link following') in Microsoft Defe
CVE-2026-45498 4.0 4.11% 1 1 2026-05-20T18:31:35 Microsoft Defender Denial of Service Vulnerability
CVE-2026-45137 8.2 0.04% 1 0 2026-05-19T16:08:42 ### Summary An logic error causes anchor programs to accept any program id when
CVE-2026-31431 7.8 2.23% 5 100 2026-05-18T18:32:28 In the Linux kernel, the following vulnerability has been resolved: crypto: alg
CVE-2026-45707 8.1 0.00% 1 0 2026-05-18T17:41:42 ## Summary When `ENABLE_MULTI_TENANT=true`, the HTTP transport documents that t
CVE-2026-45697 9.8 0.00% 2 0 2026-05-18T17:23:40 ### Impact - Unauthenticated users could submit crafted values into Hidden field
CVE-2026-43500 7.8 27.00% 1 15 2026-05-17T16:16:16.740000 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also
CVE-2026-8398 9.8 14.39% 2 0 2026-05-15T09:31:43 A supply chain attack compromised the official installation packages of DAEMON T
CVE-2026-45374 9.6 0.04% 1 0 2026-05-14T20:29:53 ### Summary The `task_create` tool spawns durable sub-agents that inherit two i
CVE-2026-45348 8.7 0.03% 1 0 2026-05-14T20:23:52 ## Summary The `packages.js` template at `src/pyload/webui/app/themes/modern/te
CVE-2026-20182 10.0 77.32% 1 3 template 2026-05-14T18:33:03 May 2026: This security advisory provides the details and fix information for a
CVE-2026-40369 7.8 0.01% 2 3 2026-05-14T17:52:50.143000 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to
CVE-2026-44882 8.1 0.04% 1 0 2026-05-14T16:24:31 ## Summary Portainer proxies requests to Kubernetes clusters through a middlewa
CVE-2026-45152 7.8 0.03% 1 0 2026-05-13T15:33:13 I discovered a command injection vulnerability in uniget that allows arbitrary c
CVE-2026-28910 3.3 0.01% 1 0 2026-05-13T14:02:20.380000 This issue was addressed with improved permissions checking. This issue is fixed
CVE-2026-44650 9.1 0.00% 2 0 2026-05-12T22:23:47 ## Summary `POST /api/extensions/delete` endpoint accepts `extensionName: "."`
CVE-2026-44649 9.8 0.00% 2 0 2026-05-12T22:23:33 ## Resolution SillyTavern 1.18.0 now includes a configuration option to limit w
CVE-2026-45088 7.5 0.03% 1 0 2026-05-12T15:08:14 ## Summary When dalfox is run in REST API server mode, the `custom-payload-file
CVE-2026-26980 9.4 56.66% 1 5 template 2026-05-12T13:31:01 ### Impact A SQL injection vulnerability existed in Ghost's Content API that al
CVE-2026-45047 7.5 0.08% 1 0 2026-05-11T16:17:49 ### Summary The `apiHandler` (and similarly `webHandlerTelegramBot`) processes u
CVE-2026-44483 8.2 0.04% 1 0 2026-05-11T16:09:41 ## Summary `setPath` in `@rvf/set-get` (used by `@rvf/core` to flatten incoming
CVE-2026-44327 10.0 0.04% 1 0 2026-05-08T22:59:24 ### Summary free5GC's NEF mounts the `nnef-oam` route group without inbound OAut
CVE-2026-39987 9.8 82.17% 2 11 template 2026-04-23T20:15:29.690000 marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE
CVE-2026-3172 8.1 0.06% 2 0 2026-04-15T00:35:42.020000 Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 all
CVE-2024-8310 9.8 0.04% 1 0 2026-04-15T00:35:42.020000 OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass auth
CVE-2024-55884 9.0 0.80% 1 0 2026-04-15T00:35:42.020000 In the Mullvad VPN client 2024.6 (Desktop), 2024.8 (iOS), and 2024.8-beta1 (Andr
CVE-2026-35616 9.8 41.17% 2 8 template 2026-04-06T18:12:57.863000 A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through
CVE-2024-49611 10.0 0.63% 1 0 2026-04-01T18:32:06 Unrestricted Upload of File with Dangerous Type vulnerability in Paxman Product
CVE-2026-4565 8.8 0.09% 1 2 2026-03-23T03:31:45 A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function
CVE-2025-10158 4.3 0.05% 1 0 2025-11-18T15:30:54 A malicious client acting as the receiver of an rsync file transfer can trigger
CVE-2019-1385 7.8 0.49% 2 0 2025-10-29T14:34:16.610000 An elevation of privilege vulnerability exists when the Windows AppX Deployment
CVE-2016-10156 7.8 0.71% 1 0 2025-04-20T03:32:27 A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files
CVE-2025-0066 9.9 0.09% 1 0 2025-01-14T03:31:48 Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet C
CVE-2021-4229 5.0 0.86% 1 1 2024-11-21T06:37:11.567000 A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated
CVE-2017-16054 7.5 0.26% 1 0 2024-11-21T03:15:44.050000 `nodefabric` was a malicious module published with the intent to hijack environm
CVE-2024-45694 9.8 2.49% 1 0 2024-09-17T18:40:07.243000 The web service of certain models of D-Link wireless routers contains a Stack-ba
CVE-2024-7261 9.8 27.88% 1 0 2024-09-13T19:39:40.570000 The improper neutralization of special elements in the parameter "host" in the C
CVE-2024-42395 9.8 0.27% 2 0 2024-08-12T18:23:57.077000 There is a vulnerability in the AP Certificate Management Service which could al
CVE-2023-25136 9.8 88.33% 1 11 2024-03-07T05:10:04 OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.
CVE-2021-24084 5.5 3.49% 2 2 2024-01-07T05:05:26 Windows Mobile Device Management Information Disclosure Vulnerability
CVE-2025-60486 0 0.00% 2 0 N/A
CVE-2025-60485 0 0.00% 2 0 N/A
CVE-2026-45632 0 0.00% 2 0 N/A
CVE-2026-45631 0 0.00% 2 0 N/A
CVE-2026-45630 0 0.00% 2 0 N/A
CVE-2026-47740 0 0.00% 2 0 N/A
CVE-2026-44421 0 0.00% 2 0 N/A
CVE-2026-44285 0 0.00% 2 0 N/A
CVE-2026-47123 0 0.00% 2 0 N/A
CVE-2026-47744 0 0.00% 2 0 N/A
CVE-2025-55664 0 0.00% 2 0 N/A
CVE-2026-48710 0 0.03% 4 3 N/A
CVE-2025-60481 0 0.00% 2 0 N/A
CVE-2025-60483 0 0.00% 2 0 N/A
CVE-2026-48778 0 0.00% 1 1 N/A
CVE-2026-48800 0 0.00% 1 1 N/A
CVE-2025-60495 0 0.00% 2 0 N/A
CVE-2026-45662 0 0.00% 2 0 N/A
CVE-2025-60477 0 0.00% 1 0 N/A
CVE-2026-44698 0 0.00% 1 0 N/A
CVE-2026-45555 0 0.00% 1 0 N/A
CVE-2026-45344 0 0.16% 1 0 N/A
CVE-2026-48116 0 0.05% 1 0 N/A
CVE-2026-45039 0 0.04% 1 0 N/A
CVE-2026-45296 0 0.03% 1 0 N/A
CVE-2026-45323 0 0.04% 1 0 N/A
CVE-2026-47761 0 0.03% 1 0 N/A
CVE-2026-42197 0 0.03% 1 0 N/A
CVE-2026-27771 0 0.00% 1 2 N/A
CVE-2026-48095 0 0.00% 2 1 N/A
CVE-2026-46402 0 0.06% 2 0 N/A
CVE-2026-44590 0 0.85% 1 1 N/A
CVE-2026-45102 0 0.06% 1 0 N/A
CVE-2026-44888 0 0.05% 1 0 N/A
CVE-2026-48064 0 0.06% 1 0 N/A
CVE-2026-44713 0 0.02% 1 0 N/A
CVE-2026-44712 0 0.02% 1 0 N/A
CVE-2026-46425 0 0.04% 1 0 N/A
CVE-2026-48152 0 0.04% 1 0 N/A
CVE-2026-48150 0 0.05% 1 0 N/A
CVE-2026-48149 0 0.03% 1 0 N/A

CVE-2026-10112
(2.4 LOW)

EPSS: 0.00%

updated 2026-05-30T08:16:16.180000

2 posts

A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the component Dashboard Page. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not

offseq at 2026-05-30T09:00:24.741Z ##

⚠️ XSS vuln (MEDIUM, CVSS 4.8) in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0 — CVE-2026-10112. 'Name' param on Dashboard Page unsanitized, allowing script injection. No patch yet — use input validation/output encoding. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-05-30T09:00:24.000Z ##

⚠️ XSS vuln (MEDIUM, CVSS 4.8) in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0 — CVE-2026-10112. 'Name' param on Dashboard Page unsanitized, allowing script injection. No patch yet — use input validation/output encoding. radar.offseq.com/threat/cve-20 #OffSeq #XSS #AppSec #Vulnerability

##

CVE-2026-10110
(7.3 HIGH)

EPSS: 0.00%

updated 2026-05-30T07:16:27.813000

2 posts

A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

1 repos

https://github.com/Xmyronn/CVE-2026-10110-SQLi

offseq at 2026-05-30T07:30:22.858Z ##

⚠️ CVE-2026-10110: MEDIUM severity SQL injection in code-projects Student Details Management System 1.0 (/index.php, roll parameter). Public exploit available — remote attack possible. Monitor and restrict access. radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-05-30T07:30:22.000Z ##

⚠️ CVE-2026-10110: MEDIUM severity SQL injection in code-projects Student Details Management System 1.0 (/index.php, roll parameter). Public exploit available — remote attack possible. Monitor and restrict access. radar.offseq.com/threat/cve-20 #OffSeq #SQLInjection #Vuln

##

CVE-2026-10044
(7.5 HIGH)

EPSS: 0.05%

updated 2026-05-30T04:17:05.463000

1 posts

Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying absolute Windows paths or backslash-based traversal sequences. Attackers can bypass the incomplete path traversal guard, which only blocks forward slashes and '

thehackerwire@mastodon.social at 2026-05-28T23:01:29.000Z ##

🟠 CVE-2026-10044 - High (7.5)

Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying absolut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44724
(7.8 HIGH)

EPSS: 0.05%

updated 2026-05-30T02:16:19.137000

1 posts

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real nmcli device status output. The library sanitizes the network interface name befor

thehackerwire@mastodon.social at 2026-05-28T05:00:48.000Z ##

🟠 CVE-2026-44724 - High (7.8)

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9831
(6.3 MEDIUM)

EPSS: 0.00%

updated 2026-05-29T22:16:23.980000

2 posts

A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API key to receive response data for another tenant. The issue was observed through ExtremeCloud IQ/XIQ API endpoints and validated against both XIQ/XAPI and Extrem

offseq at 2026-05-30T04:30:24.017Z ##

🚩 CVE-2026-9831: Medium severity race condition in Extreme Networks Extreme Platform ONE IAM Gateway. High-concurrency API key use may cause data leak across tenants. No patch yet — monitor advisories. Details: radar.offseq.com/threat/cve-20

##

offseq@infosec.exchange at 2026-05-30T04:30:24.000Z ##

🚩 CVE-2026-9831: Medium severity race condition in Extreme Networks Extreme Platform ONE IAM Gateway. High-concurrency API key use may cause data leak across tenants. No patch yet — monitor advisories. Details: radar.offseq.com/threat/cve-20 #OffSeq #ExtremeNetworks #CloudSec #CVE2026_9831

##

CVE-2026-42941
(8.3 HIGH)

EPSS: 0.00%

updated 2026-05-29T21:31:30

2 posts

The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.

thehackerwire@mastodon.social at 2026-05-30T03:00:00.000Z ##

🟠 CVE-2026-42941 - High (8.3)

The Danelec MacGregor Voyage Data Recorder

device includes a default username and password, with no enforced password change.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-30T03:00:00.000Z ##

🟠 CVE-2026-42941 - High (8.3)

The Danelec MacGregor Voyage Data Recorder

device includes a default username and password, with no enforced password change.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9051
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-05-29T21:31:24

2 posts

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure.  Successful exploitation requires an attacker to send a specially crafted HTTP request.  This vulnerability affects NI SystemLink Enterprise 2026-04 and pr

thehackerwire@mastodon.social at 2026-05-29T19:59:52.000Z ##

🔴 CVE-2026-9051 - Critical (9.1)

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure.  ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T19:59:52.000Z ##

🔴 CVE-2026-9051 - Critical (9.1)

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure.  ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49368
(8.7 HIGH)

EPSS: 0.00%

updated 2026-05-29T21:31:23

2 posts

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

thehackerwire@mastodon.social at 2026-05-29T22:00:29.000Z ##

🟠 CVE-2026-49368 - High (8.7)

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T22:00:29.000Z ##

🟠 CVE-2026-49368 - High (8.7)

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49374
(7.6 HIGH)

EPSS: 0.00%

updated 2026-05-29T21:31:23

2 posts

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

thehackerwire@mastodon.social at 2026-05-29T20:00:12.000Z ##

🟠 CVE-2026-49374 - High (7.6)

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T20:00:12.000Z ##

🟠 CVE-2026-49374 - High (7.6)

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49367
(8.0 HIGH)

EPSS: 0.00%

updated 2026-05-29T21:31:22

2 posts

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

thehackerwire@mastodon.social at 2026-05-29T20:01:24.000Z ##

🟠 CVE-2026-49367 - High (8)

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T20:01:24.000Z ##

🟠 CVE-2026-49367 - High (8)

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5343
(7.4 HIGH)

EPSS: 0.02%

updated 2026-05-29T21:31:18

1 posts

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation. This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4.

offseq@infosec.exchange at 2026-05-29T00:00:34.000Z ##

⚠️ HIGH severity: CVE-2026-5343 in Drupal SAML SSO - Service Provider (pre-3.1.4) allows privilege escalation via improper exception checks. No patch or exploits yet. Monitor advisories for updates. radar.offseq.com/threat/cve-20 #OffSeq #Drupal #Vuln #SAML

##

CVE-2026-45663
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-05-29T21:16:40.203000

2 posts

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath parameter is not properly sanitized and is directly interpolated into a shell command string. By including shell metacharacters such as ; or ", an attacke

thehackerwire@mastodon.social at 2026-05-29T17:00:15.000Z ##

🔴 CVE-2026-45663 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T17:00:15.000Z ##

🔴 CVE-2026-45663 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath p...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8364
(9.8 CRITICAL)

EPSS: 0.04%

updated 2026-05-29T20:26:29.583000

1 posts

Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache.

thehackerwire@mastodon.social at 2026-05-27T23:01:20.000Z ##

🔴 CVE-2026-8364 - Critical (9.8)

Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8363
(9.8 CRITICAL)

EPSS: 0.04%

updated 2026-05-29T20:26:29.583000

1 posts

A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:

thehackerwire@mastodon.social at 2026-05-27T22:01:59.000Z ##

🔴 CVE-2026-8363 - Critical (9.8)

A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45627
(8.2 HIGH)

EPSS: 0.00%

updated 2026-05-29T20:25:00.760000

2 posts

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via strings.ReplaceAll with no escaping. The substitution lands inside a <style> element of the embedded logo.svg, allowing an attacker to close the style block an

thehackerwire@mastodon.social at 2026-05-30T05:00:13.000Z ##

🟠 CVE-2026-45627 - High (8.2)

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via string...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-30T05:00:13.000Z ##

🟠 CVE-2026-45627 - High (8.2)

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via string...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45625
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-05-29T20:25:00.760000

2 posts

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps source repositories and their stored credentials. Eight of those endpoints (list, create, get, update, delete, test, listBranches, browseFiles) never call t

thehackerwire@mastodon.social at 2026-05-30T05:00:02.000Z ##

🔴 CVE-2026-45625 - Critical (9.9)

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps sou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-30T05:00:02.000Z ##

🔴 CVE-2026-45625 - Critical (9.9)

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and /api/git-repositories/sync for managing GitOps sou...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45661
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-05-29T20:25:00.760000

2 posts

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application deployment. When combined with Dokploy's remote server deployment feature, this vulnerability enables arbitrary file write to remote server filesystems, a

thehackerwire@mastodon.social at 2026-05-30T04:00:30.000Z ##

🔴 CVE-2026-45661 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-30T04:00:30.000Z ##

🔴 CVE-2026-45661 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application d...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45633
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-05-29T20:25:00.760000

2 posts

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges.

thehackerwire@mastodon.social at 2026-05-30T04:00:20.000Z ##

🔴 CVE-2026-45633 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are dire...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-30T04:00:20.000Z ##

🔴 CVE-2026-45633 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are dire...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47179
(7.7 HIGH)

EPSS: 0.00%

updated 2026-05-29T20:25:00.760000

2 posts

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project's compose file before any path-traversal validation runs. Because ProjectService.CreateProject writes attacker-supplied compose content to disk without validating include paths,

thehackerwire@mastodon.social at 2026-05-29T19:01:03.000Z ##

🟠 CVE-2026-47179 - High (7.7)

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project's compose file before an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T19:01:03.000Z ##

🟠 CVE-2026-47179 - High (7.7)

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project's compose file before an...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45372
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-05-29T20:23:08.683000

2 posts

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity check (is_field_value) is run before decoding, so encoded %0D%0A passes the check and is then expanded to a literal \r\n byte pair inside the stored header

thehackerwire@mastodon.social at 2026-05-29T21:01:00.000Z ##

🔴 CVE-2026-45372 - Critical (9.9)

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity ch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T21:01:00.000Z ##

🔴 CVE-2026-45372 - Critical (9.9)

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity ch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44422
(7.5 HIGH)

EPSS: 0.00%

updated 2026-05-29T20:22:37.383000

2 posts

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is reused across two pointer fields, the parser assigns the same heap object to both output fields. The generic destructor

thehackerwire@mastodon.social at 2026-05-29T22:00:19.000Z ##

🟠 CVE-2026-44422 - High (7.5)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ow...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T22:00:19.000Z ##

🟠 CVE-2026-44422 - High (7.5)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ow...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44420
(8.8 HIGH)

EPSS: 0.00%

updated 2026-05-29T20:22:37.383000

2 posts

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process (remote DoS) and may be exploitable for code execution because it corrupts heap memory. This vulner

thehackerwire@mastodon.social at 2026-05-29T21:01:20.000Z ##

🟠 CVE-2026-44420 - High (8.8)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T21:01:20.000Z ##

🟠 CVE-2026-44420 - High (8.8)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48557
(8.8 HIGH)

EPSS: 0.00%

updated 2026-05-29T20:21:38.773000

2 posts

Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypass the blocklist, with pathinfo() preserving inner .php stems in saved filenames. The blocklist also omits executable extensions including .php6, .shtml,

thehackerwire@mastodon.social at 2026-05-29T21:00:12.000Z ##

🟠 CVE-2026-48557 - High (8.8)

Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T21:00:12.000Z ##

🟠 CVE-2026-48557 - High (8.8)

Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9998
(8.3 HIGH)

EPSS: 0.03%

updated 2026-05-29T20:18:44.250000

1 posts

Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

offseq@infosec.exchange at 2026-05-29T06:00:24.000Z ##

🛡️ HIGH severity: Chrome <148.0.7778.216 has an integer overflow (CVE-2026-9998) in Skia. Potential sandbox escape if renderer is compromised. Patch ASAP! More info: radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Vuln #Infosec

##

CVE-2026-44648
(7.5 HIGH)

EPSS: 0.00%

updated 2026-05-29T20:17:38.110000

2 posts

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session for authentication, storing all session data (user handle, permissions) in a signed cookie. The endpoints POST /api/users/change-password and POST /api/users/recov

1 repos

https://github.com/zzzm0919/CVE-2026-44648

thehackerwire@mastodon.social at 2026-05-29T23:00:33.000Z ##

🟠 CVE-2026-44648 - High (7.5)

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session for authen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T23:00:33.000Z ##

🟠 CVE-2026-44648 - High (7.5)

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session for authen...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-0257
(9.1 CRITICAL)

EPSS: 0.07%

updated 2026-05-29T20:16:21.803000

6 posts

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

4 repos

https://github.com/0xBlackash/CVE-2026-0257

https://github.com/sfewer-r7/CVE-2026-0257

https://github.com/HORKimhab/CVE-2026-0257

https://github.com/akashsingh0454/CVE-2026-0257-PoC

Analyst207@mastodon.social at 2026-05-30T08:20:14.000Z ##

Palo Alto Networks Warns of Active Exploitation of GlobalProtect Flaw

Palo Alto Networks has issued a warning about a critical GlobalProtect flaw, CVE-2026-0257, that is being actively exploited, allowing attackers to bypass security restrictions and establish unauthorized VPN connections. This vulnerability affects specific PAN-OS and Prisma Access deployments with certain…

osintsights.com/palo-alto-netw

#PaloAltoNetworks #Globalprotect #Cve20260257 #VpnExploitation #AuthenticationBypass

##

bugxhunter at 2026-05-30T06:01:24.686Z ##

🏛️ Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

📝 CISA added CVE-2026-0257 to its KEV Catalog due to active exploitation, posing risks to...

cisa.gov/news-events/alerts/20

📰 Alerts

##

cisakevtracker@mastodon.social at 2026-05-29T20:00:42.000Z ##

CVE ID: CVE-2026-0257
Vendor: Palo Alto Networks
Product: PAN-OS
Date Added: 2026-05-29
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CapTechGroup@mastodon.social at 2026-05-29T18:17:10.000Z ##

CVE-2026-0257 exploits a missing signature verification in GlobalProtect's cookie validation. Attackers forge authentication cookies using the /usr/local/bin/gpsvc binary's RSA private keys, gaining VPN access without...

captechgroup.com/about-us/thre

##

bugxhunter@infosec.exchange at 2026-05-30T06:01:24.000Z ##

🏛️ Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

📝 CISA added CVE-2026-0257 to its KEV Catalog due to active exploitation, posing risks to...

cisa.gov/news-events/alerts/20

📰 Alerts

#GovSec #CVE #ZeroDay

##

cisakevtracker@mastodon.social at 2026-05-29T20:00:42.000Z ##

CVE ID: CVE-2026-0257
Vendor: Palo Alto Networks
Product: PAN-OS
Date Added: 2026-05-29
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-49366
(7.8 HIGH)

EPSS: 0.00%

updated 2026-05-29T20:11:15.977000

2 posts

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

thehackerwire@mastodon.social at 2026-05-29T20:01:14.000Z ##

🟠 CVE-2026-49366 - High (7.8)

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T20:01:14.000Z ##

🟠 CVE-2026-49366 - High (7.8)

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49372
(7.5 HIGH)

EPSS: 0.00%

updated 2026-05-29T20:11:15.977000

2 posts

In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible

thehackerwire@mastodon.social at 2026-05-29T20:00:02.000Z ##

🟠 CVE-2026-49372 - High (7.5)

In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T20:00:02.000Z ##

🟠 CVE-2026-49372 - High (7.5)

In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45321
(9.6 CRITICAL)

EPSS: 15.09%

updated 2026-05-29T19:41:37.437000

3 posts

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn

12 repos

https://github.com/nkopylov/tanscript-exploit-check

https://github.com/Intrudify/mini-shai-hulud-scanner

https://github.com/qi-scape/scan-shai-hulud

https://github.com/Yomisana/are-you-get-tanstack-attack

https://github.com/digi4care/shai-scan

https://github.com/Caixa-git/tanstack-shield

https://github.com/fabriziosalmi/tanstack-compromise-checker

https://github.com/shayr1/shai-hulud-scan

https://github.com/Breakingcircuitsllc/teampcp_shai_hulud.yar

https://github.com/ry-allan/tanstack-compromise-checker

https://github.com/renewablehacking/CVE-2026-45321-Tanstack

https://github.com/prashanthnataraj/mini-shai-hulud-detector

kev_Stalker@infosec.exchange at 2026-05-28T19:01:11.000Z ##

CVE-2026-45321 - Changed to Known Ransomware Status

TanStack Unspecified VulnerabilityVendor: TanStackProduct: TanStackTanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: May 28, 2026 at 18:00:35 UTCDate Added to KEV: nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-05-27T20:00:15.000Z ##

🚨 [CISA-2026:0527] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-45321 (secdb.nttzen.cloud/cve/detail/)
- Name: TanStack Unspecified Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TanStack
- Product: TanStack
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/TanStack/router/sec ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-48027 (secdb.nttzen.cloud/cve/detail/)
- Name: Nx Console Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Nx
- Product: Nx Console
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/nrwl/nx-console/sec ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8398 (secdb.nttzen.cloud/cve/detail/)
- Name: Daemon Tools Lite Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Daemon
- Product: Daemon Tools Lite
- Notes: blog.daemon-tools.cc/post/secu ; nvd.nist.gov/vuln/detail/CVE-2

#SecDB #InfoSec #CVE #CISA_KEV #cisa_20260527 #cisa20260527 #cve_2026_45321 #cve_2026_48027 #cve_2026_8398 #cve202645321 #cve202648027 #cve20268398

##

cisakevtracker@mastodon.social at 2026-05-27T18:01:05.000Z ##

CVE ID: CVE-2026-45321
Vendor: TanStack
Product: TanStack
Date Added: 2026-05-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-42929
(8.3 HIGH)

EPSS: 0.00%

updated 2026-05-29T19:16:23.830000

2 posts

Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

thehackerwire@mastodon.social at 2026-05-30T01:00:23.000Z ##

🟠 CVE-2026-42929 - High (8.3)

Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-30T01:00:23.000Z ##

🟠 CVE-2026-42929 - High (8.3)

Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46834
(7.5 HIGH)

EPSS: 0.04%

updated 2026-05-29T18:32:27

1 posts

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servic

thehackerwire@mastodon.social at 2026-05-28T22:00:35.000Z ##

🟠 CVE-2026-46834 - High (7.5)

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5386
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-05-29T18:31:42

2 posts

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the camera feeds and settings.

thehackerwire@mastodon.social at 2026-05-29T19:01:16.000Z ##

🔴 CVE-2026-5386 - Critical (9.1)

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T19:01:16.000Z ##

🔴 CVE-2026-5386 - Critical (9.1)

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access to the ca...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7786
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-05-29T18:31:42

2 posts

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can be extracted through firmware analysis and used to authenticate to device services.

thehackerwire@mastodon.social at 2026-05-29T19:00:11.000Z ##

🔴 CVE-2026-7786 - Critical (9.8)

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can be extracted through firmware analysis and u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T19:00:11.000Z ##

🔴 CVE-2026-7786 - Critical (9.8)

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can be extracted through firmware analysis and u...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-6824
(8.4 HIGH)

EPSS: 0.00%

updated 2026-05-29T18:31:42

2 posts

A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently stored on the device backend. When administrators or users access affected pages, the stored scripts are executed in their browsers, leading to potentia

thehackerwire@mastodon.social at 2026-05-29T19:00:01.000Z ##

🟠 CVE-2026-6824 - High (8.4)

A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T19:00:01.000Z ##

🟠 CVE-2026-6824 - High (8.4)

A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-32905
(8.3 HIGH)

EPSS: 0.00%

updated 2026-05-29T18:31:42

2 posts

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can create setup codes to enroll devices with operator/node capabilities, granting persistent credentials until manual removal.

thehackerwire@mastodon.social at 2026-05-29T17:01:23.000Z ##

🟠 CVE-2026-32905 - High (8.3)

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T17:01:23.000Z ##

🟠 CVE-2026-32905 - High (8.3)

OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat co...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44962
(9.9 CRITICAL)

EPSS: 0.00%

updated 2026-05-29T18:31:42

2 posts

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.

thehackerwire@mastodon.social at 2026-05-29T17:00:25.000Z ##

🔴 CVE-2026-44962 - Critical (9.9)

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to exe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T17:00:25.000Z ##

🔴 CVE-2026-44962 - Critical (9.9)

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to exe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10066
(8.8 HIGH)

EPSS: 0.00%

updated 2026-05-29T18:31:41

2 posts

A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.

thehackerwire@mastodon.social at 2026-05-29T18:00:09.000Z ##

🟠 CVE-2026-10066 - High (8.8)

A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. The attack can be initi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T18:00:09.000Z ##

🟠 CVE-2026-10066 - High (8.8)

A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. The attack can be initi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10065
(8.8 HIGH)

EPSS: 0.00%

updated 2026-05-29T18:31:41

2 posts

A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.

thehackerwire@mastodon.social at 2026-05-29T18:00:00.000Z ##

🟠 CVE-2026-10065 - High (8.8)

A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack-based buffer overflow. It is possible to launch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T18:00:00.000Z ##

🟠 CVE-2026-10065 - High (8.8)

A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack-based buffer overflow. It is possible to launch...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46821
(7.7 HIGH)

EPSS: 0.03%

updated 2026-05-29T18:31:20

1 posts

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. While the vulnerability is in Oracle Financials Common Modules, attacks may sig

thehackerwire@mastodon.social at 2026-05-29T01:00:00.000Z ##

🟠 CVE-2026-46821 - High (7.7)

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46840
(10.0 CRITICAL)

EPSS: 0.04%

updated 2026-05-29T18:31:20

1 posts

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). S

1 repos

https://github.com/fangbarristerbar/CVE-2026-46840-ORDS-RCE

thehackerwire@mastodon.social at 2026-05-29T00:00:22.000Z ##

🔴 CVE-2026-46840 - Critical (10)

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Ora...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46837
(8.8 HIGH)

EPSS: 0.04%

updated 2026-05-29T18:31:20

1 posts

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturing. CVSS 3.1

thehackerwire@mastodon.social at 2026-05-28T22:01:36.000Z ##

🟠 CVE-2026-46837 - High (8.8)

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9999
(8.8 HIGH)

EPSS: 0.04%

updated 2026-05-29T18:17:18.940000

1 posts

Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

1 repos

https://github.com/24520597-blip/CVE-2026-999999

offseq@infosec.exchange at 2026-05-29T01:30:24.000Z ##

CVE-2026-9999: HIGH severity flaw in Chrome (Mac, <148.0.7778.216) allows remote code execution in the sandbox via crafted HTML. No exploits in the wild. Patch to 148.0.7778.216+ now! radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Mac #Vuln #Security

##

CVE-2026-5768
(8.8 HIGH)

EPSS: 0.00%

updated 2026-05-29T18:17:12.997000

2 posts

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce une

thehackerwire@mastodon.social at 2026-05-29T19:01:26.000Z ##

🟠 CVE-2026-5768 - High (8.8)

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T19:01:26.000Z ##

🟠 CVE-2026-5768 - High (8.8)

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45615
(8.2 HIGH)

EPSS: 0.00%

updated 2026-05-29T18:17:10.163000

1 posts

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsing a maliciously crafted, zero-length OER payload for a variable-length, non-negative INTEGER type, the decoder fails to validate the required bytes before extracting the Most Significant Bit (MSB). Thi

thehackerwire@mastodon.social at 2026-05-29T15:01:06.000Z ##

🟠 CVE-2026-45615 - High (8.2)

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsing a maliciously crafted, zero-length OER payload...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44973
(8.1 HIGH)

EPSS: 0.05%

updated 2026-05-29T16:32:14.400000

1 posts

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was not originally designed to provide a strong security boundary, some of these issues were inconsisten

thehackerwire@mastodon.social at 2026-05-28T23:01:19.000Z ##

🟠 CVE-2026-44973 - High (8.1)

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35674
(8.8 HIGH)

EPSS: 0.00%

updated 2026-05-29T16:29:34.540000

2 posts

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to bypass operator.approvals and operator.admin scope requirements, enabling unauthorized plugin, config, MCP, allowlist, and ACP mutations.

thehackerwire@mastodon.social at 2026-05-29T17:01:13.000Z ##

🟠 CVE-2026-35674 - High (8.8)

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T17:01:13.000Z ##

🟠 CVE-2026-35674 - High (8.8)

OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35630
(8.0 HIGH)

EPSS: 0.00%

updated 2026-05-29T16:29:34.540000

2 posts

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval requests without proper authorization.

thehackerwire@mastodon.social at 2026-05-29T17:01:03.000Z ##

🟠 CVE-2026-35630 - High (8)

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T17:01:03.000Z ##

🟠 CVE-2026-35630 - High (8)

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-10067
(8.8 HIGH)

EPSS: 0.00%

updated 2026-05-29T16:29:11.350000

2 posts

A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.

thehackerwire@mastodon.social at 2026-05-29T18:00:19.000Z ##

🟠 CVE-2026-10067 - High (8.8)

A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. This project is superseded by FreshTomato...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T18:00:19.000Z ##

🟠 CVE-2026-10067 - High (8.8)

A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. This project is superseded by FreshTomato...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45104
(7.5 HIGH)

EPSS: 0.04%

updated 2026-05-29T16:25:57.843000

1 posts

MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFilter/> — it assumes msSLDParseRule added one class. When the rule has no symbolizer (a structurally valid SLD), msSLDParseRule adds zero, and _SLDApplyRuleValues ends up indexing _class[-1], resulting i

thehackerwire@mastodon.social at 2026-05-28T03:01:24.000Z ##

🟠 CVE-2026-45104 - High (7.5)

MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any carrying — it assumes msSLDParseRule added one class. When the rule ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-32847
(7.5 HIGH)

EPSS: 0.08%

updated 2026-05-29T16:19:35.753000

1 posts

DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full_path:path} endpoint. Attackers can bypass Starlette's path normalization by encoding slashes as %2F and dots as %2E%2E, causing the joined path to trave

thehackerwire@mastodon.social at 2026-05-28T21:00:21.000Z ##

🟠 CVE-2026-32847 - High (7.5)

DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46839
(9.9 CRITICAL)

EPSS: 0.04%

updated 2026-05-29T16:16:30.780000

1 posts

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services. While the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks

thehackerwire@mastodon.social at 2026-05-28T22:01:46.000Z ##

🔴 CVE-2026-46839 - Critical (9.9)

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Ser...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46835
(7.5 HIGH)

EPSS: 0.04%

updated 2026-05-29T16:16:30.520000

1 posts

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servic

thehackerwire@mastodon.social at 2026-05-28T22:01:26.000Z ##

🟠 CVE-2026-46835 - High (7.5)

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service....

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9739
(0 None)

EPSS: 0.02%

updated 2026-05-29T15:42:56.873000

1 posts

Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. However, the hardcoded `Access-Control-Allow-Origin: *` header in the SSE initialization handler was inadvertently retained. This vulnerability specifically impacts users connecting via Toolbox using SSE un

offseq@infosec.exchange at 2026-05-28T00:00:38.000Z ##

🚨 CRITICAL: CVE-2026-9739 in Google MCP Toolbox for Databases (CVSS 9.4) allows DNS rebinding via a permissive cross-domain policy in SSE. No patch yet — restrict untrusted domains & monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #Google

##

CVE-2026-32999
(9.0 CRITICAL)

EPSS: 0.05%

updated 2026-05-29T15:39:34.620000

1 posts

Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.

thehackerwire@mastodon.social at 2026-05-28T07:00:21.000Z ##

🔴 CVE-2026-32999 - Critical (9)

Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44887
(9.8 CRITICAL)

EPSS: 0.21%

updated 2026-05-29T15:29:42.387000

1 posts

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be injected into pialert.conf. Since the background scan daemon loads this file via Python's exec(), injected code executes as the daemon process. With web protection disabled (the default configuration), no authentication is require

thehackerwire@mastodon.social at 2026-05-28T16:01:00.000Z ##

🔴 CVE-2026-44887 - Critical (9.8)

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be injected into pialert.conf. Since the background scan daemon loads this file ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45083
(9.8 CRITICAL)

EPSS: 0.04%

updated 2026-05-29T15:29:42.387000

1 posts

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted an arbitrary Solr streaming expression from unauthenticated network clients and forwarded it to the backend Solr server without restriction. An attacker could read the complete Solr index and, in defau

thehackerwire@mastodon.social at 2026-05-27T23:00:34.000Z ##

🔴 CVE-2026-45083 - Critical (9.8)

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted an arbitrary Solr streaming expression from unau...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45578
(8.8 HIGH)

EPSS: 0.00%

updated 2026-05-29T15:06:44.207000

1 posts

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single-quoting each argument but never calling escapeshellarg(). A ' in any of the three interpolated values ($users_id, $m3u8, $obj->liveTransmitionHistory_id

thehackerwire@mastodon.social at 2026-05-29T15:00:56.000Z ##

🟠 CVE-2026-45578 - High (8.8)

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44850
(8.5 HIGH)

EPSS: 0.03%

updated 2026-05-29T15:06:44.207000

1 posts

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer offers an environment-level Disable bind mounts for non-administrators security setting that blocks regular users from binding host paths into containers they crea

thehackerwire@mastodon.social at 2026-05-28T23:00:28.000Z ##

🟠 CVE-2026-44850 - High (8.5)

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer offers an ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7480
(0 None)

EPSS: 0.01%

updated 2026-05-29T14:46:09.837000

1 posts

An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism. Refer to the 'Security Update for ASUS System Control Interface' section on the ASUS Security Advisory for more information.

offseq@infosec.exchange at 2026-05-29T03:00:26.000Z ##

ASUS System Control Interface (≤3.1.59.0) hit by HIGH-severity vuln (CVE-2026-7480): local attackers can escalate to SYSTEM via crafted RPC calls. No patch yet — restrict local access & monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #ASUS #Infosec

##

CVE-2026-46510
(8.2 HIGH)

EPSS: 0.00%

updated 2026-05-29T14:16:31.807000

1 posts

form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, or prototype. A single HTTP form field whose name starts with __proto__[...] causes the library to mutate Object.prototype, which is a prototype pollution primitive of the entire Node.js process. This

thehackerwire@mastodon.social at 2026-05-29T15:00:10.000Z ##

🟠 CVE-2026-46510 - High (8.2)

form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, or prototype. A single HTTP form field whose nam...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35675
(8.2 HIGH)

EPSS: 0.11%

updated 2026-05-29T14:16:26.403000

1 posts

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via email, and achieve complete account takeover including administrative access.

thehackerwire@mastodon.social at 2026-05-28T17:02:23.000Z ##

🟠 CVE-2026-35675 - High (8.2)

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-38703
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-05-29T14:09:03.913000

1 posts

A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.

thehackerwire@mastodon.social at 2026-05-28T21:01:20.000Z ##

🔴 CVE-2026-38703 - Critical (9.8)

A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerabil...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-38707
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-05-29T14:08:41.327000

1 posts

A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.

cR0w@infosec.exchange at 2026-05-28T18:41:42.000Z ##

Anyone know anything about these router vulns? I'm especially interested in CVE-2026-38704, a command injection in the Wireguard function, and CVE-2026-38707, a command injection in the IPSEC function.

inhand.com/wp-content/uploads/

##

CVE-2026-49127
(8.6 HIGH)

EPSS: 0.06%

updated 2026-05-29T14:07:47.980000

1 posts

Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue two MPD commands referencing a malicious HTTP audio source to cause the unpack loop to write 1366 entries int

thehackerwire@mastodon.social at 2026-05-28T20:59:58.000Z ##

🟠 CVE-2026-49127 - High (8.6)

Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-3655
(9.8 CRITICAL)

EPSS: 0.26%

updated 2026-05-29T13:09:05.450000

1 posts

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The `idehweb_lwp_activate_through_firebase()` function validates that a Firebase OTP sessio

offseq@infosec.exchange at 2026-05-29T09:00:37.000Z ##

CVE-2026-3655 (CRITICAL, CVSS 9.8): glboy OTP Login plugin (v1.8.50 – 1.8.60) suffers from improper authentication via Firebase OTP. Attackers can log in as any user/admin. Patch now! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #Vulnerability

##

CVE-2026-8732
(9.8 CRITICAL)

EPSS: 0.07%

updated 2026-05-29T07:20:15

1 posts

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonc

1 repos

https://github.com/xShadow-Here/CVE-2026-8732

offseq@infosec.exchange at 2026-05-29T07:30:25.000Z ##

🚨 CVE-2026-8732: WP Maps Pro ≤6.1.0 has a CRITICAL flaw (CVSS 9.8). Unauthenticated attackers can create admin accounts via an AJAX action protected only by a public nonce. Full site takeover risk. Disable or remove plugin until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

CVE-2026-8070(CVSS UNKNOWN)

EPSS: 0.01%

updated 2026-05-29T03:31:14

1 posts

Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the '  Security Update for Armoury Crate App   ' section on the ASUS Security Advisory for more information.

offseq@infosec.exchange at 2026-05-29T04:30:25.000Z ##

🔒 CVE-2026-8070 (HIGH): ASUS Armoury Crate lets local attackers bypass driver validation for physical memory access. Patch pending — restrict local access and monitor for abuse. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #ASUS #InfoSec

##

CVE-2026-46833
(9.0 CRITICAL)

EPSS: 0.04%

updated 2026-05-29T02:47:03.023000

1 posts

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerabi

thehackerwire@mastodon.social at 2026-05-28T22:00:24.000Z ##

🔴 CVE-2026-46833 - Critical (9)

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Servic...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47333
(7.8 HIGH)

EPSS: 0.01%

updated 2026-05-29T02:45:36.283000

1 posts

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.

thehackerwire@mastodon.social at 2026-05-28T20:00:29.000Z ##

🟠 CVE-2026-47333 - High (7.8)

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unpri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-49128
(7.5 HIGH)

EPSS: 0.11%

updated 2026-05-29T00:39:36

1 posts

Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 within the local storage plugin, where the on-disk path is constructed by joining the storage root with a user-supplied URI as plain strings without canonicalization, allowing '..' segments to survive into the resolved path and be flattened by the kernel

thehackerwire@mastodon.social at 2026-05-28T21:00:09.000Z ##

🟠 CVE-2026-49128 - High (7.5)

Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 within the local storage plugin, where the on-disk path is constructed by joining the storage root wit...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8809
(9.8 CRITICAL)

EPSS: 0.19%

updated 2026-05-29T00:38:45

1 posts

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with no authentication or integrity verification — to select a cleanup branch that sil

thehackerwire@mastodon.social at 2026-05-29T00:00:00.000Z ##

🔴 CVE-2026-8809 - Critical (9.8)

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditiona...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39929
(7.5 HIGH)

EPSS: 0.11%

updated 2026-05-28T22:16:58.693000

1 posts

Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially crafted UDP packet. Attackers can send a malformed packet with an invalid memory address at offset 0x4 in the payload to trigger an access violation and c

thehackerwire@mastodon.social at 2026-05-29T00:00:10.000Z ##

🟠 CVE-2026-39929 - High (7.5)

Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially c...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9645
(9.9 CRITICAL)

EPSS: 0.05%

updated 2026-05-28T21:32:17

1 posts

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.

thehackerwire@mastodon.social at 2026-05-28T22:00:12.000Z ##

🔴 CVE-2026-9645 - Critical (9.9)

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47331
(7.8 HIGH)

EPSS: 0.01%

updated 2026-05-28T21:32:10

1 posts

Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution.

thehackerwire@mastodon.social at 2026-05-28T20:00:48.000Z ##

🟠 CVE-2026-47331 - High (7.8)

Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code exec...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-4944
(8.8 HIGH)

EPSS: 0.09%

updated 2026-05-28T21:32:10

1 posts

vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and `vllm/model_executor/models/kimi_k25.py`). This bypasses the user's explicit `--trust-remote-code=False` setting, enabling remote code execution via malicious HuggingFace model repositories. This issue

thehackerwire@mastodon.social at 2026-05-28T20:00:38.000Z ##

🟠 CVE-2026-4944 - High (8.8)

vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and `vllm/model_executor/models/kimi_k25.py`). This ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-43898
(10.0 CRITICAL)

EPSS: 0.05%

updated 2026-05-28T20:16:23.810000

1 posts

SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That callback can then be invoked with attacker-controlled fake context and obj values to extract blocked host statics, recover the real host Function constructor, and execute arbitrary host JavaScript. This

thehackerwire@mastodon.social at 2026-05-28T19:02:01.000Z ##

🔴 CVE-2026-43898 - Critical (10)

SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That callback can then be invoked with attacker-control...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47759
(8.7 HIGH)

EPSS: 0.03%

updated 2026-05-28T19:19:37.803000

1 posts

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. This vulnerability is fixed in 5.11.1, 7.9.3, and 8.5.1.

thehackerwire@mastodon.social at 2026-05-28T17:00:19.000Z ##

🟠 CVE-2026-47759 - High (8.7)

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values tha...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47760
(8.7 HIGH)

EPSS: 0.03%

updated 2026-05-28T19:19:03.740000

1 posts

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in 7.1.0.

thehackerwire@mastodon.social at 2026-05-28T17:00:31.000Z ##

🟠 CVE-2026-47760 - High (8.7)

TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitizati...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46509
(8.2 HIGH)

EPSS: 0.04%

updated 2026-05-28T19:16:39.280000

1 posts

deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not be exposed as user input. This vulnerability is fixed in 1.0.3.

thehackerwire@mastodon.social at 2026-05-28T20:01:38.000Z ##

🟠 CVE-2026-46509 - High (8.2)

deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not be exposed as user input. This vulnerability is f...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46414
(8.8 HIGH)

EPSS: 0.04%

updated 2026-05-28T18:56:36.823000

2 posts

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fields in task messages. A client connection can register as a normal device, but later send a TASK message claiming client_type="constellation" and target_id=<victim-device-id>. The server trusts the rol

offseq@infosec.exchange at 2026-05-28T03:00:27.000Z ##

🛡️ CVE-2026-46414 (HIGH): Auth bypass in Microsoft UFO 3.0.1-4-ge2626659. Attackers can spoof roles & hijack device tasks via WebSocket. No patch yet — restrict server token & trusted client access. More: radar.offseq.com/threat/cve-20 #OffSeq #CVE202646414 #MicrosoftUFO #Vuln

##

thehackerwire@mastodon.social at 2026-05-28T00:00:21.000Z ##

🟠 CVE-2026-46414 - High (8.8)

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fields in task messages. A client connection can re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45322
(7.8 HIGH)

EPSS: 0.06%

updated 2026-05-28T18:56:36.823000

1 posts

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in the shell action replay path. In affected releases, ShellReceiver.run_shell() passes a command string from action parameters directly to subprocess.Popen() with shell=True and executable=powershell.exe

thehackerwire@mastodon.social at 2026-05-28T00:00:02.000Z ##

🟠 CVE-2026-45322 - High (7.8)

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in the shell action replay path. In affected releas...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45311
(9.6 CRITICAL)

EPSS: 0.04%

updated 2026-05-28T18:40:37.990000

1 posts

CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user approval prompt. cargo test compiles and executes arbitrary code: test binaries, build.rs build scripts, and proc macros. While auto-approving test execution is a deliberate design choice, it creates

thehackerwire@mastodon.social at 2026-05-28T19:00:11.000Z ##

🔴 CVE-2026-45311 - Critical (9.6)

CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user approval prompt. cargo test compiles and execut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-38702
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-05-28T18:30:39

1 posts

A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.

thehackerwire@mastodon.social at 2026-05-28T21:01:09.000Z ##

🔴 CVE-2026-38702 - Critical (9.8)

A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerabil...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9095
(8.1 HIGH)

EPSS: 0.04%

updated 2026-05-28T18:30:39

1 posts

Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is no assertion ID cache, OneTimeUse condition enforcement, or replay detection anywhere in the SAML SP code path. As a result, an attacker can replay a pr

thehackerwire@mastodon.social at 2026-05-28T21:00:58.000Z ##

🟠 CVE-2026-9095 - High (8.1)

Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-38704
(9.8 CRITICAL)

EPSS: 0.27%

updated 2026-05-28T18:30:39

1 posts

A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.

cR0w@infosec.exchange at 2026-05-28T18:41:42.000Z ##

Anyone know anything about these router vulns? I'm especially interested in CVE-2026-38704, a command injection in the Wireguard function, and CVE-2026-38707, a command injection in the IPSEC function.

inhand.com/wp-content/uploads/

##

CVE-2026-49238
(8.4 HIGH)

EPSS: 0.02%

updated 2026-05-28T18:00:33.730000

1 posts

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The function performs a plain string prefix comparison on requested paths without path separator validation or

thehackerwire@mastodon.social at 2026-05-28T14:59:58.000Z ##

🟠 CVE-2026-49238 - High (8.4)

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path fu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44326
(9.4 CRITICAL)

EPSS: 0.04%

updated 2026-05-28T16:25:38.687000

1 posts

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, patch, and delete traffic-influence subscriptions either with no Authorization header at all, or with a forged bearer token (e.g. Authorization: Beare

thehackerwire@mastodon.social at 2026-05-27T18:00:52.000Z ##

🔴 CVE-2026-44326 - Critical (9.4)

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, rea...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48151
(7.5 HIGH)

EPSS: 0.03%

updated 2026-05-28T16:16:28.793000

1 posts

Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for all paths matching /api/webhooks/schema. As a result, an unauthenticated caller can update the body schema for a known webhook and mutate the corresponding automation trigger output schema. This vulne

thehackerwire@mastodon.social at 2026-05-27T19:00:31.000Z ##

🟠 CVE-2026-48151 - High (7.5)

Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for all paths matching /api/webhooks/schema. As a r...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-35671
(8.8 HIGH)

EPSS: 0.04%

updated 2026-05-28T14:19:43

1 posts

### Summary An Insecure Direct Object Reference (IDOR) vulnerability in phpMyFAQ's Admin API allows any authenticated administrator to change the password of any user account, including SuperAdmin accounts (userId=1), without authorization verification. An attacker with a low-privilege admin account can escalate privileges to full SuperAdmin control by simply changing the target user's ID in the A

thehackerwire@mastodon.social at 2026-05-28T17:02:00.000Z ##

🟠 CVE-2026-35671 - High (8.8)

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with lo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44711
(7.9 HIGH)

EPSS: 0.02%

updated 2026-05-28T14:16:21.263000

1 posts

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption. This vulnerability is fixed in 0.8.7.

thehackerwire@mastodon.social at 2026-05-27T22:00:30.000Z ##

🟠 CVE-2026-44711 - High (7.9)

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption. This vulnerability is fixed in 0.8.7.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44635
(7.5 HIGH)

EPSS: 0.05%

updated 2026-05-28T14:16:20.450000

1 posts

Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlled input flows into eb.ref(col, '->$').key(input) or .at(input) — including type-safe code where the JSON column is shaped like Record<string, T> so K extends string is the inferred type — every dot bec

thehackerwire@mastodon.social at 2026-05-28T17:02:41.000Z ##

🟠 CVE-2026-44635 - High (7.5)

Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlled input flows into eb.ref(col, '->$').key(input)...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44709
(7.8 HIGH)

EPSS: 0.02%

updated 2026-05-28T13:57:25.390000

1 posts

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment variable and executes it directly without any validation. Any process that can set environment variables before pamusb-pinentry is invoked can point PINENTRY_FALLBACK_APP at an arbitrary binary or script and have it executed with the privile

thehackerwire@mastodon.social at 2026-05-27T22:01:50.000Z ##

🟠 CVE-2026-44709 - High (7.8)

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment variable and executes it directly without any validation. Any process that can set envir...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9227
(8.8 HIGH)

EPSS: 0.14%

updated 2026-05-28T13:45:25.260000

1 posts

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only verifies whether the filename contains the string '.json' rather than confirming the filename ends with a .json extension, allowing double-extension filenames

thehackerwire@mastodon.social at 2026-05-28T15:01:19.000Z ##

🟠 CVE-2026-9227 - High (8.8)

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only veri...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9009
(8.8 HIGH)

EPSS: 0.24%

updated 2026-05-28T13:45:25.260000

2 posts

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due to passing the attacker-supplied 'callback_raw' shortcode attribute directly into call_user_func() with no sanitization or allowlist validation, relying solely on an is_callable() check that permits dan

offseq@infosec.exchange at 2026-05-28T07:30:27.000Z ##

⚠️ CVE-2026-9009 (HIGH): Crawlomatic Multipage Scraper Post Generator for WordPress lets author+ users trigger arbitrary PHP code via unsafe shortcodes. No patch yet — restrict author access & consider disabling plugin. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

##

thehackerwire@mastodon.social at 2026-05-28T07:00:01.000Z ##

🟠 CVE-2026-9009 - High (8.8)

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due to passing the attacker-supplied 'callback_raw' s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8915
(8.8 HIGH)

EPSS: 0.02%

updated 2026-05-28T13:44:54.327000

2 posts

Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31.

thehackerwire@mastodon.social at 2026-05-28T03:00:43.000Z ##

🟠 CVE-2026-8915 - High (8.8)

Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.

This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-05-28T01:30:26.000Z ##

🔔 CVE-2026-8915 (HIGH): Out-of-bounds write in Samsung Open Source Escargot (commit 36f5fb58...) enables buffer overflow risks — system compromise possible. No patch yet; monitor advisories & restrict access. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Escargot

##

CVE-2026-7862
(8.6 HIGH)

EPSS: 0.04%

updated 2026-05-28T12:33:02

1 posts

The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gateway credentials, and for applicable payment methods, to redirect refunded funds to an attacker-controlled bank account.

thehackerwire@mastodon.social at 2026-05-28T15:01:04.000Z ##

🟠 CVE-2026-7862 - High (8.6)

The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request handler, allowing unauthenticated attackers to initiate refunds against any WooCommerce order using the merchant's payment gat...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-4408
(9.0 None)

EPSS: 0.23%

updated 2026-05-28T09:31:27

2 posts

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execu

thehackerwire@mastodon.social at 2026-05-28T15:00:33.000Z ##

🔴 CVE-2026-4408 - Critical (9)

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the cli...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

offseq@infosec.exchange at 2026-05-28T09:00:28.000Z ##

🚨 CRITICAL: CVE-2026-4408 in Red Hat Enterprise Linux 10 via Samba misconfig enables remote command execution if "check password script" uses %u. Audit your configs now! Details: radar.offseq.com/threat/cve-20 #OffSeq #Linux #Samba #Infosec

##

CVE-2026-6455
(8.1 HIGH)

EPSS: 0.04%

updated 2026-05-28T09:31:26

1 posts

The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the nonce check is only executed when _wpnonce is present in the POST body, allowing it to be trivially

thehackerwire@mastodon.social at 2026-05-28T16:00:40.000Z ##

🟠 CVE-2026-6455 - High (8.1)

The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce ver...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-7802
(8.8 HIGH)

EPSS: 0.06%

updated 2026-05-28T06:31:16

1 posts

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite an administrator's user_pass, user_email, first_name, last_n

thehackerwire@mastodon.social at 2026-05-28T07:00:12.000Z ##

🟠 CVE-2026-7802 - High (8.8)

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes i...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-9789(CVSS UNKNOWN)

EPSS: 0.02%

updated 2026-05-28T03:31:21

1 posts

A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the service does not check the caller's privileges before running file deletion comma

offseq@infosec.exchange at 2026-05-28T04:30:26.000Z ##

🛡️ CVE-2026-9789 (HIGH, CVSS 8.5): Acer NitroSense V3 (≤3.01.3001) local users can delete arbitrary files via PSAdminAgent's weak pipe ACL. No patch yet — restrict access, monitor activity. More: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Acer #PrivilegeEscalation

##

CVE-2026-9208
(8.8 HIGH)

EPSS: 0.07%

updated 2026-05-28T00:30:35

1 posts

Tanium addressed an unauthorized code execution vulnerability in Connect.

thehackerwire@mastodon.social at 2026-05-27T23:00:25.000Z ##

🟠 CVE-2026-9208 - High (8.8)

Tanium addressed an unauthorized code execution vulnerability in Connect.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45332
(7.5 HIGH)

EPSS: 0.04%

updated 2026-05-27T21:32:32

1 posts

### Summary A Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account with a single POST request. The `/_api/user-collection/create-first-user` setup endpoint remains publicly accessible once initial configuration is complete and returns full serialized user data in the JSON response body. ### Details Affected

thehackerwire@mastodon.social at 2026-05-28T20:01:28.000Z ##

🟠 CVE-2026-45332 - High (7.5)

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcrypt password hash of every administrator account...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8359
(7.5 HIGH)

EPSS: 0.05%

updated 2026-05-27T21:31:33

1 posts

When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule function in the dll would be called to set up a "module" object for that module. However, WOSHttpStatusModule.dll is not present in the installation. As a result, a function pointer to WOSBin_LoadHttpModule (which would have bee

thehackerwire@mastodon.social at 2026-05-27T23:01:29.000Z ##

🟠 CVE-2026-8359 - High (7.5)

When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule function in the dll would be called to set up a "module" object for that mo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8362
(9.8 CRITICAL)

EPSS: 0.04%

updated 2026-05-27T21:31:32

1 posts

A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome

thehackerwire@mastodon.social at 2026-05-28T00:01:07.000Z ##

🔴 CVE-2026-8362 - Critical (9.8)

A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8361
(7.5 HIGH)

EPSS: 0.04%

updated 2026-05-27T21:31:32

1 posts

A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome

thehackerwire@mastodon.social at 2026-05-28T00:00:57.000Z ##

🟠 CVE-2026-8361 - High (7.5)

A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8360
(7.5 HIGH)

EPSS: 0.04%

updated 2026-05-27T21:31:32

1 posts

Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The returned NULL pointer is not checked before being dereferenced.

thehackerwire@mastodon.social at 2026-05-27T23:01:39.000Z ##

🟠 CVE-2026-8360 - High (7.5)

Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48027
(9.8 CRITICAL)

EPSS: 26.85%

updated 2026-05-27T20:34:24.850000

3 posts

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx C

kev_Stalker@infosec.exchange at 2026-05-28T18:56:25.000Z ##

CVE-2026-48027 - Changed to Known Ransomware Status

Nx Console Embedded Malicious Code VulnerabilityVendor: NxProduct: Nx ConsoleNx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.Status changed from Unknown to Known for ransomware nvd.nist.gov/vuln/detail/CVE-2

##

secdb@infosec.exchange at 2026-05-27T20:00:15.000Z ##

🚨 [CISA-2026:0527] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-45321 (secdb.nttzen.cloud/cve/detail/)
- Name: TanStack Unspecified Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TanStack
- Product: TanStack
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/TanStack/router/sec ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-48027 (secdb.nttzen.cloud/cve/detail/)
- Name: Nx Console Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Nx
- Product: Nx Console
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/nrwl/nx-console/sec ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8398 (secdb.nttzen.cloud/cve/detail/)
- Name: Daemon Tools Lite Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Daemon
- Product: Daemon Tools Lite
- Notes: blog.daemon-tools.cc/post/secu ; nvd.nist.gov/vuln/detail/CVE-2

#SecDB #InfoSec #CVE #CISA_KEV #cisa_20260527 #cisa20260527 #cve_2026_45321 #cve_2026_48027 #cve_2026_8398 #cve202645321 #cve202648027 #cve20268398

##

cisakevtracker@mastodon.social at 2026-05-27T18:00:49.000Z ##

CVE ID: CVE-2026-48027
Vendor: Nx
Product: Nx Console
Date Added: 2026-05-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-45716
(8.8 HIGH)

EPSS: 0.03%

updated 2026-05-27T20:16:39.200000

1 posts

Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user with builder permissions to access it. When SMTP email is not configured (the default for self-hosted Budibase instances), this endpoint bypasses the admin-restricted invite flow and directly creates users via bulkCreate, a

thehackerwire@mastodon.social at 2026-05-28T18:01:00.000Z ##

🟠 CVE-2026-45716 - High (8.8)

Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user with builder permissions to access it. When SMTP email is not configur...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45108
(8.4 HIGH)

EPSS: 0.07%

updated 2026-05-27T20:16:38.550000

1 posts

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, Himmelblau contained an authentication bypass vulnerability in the Device Authorization Grant (DAG) flow that allowed a user within the same Entra ID domain to obtain a local Unix session as another user by providing their own valid credentials. The vulnerability existed in the t

thehackerwire@mastodon.social at 2026-05-28T05:00:29.000Z ##

🟠 CVE-2026-45108 - High (8.4)

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, Himmelblau contained an authentication bypass vulnerability in the Device Authorization Grant (DAG) flow that allowed a user wi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48153
(8.5 HIGH)

EPSS: 0.03%

updated 2026-05-27T19:44:35.987000

1 posts

Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-supplied URL with plain node-fetch, skipping the blacklist.isBlacklisted check that every other outbound fetch path in the codebase uses. The Joi schema for the OAuth2 URL has no scheme or host restriction. This vulnerability is fixed in 3.39.0.

thehackerwire@mastodon.social at 2026-05-27T19:01:32.000Z ##

🟠 CVE-2026-48153 - High (8.5)

Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-supplied URL with plain node-fetch, skipping the blacklist.isBlacklisted check that every other outbound fetch path in the codeba...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45659
(8.8 HIGH)

EPSS: 0.62%

updated 2026-05-27T18:32:54.337000

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

2 repos

https://github.com/HORKimhab/CVE-2026-45659

https://github.com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE

hackmag@infosec.exchange at 2026-05-28T15:00:03.000Z ##

⚪️ Microsoft Fixes RCE Vulnerability in SharePoint

🗨️ Microsoft engineers have released out-of-band patches for an RCE vulnerability in SharePoint Server (CVE-2026-45659). The issue has a CVSS score of 8.8 and affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Exploiting it only requires…

🔗 hackmag.com/news/cve-2026-4565

#news

##

CVE-2015-2808
(10.0 CRITICAL)

EPSS: 23.36%

updated 2026-05-27T18:32:34

1 posts

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force appro

TomSellers@infosec.exchange at 2026-05-27T18:22:44.000Z ##

RE: infosec.exchange/@perfect10_bo

So CVE-2015-2808 (RC4 weaknesses in TLS) got bumped to 10.0 today due to CISA enrichment...

#Security

##

CVE-2025-14713
(7.5 HIGH)

EPSS: 0.03%

updated 2026-05-27T14:54:20.160000

1 posts

An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.

thehackerwire@mastodon.social at 2026-05-27T17:02:25.000Z ##

🟠 CVE-2025-14713 - High (7.5)

An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46372
(8.5 HIGH)

EPSS: 0.00%

updated 2026-05-27T06:01:20

2 posts

## Resolution SillyTavern 1.18.0 added a generic server-side request filter (Private Request Whitelisting). Since we expect users to use the application in a trusted environment, the filter is disabled by default, however it is strongly advised to be enabled and properly configured when an instance is being hosted over a network, as suggested by a console warning message and an officially publish

Nuclei template

thehackerwire@mastodon.social at 2026-05-29T23:00:14.000Z ##

🟠 CVE-2026-46372 - High (8.5)

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searxng, which ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T23:00:14.000Z ##

🟠 CVE-2026-46372 - High (8.5)

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searxng, which ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-5426
(9.1 CRITICAL)

EPSS: 0.07%

updated 2026-05-26T19:16:29.123000

2 posts

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks

1 repos

https://github.com/HORKimhab/CVE-2026-5426

beyondmachines1@infosec.exchange at 2026-05-27T20:01:06.000Z ##

KnowledgeDeliver Zero-Day Flaw Exploited to Deploy Web Shells

KnowledgeDeliver LMS installations are being targeted by a zero-day deserialization vulnerability (CVE-2026-5426) caused by hardcoded machine keys, allowing attackers to deploy web shells and Cobalt Strike backdoors.

**If you run Digital Knowledge's KnowledgeDeliver LMS, immediately replace the default ASP.NET machine keys in your web.config with unique, cryptographically strong ones to block these attacks. If possible, restrict portal access to trusted IP ranges, and monitor Windows Application logs for Event ID 1316 (ViewState verification failures).**
#cybersecurity #infosec #attack #activeexploit
beyondmachines.net/event_detai

##

Mozilla@activitypub.awakari.com at 2026-05-27T18:59:43.000Z ## 🚩 Critical KnowledgeDeliver RCE (CVE-2026-5426) abused via shared ASP.NET machine keys to deliver web shells and Cobalt Strike KnowledgeDeliver exploit (CVE-2026-5426) enables RCE via ViewState ...

#TIGR #malware #vulnerability

Origin | Interest | Match ##

CVE-2026-43284
(7.8 HIGH)

EPSS: 25.56%

updated 2026-05-26T18:32:39

1 posts

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when

33 repos

https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284

https://github.com/AtlasVector/Dirty-Frag-CVE-2026-43284

https://github.com/ryan2929/CVE-2026-43284-

https://github.com/LucasPDiniz/CVE-2026-43284

https://github.com/dixyes/dirtypatch

https://github.com/XRSecCD/202605_dirty_frag

https://github.com/jayhutajulu1/CVE-2026-43284-DirtyFrag-PoC

https://github.com/krisiasty/vcheck

https://github.com/metalx1993/dirtyfrag-patches

https://github.com/haydenjames/dirty-frag-check

https://github.com/FrosterDL/CVE-2026-43284

https://github.com/attaattaatta/CVE-2026-43500

https://github.com/kuniyal08/Dirty-Frag-CVE-2026-43284

https://github.com/gagaltotal/CVE-2026-43284-CVE-2026-43500-scan

https://github.com/0xBlackash/CVE-2026-43284

https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC

https://github.com/ChernStepanov/DirtyFrag-for-dummies

https://github.com/liamromanis101/DirtyFrag-Detector

https://github.com/scriptzteam/Paranoid-Dirty-Frag-CVE-2026-43284

https://github.com/AK777177/Dirty-Frag-Analysis

https://github.com/mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4

https://github.com/suominen/CVE-2026-43284

https://github.com/Aiyakami/rust_dirtyfrag

https://github.com/DylanClaudio/Reporte-de-Escalada-de-Privilegios-Local-Dirty-Frag

https://github.com/grabesec/XCP_ng_CVE-2026-43284_tester

https://github.com/Koshmare-Blossom/DirtyFrag-go

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/whosfault/CVE-2026-43284

https://github.com/linnemanlabs/dirtyfrag-arm64

https://github.com/0xlane/pagecache-guard

https://github.com/xd20111/CVE-2026-43284

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

linux@activitypub.awakari.com at 2026-05-28T03:43:38.000Z ## Dirty Frag: a kernel zero-day vs. container and microVM sandboxes On May 7, Hyunwoo Kim (V4bel) disclosed Dirty Frag — two Linux kernel vulnerabilities (CVE-2026-43284 and CVE-2026-43500) that gi...


Origin | Interest | Match ##

CVE-2026-47125
(8.8 HIGH)

EPSS: 0.00%

updated 2026-05-23T00:16:58

2 posts

## Summary The `PUT /api/environments/{id}/templates/variables` endpoint, which writes the system-wide `.env.global` file used for variable substitution in every project's compose file, is missing an admin authorization check. Any authenticated non-admin user can call this endpoint with their bearer token or API key and overwrite the global environment variables that are merged into every project

thehackerwire@mastodon.social at 2026-05-29T19:00:21.000Z ##

🟠 CVE-2026-47125 - High (8.8)

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file used for variable substitution in eve...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T19:00:21.000Z ##

🟠 CVE-2026-47125 - High (8.8)

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file used for variable substitution in eve...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-41091
(7.8 HIGH)

EPSS: 6.98%

updated 2026-05-20T19:06:36.850000

1 posts

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

2 repos

https://github.com/0xBlackash/CVE-2026-41091

https://github.com/ridhinva/defender-vulnerability-scanner

hackmag@infosec.exchange at 2026-05-27T18:30:03.000Z ##

⚪️ Microsoft patches UnDefend and RedSun 0‑day vulnerabilities

🗨️ Microsoft developers have released out-of-band updates to fix two 0‑day vulnerabilities in Microsoft Defender that are already being used in real-world attacks. These are the bugs CVE-2026-41091 and CVE-2026-45498, known as RedSun and UnDefend. The first issue (7.8 on the…

🔗 hackmag.com/news/undefend-reds

#news

##

CVE-2026-45498
(4.0 None)

EPSS: 4.11%

updated 2026-05-20T18:31:35

1 posts

Microsoft Defender Denial of Service Vulnerability

1 repos

https://github.com/ridhinva/defender-vulnerability-scanner

hackmag@infosec.exchange at 2026-05-27T18:30:03.000Z ##

⚪️ Microsoft patches UnDefend and RedSun 0‑day vulnerabilities

🗨️ Microsoft developers have released out-of-band updates to fix two 0‑day vulnerabilities in Microsoft Defender that are already being used in real-world attacks. These are the bugs CVE-2026-41091 and CVE-2026-45498, known as RedSun and UnDefend. The first issue (7.8 on the…

🔗 hackmag.com/news/undefend-reds

#news

##

CVE-2026-45137
(8.2 HIGH)

EPSS: 0.04%

updated 2026-05-19T16:08:42

1 posts

### Summary An logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumptions resulting in potential arbitrary cpi in programs that invoke system program instructions. ### Details In the TryFrom<&'a AccountInfo<'a>> implementation for Program<'a, T>, the id of T is compared with Pubkey::default() to check whether anchor should allow any

thehackerwire@mastodon.social at 2026-05-27T22:01:41.000Z ##

🟠 CVE-2026-45137 - High (8.2)

Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, an logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumpti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-31431
(7.8 HIGH)

EPSS: 2.23%

updated 2026-05-18T18:32:28

5 posts

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just

100 repos

https://github.com/qi4L/CVE-2026-31431-Container-Escape

https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script

https://github.com/bigwario/copy-fail-CVE-2026-31431-C

https://github.com/AliHzSec/CVE-2026-31431

https://github.com/sudoytang/copyfail-arm64

https://github.com/Sl4cK0TH/CVE-2026-31431-PoC

https://github.com/AdityaBhatt3010/CVE-2026-31431

https://github.com/bootsareme/copyfail-deconstructed

https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit

https://github.com/wvverez/CVE-2026-31431-Copy-Fail

https://github.com/xn0kkx/CVE-2026-31431_CopyFail_LinuxKernel_LPE

https://github.com/RoflSecurity/copy_fail

https://github.com/ZephrFish/CopyFail-CVE-2026-31431

https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431

https://github.com/Boos4721/copyfail-rs

https://github.com/wesmar/CVE-2026-31431

https://github.com/professional-slacker/alg_check

https://github.com/suominen/CVE-2026-31431

https://github.com/sgkdev/ptrace_may_dream

https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite

https://github.com/povzayd/CVE-2026-31431

https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431

https://github.com/philfry/cve-2026-31431-ftrace

https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe

https://github.com/lonelyor/CVE-2026-31431-exp

https://github.com/MrAriaNet/cPanel-Fix

https://github.com/sec17br/CVE-2026-31431-Copy-Fail

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail

https://github.com/rootsecdev/cve_2026_31431

https://github.com/0xBlackash/CVE-2026-31431

https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431

https://github.com/Iamliuxiaozhen/copy_fail

https://github.com/guiimoraes/CVE-2026-31431

https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431

https://github.com/adysec/cve-2026-31431

https://github.com/abdullaabdullazade/CVE-2026-31431

https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit

https://github.com/sgkdev/page_inject

https://github.com/theori-io/copy-fail-CVE-2026-31431

https://github.com/MartinPham/copy-fail-CVE-2026-31431-php

https://github.com/JuanBindez/CVE-2026-31431

https://github.com/insomnisec/Detections-CVE-2026-31431

https://github.com/ExploitEoom/CVE-2026-31431

https://github.com/xeloxa/copyfail-exploit

https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC

https://github.com/tgies/copy-fail-c

https://github.com/0xShe/CVE-2026-31431

https://github.com/novysodope/copy-fail-CVE-2026-31431-C

https://github.com/luotian2/CVE-2026-31431

https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit

https://github.com/wgnet/wg.copyfail.patch

https://github.com/Dabbleam/CVE-2026-31431-mitigation

https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection

https://github.com/gbonacini/CVE-2026-31431

https://github.com/Huchangzhi/autorootlinux

https://github.com/aestechno/cve-2026-31431-ansible

https://github.com/darioomatos/cve-2026-31431-copyfail

https://github.com/yxdm02/CVE-2026-31431

https://github.com/Koshmare-Blossom/Copyfail-sh

https://github.com/rvizx/CVE-2026-31431

https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized

https://github.com/cozystack/copy-fail-blocker

https://github.com/Aurillium/RootRemover

https://github.com/badsectorlabs/copyfail-go

https://github.com/ErdemOzgen/copy-fail-cve-2026-31431

https://github.com/Alfredooe/CVE-2026-31431

https://github.com/cyber-joker/copy-fail-python

https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation

https://github.com/pascal-gujer/CVE-2026-31431

https://github.com/samanzamani/copy-fail-checker

https://github.com/SeanRickerd/cve-2026-31431

https://github.com/Smarttfoxx/copyfail

https://github.com/XsanFlip/CVE-2026-31431-Patch

https://github.com/desultory/CVE-2026-31431

https://github.com/wuwu001/CVE-2026-31431-exploit

https://github.com/b5null/CVE-2026-31431-C

https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431

https://github.com/kadir/copy-fail-CVE-2026-31431-IOC

https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431

https://github.com/diemoeve/copyfail-rs

https://github.com/ncmprbll/copy-fail-rs

https://github.com/ben-slates/CVE-2026-31431-Exploit

https://github.com/krisiasty/vcheck

https://github.com/atgreen/block-copyfail

https://github.com/Xerxes-2/CVE-2026-31431-rs

https://github.com/toxy4ny/copy-fail-exploit-on-c-redteam

https://github.com/malwarekid/CVE-2026-31431

https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs

https://github.com/yuspring/cve-2026-31431-poc

https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail

https://github.com/4xura/CVE-2026-31431-Copy-Fail

https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE

https://github.com/jbnetwork-git/copy-fail-check

https://github.com/H1d3r/copy-fail_LPE_Interactive

https://github.com/KaraZajac/DIRTYFAIL

https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag

https://github.com/mrunalp/block-copyfail

https://github.com/sammwyy/copyfail-rs

https://github.com/rippsec/CVE-2026-31431-Copy-Fail

ChrisShort@hachyderm.io at 2026-05-29T17:32:57.000Z ##

Mitigating CVE-2026-31431 ("Copy Fail") in Docker Engine #devopsish docker.com/blog/mitigating-cve

##

undercodenews@mastodon.social at 2026-05-29T17:11:30.000Z ##

CVE-2026-31431 “Copy Fail” Exposes Linux Kernel to Active Exploitation as CISA Flags Real-World Attacks and BlackSuit-Linked Intrusions Expand

Critical Linux Kernel Flaw Turns Into a Real-World Exploitation Tool Across Enterprise Environments CVE-2026-31431, internally tracked and now widely referred to as “Copy Fail,” has rapidly escalated from a technical kernel bug into a confirmed, actively exploited security crisis affecting Linux-based infrastructure worldwide.…

undercodenews.com/cve-2026-314

##

ChrisShort@hachyderm.io at 2026-05-29T17:32:57.000Z ##

Mitigating CVE-2026-31431 ("Copy Fail") in Docker Engine #devopsish docker.com/blog/mitigating-cve

##

governa@fosstodon.org at 2026-05-29T02:26:33.000Z ##

#Docker Releases Mitigation for Copy Fail (CVE-2026-31431)

ostechnix.com/docker-copy-fail

##

linux@activitypub.awakari.com at 2026-05-28T00:00:00.000Z ## From Exploit Code to Production Detection: Building a CVE-2026-31431 (Copy Fail) detection with Agents CVE-2026-31431 (Copy Fail) lets any unprivileged user corrupt the Linux page cache via AF_ALG ...


Origin | Interest | Match ##

CVE-2026-45707
(8.1 HIGH)

EPSS: 0.00%

updated 2026-05-18T17:41:42

1 posts

## Summary When `ENABLE_MULTI_TENANT=true`, the HTTP transport documents that the target n8n instance is selected per-request from `x-n8n-url` / `x-n8n-key` headers. Requests that omitted those headers — or supplied only one of them — silently fell back to the process-level `N8N_API_URL` / `N8N_API_KEY` credentials configured for the operator's own n8n instance. As a result, an authenticated MCP

thehackerwire@mastodon.social at 2026-05-29T15:00:00.000Z ##

🟠 CVE-2026-45707 - High (8.1)

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that the target n8n instance is selected per-request fr...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45697
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-05-18T17:23:40

2 posts

### Impact - Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). - Sites with public Formie forms that include at least one Hidden field with that configuration. - No CP login for the reported chain

thehackerwire@mastodon.social at 2026-05-29T21:00:22.000Z ##

🔴 CVE-2026-45697 - Critical (9.8)

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T21:00:22.000Z ##

🔴 CVE-2026-45697 - Critical (9.8)

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could l...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

linux@activitypub.awakari.com at 2026-05-28T03:43:38.000Z ## Dirty Frag: a kernel zero-day vs. container and microVM sandboxes On May 7, Hyunwoo Kim (V4bel) disclosed Dirty Frag — two Linux kernel vulnerabilities (CVE-2026-43284 and CVE-2026-43500) that gi...


Origin | Interest | Match ##

CVE-2026-8398
(9.8 CRITICAL)

EPSS: 14.39%

updated 2026-05-15T09:31:43

2 posts

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.ex

secdb@infosec.exchange at 2026-05-27T20:00:15.000Z ##

🚨 [CISA-2026:0527] CISA Adds 3 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

CISA has added 3 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

⚠️ CVE-2026-45321 (secdb.nttzen.cloud/cve/detail/)
- Name: TanStack Unspecified Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: TanStack
- Product: TanStack
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/TanStack/router/sec ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-48027 (secdb.nttzen.cloud/cve/detail/)
- Name: Nx Console Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Nx
- Product: Nx Console
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: github.com/nrwl/nx-console/sec ; nvd.nist.gov/vuln/detail/CVE-2

⚠️ CVE-2026-8398 (secdb.nttzen.cloud/cve/detail/)
- Name: Daemon Tools Lite Embedded Malicious Code Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Daemon
- Product: Daemon Tools Lite
- Notes: blog.daemon-tools.cc/post/secu ; nvd.nist.gov/vuln/detail/CVE-2

#SecDB #InfoSec #CVE #CISA_KEV #cisa_20260527 #cisa20260527 #cve_2026_45321 #cve_2026_48027 #cve_2026_8398 #cve202645321 #cve202648027 #cve20268398

##

cisakevtracker@mastodon.social at 2026-05-27T18:01:22.000Z ##

CVE ID: CVE-2026-8398
Vendor: Daemon
Product: Daemon Tools Lite
Date Added: 2026-05-27
CVE URL: nvd.nist.gov/vuln/detail/CVE-2

##

CVE-2026-45374
(9.6 CRITICAL)

EPSS: 0.04%

updated 2026-05-14T20:29:53

1 posts

### Summary The `task_create` tool spawns durable sub-agents that inherit two insecure defaults: - `allow_shell` defaults to `true` (`config.rs:1499`: `self.allow_shell.unwrap_or(true)`) - `auto_approve` defaults to `true` (`task_manager.rs:297`: `auto_approve: Some(true)`) When a user approves a `task_create` call (which requires `ApprovalRequirement::Required`), they approve what appears to b

thehackerwire@mastodon.social at 2026-05-28T19:01:38.000Z ##

🔴 CVE-2026-45374 - Critical (9.6)

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:1499: self.allow_shell.unwrap_or(true)) and auto_a...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45348
(8.7 HIGH)

EPSS: 0.03%

updated 2026-05-14T20:23:52

1 posts

## Summary The `packages.js` template at `src/pyload/webui/app/themes/modern/templates/js/packages.js:172` interpolates a stored link URL into a template literal inside single-quoted HTML and then writes the result to the DOM via `$(div).html(html)`. No escaping runs between the API value and `innerHTML`. An attacker (Alice) who can submit a package link puts a single quote plus event handler int

thehackerwire@mastodon.social at 2026-05-28T19:00:41.000Z ##

🟠 CVE-2026-45348 - High (8.7)

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/templates/js/packages.js:172 interpolates a stored link URL into a template literal inside...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-20182
(10.0 CRITICAL)

EPSS: 77.32%

updated 2026-05-14T18:33:03

1 posts

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.&nbsp; A vulnerability in the peering authentica

Nuclei template

3 repos

https://github.com/portbuster1337/CVE-2026-20182

https://github.com/HORKimhab/CVE-2026-20182

https://github.com/Nxploited/CVE-2026-20182

AAKL@infosec.exchange at 2026-05-28T16:45:36.000Z ##

Cisco, posted yesterday:

CRITICAL: CVE-2026-20182: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability sec.cloudapps.cisco.com/securi @TalosSecurity #Cisco #vulnerability #infosec

##

CVE-2026-40369
(7.8 HIGH)

EPSS: 0.01%

updated 2026-05-14T17:52:50.143000

2 posts

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

3 repos

https://github.com/ercihan/CVE-2026-40369

https://github.com/piffd0s/ntoskrnl-metadata

https://github.com/orinimron123/CVE-2026-40369-EXPLOIT

kallisti at 2026-05-29T19:30:22.976Z ##

CVE-2026-40369 seems fun...

##

kallisti@infosec.exchange at 2026-05-29T19:30:22.000Z ##

CVE-2026-40369 seems fun...

##

CVE-2026-44882
(8.1 HIGH)

EPSS: 0.04%

updated 2026-05-14T16:24:31

1 posts

## Summary Portainer proxies requests to Kubernetes clusters through a middleware layer (`kubeClientMiddleware`) that validates the requesting user's token before forwarding traffic to the cluster. When `security.RetrieveTokenData` returned an error, the middleware wrote an HTTP 403 response but was missing a `return` statement — execution continued into the handler with a nil `tokenData` value.

thehackerwire@mastodon.social at 2026-05-28T23:01:10.000Z ##

🟠 CVE-2026-44882 - High (8.1)

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33., Portainer proxies requests to Kubernetes ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45152
(7.8 HIGH)

EPSS: 0.03%

updated 2026-05-13T15:33:13

1 posts

I discovered a command injection vulnerability in uniget that allows arbitrary command execution through the metadata loading and version check mechanism. ### Summary A command injection vulnerability exists in uniget due to unsafe execution of the `check` field from metadata files using `/bin/bash -c`. Because the `check` field is loaded directly from untrusted JSON metadata without validation

thehackerwire@mastodon.social at 2026-05-27T23:00:43.000Z ##

🟠 CVE-2026-45152 - High (7.8)

uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution of the check field from metadata files using /bin/bash -c. Because the check field is lo...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-28910
(3.3 LOW)

EPSS: 0.01%

updated 2026-05-13T14:02:20.380000

1 posts

This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app may be able to access arbitrary files.

mysk@mastodon.social at 2026-05-28T14:04:21.000Z ##

We had lengthy discussions explaining the bug to Apple. It was clear to us the bug was new to Apple Product Security. After 5 months, they informed us that the report was treated as a duplicate and it was addressed.
We just got this update for CVE-2026-28910: No bounty

You can read the full blog post (aka charity work for a 4-trillion-dollar company) highlighting this bug here:

mysk.blog/2026/05/19/cve-2026-

#apple #privacy #macos #infosec #security

##

CVE-2026-44650
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-05-12T22:23:47

2 posts

## Summary `POST /api/extensions/delete` endpoint accepts `extensionName: "."` which bypasses `sanitize-filename` validation, causing the entire user extensions directory to be recursively deleted. No authentication is required in the default configuration. ## Affected File `src/endpoints/extensions.js` (last modified: commit `3ad9b05e2`) ## Root Cause The validation check occurs **before**

thehackerwire@mastodon.social at 2026-05-30T01:00:13.000Z ##

🔴 CVE-2026-44650 - Critical (9.1)

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint accepts ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-30T01:00:13.000Z ##

🔴 CVE-2026-44650 - Critical (9.1)

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint accepts ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44649
(9.8 CRITICAL)

EPSS: 0.00%

updated 2026-05-12T22:23:33

2 posts

## Resolution SillyTavern 1.18.0 now includes a configuration option to limit which IP addresses can authorize using SSO headers, limiting to just loopback addresses by default. A setting can be customized according to user's needs. Documentation: https://docs.sillytavern.app/administration/sso/ ## Summary SillyTavern accepts `Remote-User` (Authelia) and `X-Authentik-Username` (Authentik) HTTP

thehackerwire@mastodon.social at 2026-05-30T01:00:02.000Z ##

🔴 CVE-2026-44649 - Critical (9.8)

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-30T01:00:02.000Z ##

🔴 CVE-2026-44649 - Critical (9.8)

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authelia) and ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45088
(7.5 HIGH)

EPSS: 0.03%

updated 2026-05-12T15:08:14

1 posts

## Summary When dalfox is run in REST API server mode, the `custom-payload-file` field in `model.Options` is JSON-tagged and deserialized directly from the attacker's request body, then propagated unchanged through `dalfox.Initialize` into the scan engine. The engine passes the value to `voltFile.ReadLinesOrLiteral`, which reads lines from any file path accessible to the dalfox process and embeds

thehackerwire@mastodon.social at 2026-05-28T18:01:53.000Z ##

🟠 CVE-2026-45088 - High (7.5)

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-file field in model.Options is JSON-tagged and deserialized directly from the attacker'...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-26980
(9.4 CRITICAL)

EPSS: 56.66%

updated 2026-05-12T13:31:01

1 posts

### Impact A SQL injection vulnerability existed in Ghost's Content API that allowed unauthenticated attackers to read arbitrary data from the database. ### Vulnerable Versions This vulnerability is present in Ghost v3.24.0 to v6.19.0. ### Patches v6.19.1 contains a fix for this issue. **Note:** as this vulnerability lets an attacker gain access to a site's API keys, we recommend reviewing

Nuclei template

5 repos

https://github.com/vognik/CVE-2026-26980

https://github.com/Kulik-Labs-Development/Ghost-CMS-Code-Injection-Audit-CVE-2026-26980

https://github.com/EQSTLab/CVE-2026-26980

https://github.com/ByteWraith1/CVE-2026-26980

https://github.com/dinosn/ghost-cve-2026-26980

CVE-2026-45047
(7.5 HIGH)

EPSS: 0.08%

updated 2026-05-11T16:17:49

1 posts

### Summary The `apiHandler` (and similarly `webHandlerTelegramBot`) processes user-provided JSON payloads by directly using `json.NewDecoder(r.Body).Decode(&request)` without restricting the maximum read size. An unauthenticated remote attacker can stream an extremely large, endless JSON payload (e.g., several Gigabytes of padding) over a single TCP connection. Because Go's JSON decoder attempts

thehackerwire@mastodon.social at 2026-05-28T18:01:28.000Z ##

🟠 CVE-2026-45047 - High (7.5)

bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read si...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44483
(8.2 HIGH)

EPSS: 0.04%

updated 2026-05-11T16:09:41

1 posts

## Summary `setPath` in `@rvf/set-get` (used by `@rvf/core` to flatten incoming form data into a nested object) does not block the keys `__proto__`, `constructor`, or `prototype` when walking a path. Because field names in submitted form data are passed directly to `setPath` via `preprocessFormData` (and through `parseFormData` / `validate`), an attacker who can submit a form to a Remix / React R

thehackerwire@mastodon.social at 2026-05-27T18:00:43.000Z ##

🟠 CVE-2026-44483 - High (8.2)

RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @Rvf/set-get (used by @Rvf/core to flatten incoming form data into a nested object) does not block t...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44327
(10.0 CRITICAL)

EPSS: 0.04%

updated 2026-05-08T22:59:24

1 posts

### Summary free5GC's NEF mounts the `nnef-oam` route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no `Authorization` header at all and the handler returns `200 OK`. The current OAM handler is a stub that returns `null`, but the structural defect is route-group-scoped: the entire OAM route group has no inbound a

thehackerwire@mastodon.social at 2026-05-27T18:01:01.000Z ##

🔴 CVE-2026-44327 - Critical (10)

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-39987
(9.8 CRITICAL)

EPSS: 82.17%

updated 2026-04-23T20:15:29.690000

2 posts

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpo

Nuclei template

11 repos

https://github.com/fevar54/marimo_CVE-2026-39987_RCE_PoC

https://github.com/HORKimhab/CVE-2026-39987

https://github.com/0xdeadroot/CVE-2026-39987-marimo-rce

https://github.com/M3PH1569/CVE-2026-39987-POC

https://github.com/h3raklez/CVE-2026-39987

https://github.com/mki9/CVE-2026-39987_exploit

https://github.com/rootdirective-sec/CVE-2026-39987-Lab

https://github.com/keraattin/CVE-2026-39987

https://github.com/Nxploited/CVE-2026-39987

https://github.com/0xBlackash/CVE-2026-39987

https://github.com/Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab

Analyst207@mastodon.social at 2026-05-29T16:20:33.000Z ##

LLM Agent Enables Rapid Post-Exploitation in Marimo Networks

On May 10, 2026, a savvy attacker used a large language model agent to rapidly exploit a vulnerable Marimo instance, leveraging CVE-2026-39987 to spark a swift and damaging breach. This critical vulnerability allowed the attacker to execute arbitrary system commands, paving the way for cloud credential…

osintsights.com/llm-agent-enab

#MarimoNetworkExploitation #LargeLanguageModelAgent #Cve202639987 #Postexploitation #RemoteCodeExecution

##

LLMs@activitypub.awakari.com at 2026-05-29T14:39:00.000Z ## Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit TheHackerNews LLM-driven attackers exploited CVE-2026-39987 on May 10, 2026, to steal credentials and exfiltrate a ...

#Security #News

Origin | Interest | Match ##

CVE-2026-3172
(8.1 HIGH)

EPSS: 0.06%

updated 2026-04-15T00:35:42.020000

2 posts

Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.

mastokukei@social.josko.org at 2026-05-30T09:01:59.000Z ##

other databases.
- **Rust ecosystem updates**: Rust 1.96 release, async runtime discussions, idiomatic error handling, GitHub migration, and no-AI policy adoption.
- **Open-source security incidents**: GitHub "Megalodon" attack (5,500+ repos compromised), malicious npm packages (e.g., Laravel Lang, AntV), and supply chain risks.
- **PostgreSQL updates**: PGConf.EU 2026 Call for Papers, security patches (CVE-2026-3172), pgvector fixes, and pgBackRest funding.
- **Vibe coding [2/3]

##

mastokukei@social.josko.org at 2026-05-29T18:02:02.000Z ##

Blip blop, I'm a #mastobot.
Here is a summary (in beta) of the latest posts in #programmingAtKukei masto.kukei.eu/browse/programm category:
- **PGConf.EU 2026 Call for Papers** deadline: June 1, Valencia (October 20–23).
- **AI coding tools controversies**: GitHub Copilot, Claude Code, Cursor, AI-generated code quality/security risks (e.g., symlink RCE, hidden "delete all code" prompts).
- **PostgreSQL updates**: PGConf.EU 2026, security patches (CVE-2026-3172), pgvector fixes, [1/2]

##

CVE-2024-8310
(9.8 CRITICAL)

EPSS: 0.04%

updated 2026-04-15T00:35:42.020000

1 posts

OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.

hugovalters@mastodon.social at 2026-05-29T23:10:06.000Z ##

CVE-2024-8310 - Critical auth bypass in OPW Fuel Management SiteSentinel. Full admin access. CVSS 9.8. No patch available. Isolate systems immediately. #CVE #infosec #OTsecurity

valtersit.com/cve/CVE-2024-831

##

CVE-2024-55884
(9.0 CRITICAL)

EPSS: 0.80%

updated 2026-04-15T00:35:42.020000

1 posts

In the Mullvad VPN client 2024.6 (Desktop), 2024.8 (iOS), and 2024.8-beta1 (Android), the exception-handling alternate stack can be exhausted, leading to heap-based out-of-bounds writes in enable() in exception_logging/unix.rs, aka MLLVD-CR-24-01. NOTE: achieving code execution is considered non-trivial.

hugovalters@mastodon.social at 2026-05-29T09:06:17.000Z ##

CVE-2024-55884 - Critical OOB access in Mullvad VPN. Heap-based write via exception stack exhaustion. CVSS 9.0. Code execution possible. No patch available yet. Monitor for updates. #CVE #Mullvad #infosec

valtersit.com/cve/CVE-2024-558

##

CVE-2026-35616
(9.8 CRITICAL)

EPSS: 41.17%

updated 2026-04-06T18:12:57.863000

2 posts

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Nuclei template

8 repos

https://github.com/fevar54/CVE-2026-35616-detector.py

https://github.com/fevar54/forticlient_ems_cve_2026_35616_poc.py

https://github.com/wa6n3r/CVE-2026-35616

https://github.com/keraattin/CVE-2026-35616

https://github.com/HORKimhab/CVE-2026-35616

https://github.com/BishopFox/CVE-2026-35616-check

https://github.com/Alaatk/CVE-2026-35616

https://github.com/0xBlackash/CVE-2026-35616

Matchbook3469@mastodon.social at 2026-05-29T18:34:07.000Z ##

🔵 THREAT INTELLIGENCE

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Vulnerability | CRITICAL
CVEs: CVE-2026-35616

Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an...

Full analysis:
yazoul.net/news/article/threat

#InfoSec #ZeroDay #ThreatHunting

##

jbhall56@infosec.exchange at 2026-05-29T12:28:02.000Z ##

The activity, observed by the cybersecurity company in May 2026, involves the exploitation of CVE-2026-35616 (CVSS score: 9.1), a critical pre-authentication API access bypass leading to privilege escalation. thehackernews.com/2026/05/thre

##

CVE-2024-49611
(10.0 CRITICAL)

EPSS: 0.63%

updated 2026-04-01T18:32:06

1 posts

Unrestricted Upload of File with Dangerous Type vulnerability in Paxman Product Website Showcase allows Upload a Web Shell to a Web Server.This issue affects Product Website Showcase: from n/a through 1.0.

hugovalters@mastodon.social at 2026-05-29T18:05:52.000Z ##

CVE-2024-49611 - Critical arbitrary file upload in Paxman Product Website Showcase. CVSS 10. Allows web shell upload. No patch available. Disable plugin immediately. #CVE #infosec #WordPress

valtersit.com/cve/CVE-2024-496

##

CVE-2026-4565
(8.8 HIGH)

EPSS: 0.09%

updated 2026-03-23T03:31:45

1 posts

A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetNetControlList. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

2 repos

https://github.com/HORKimhab/CVE-2026-45659

https://github.com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE

hackmag@infosec.exchange at 2026-05-28T15:00:03.000Z ##

⚪️ Microsoft Fixes RCE Vulnerability in SharePoint

🗨️ Microsoft engineers have released out-of-band patches for an RCE vulnerability in SharePoint Server (CVE-2026-45659). The issue has a CVSS score of 8.8 and affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Exploiting it only requires…

🔗 hackmag.com/news/cve-2026-4565

#news

##

CVE-2025-10158
(4.3 MEDIUM)

EPSS: 0.05%

updated 2025-11-18T15:30:54

1 posts

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via a negative array index. The malicious rsync client requires at least read access to the remote rsync module in order to trigger the issue.

gabrielesvelto@mas.to at 2026-05-29T12:27:03.000Z ##

So here's one of the cool things you can do with Gentoo. You're not forced to stick to the latest version of a package, multiple stable versions might be available simultaneously. So in this case you can mask rsync-3.4.3 to avoid the slop-induced bugs and the package manager will automatically fall back to rsync-3.4.1-r2. See that '-r2' suffix? That's important, it means that it's the base 3.4.1 version plus a set of patches added by the Gentoo maintainers. In this particular case those patches address CVE-2025-10158, so you get the important security fix but avoid the slop issues introduced in the next stable release. Naturally, while the technical brilliance of this system is remarkable, what really shines it the will of Gentoo maintainers to go above and beyond to solve users' issues. Thanks (and donations) should go to them.

mastodon.gamedev.place/@Jeremi

#Gentoo #rsync

##

CVE-2019-1385
(7.8 HIGH)

EPSS: 0.49%

updated 2025-10-29T14:34:16.610000

2 posts

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages p

briankrebs at 2026-05-30T03:02:29.837Z ##

RE: c.im/@cdarwin/1166607696958375

One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.

Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.

On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.

For the record, I think @GossiTheDog called it that this person was a former MS employee.

x.com/ChaoticEclipse0/with_rep

##

briankrebs@infosec.exchange at 2026-05-30T03:02:29.000Z ##

RE: c.im/@cdarwin/1166607696958375

One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.

Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.

On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.

For the record, I think @GossiTheDog called it that this person was a former MS employee.

x.com/ChaoticEclipse0/with_rep

##

CVE-2016-10156
(7.8 HIGH)

EPSS: 0.71%

updated 2025-04-20T03:32:27

1 posts

A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.

grawity@treehouse.systems at 2026-05-28T07:50:28.000Z ##

my approach to finding security bugs:

me in 2017: "hmm the directory is world-writable, and the sticky bit looks ugly in my colorized ls, I'll send a patch"
someone on IRC a week later: "hey you're named in CVE-2016-10156"

me in 2023: "ugh OpenSSH crashes when I'm connecting from my retro Win98 VM"
someone on IRC a week later: "hey did you know you're in CVE-2023-25136"

##

CVE-2025-0066
(9.9 CRITICAL)

EPSS: 0.09%

updated 2025-01-14T03:31:48

1 posts

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application

hugovalters@mastodon.social at 2026-05-28T23:07:21.000Z ##

CVE-2025-0066 — Critical supply chain attack in SAP NetWeaver AS for ABAP. Weak access controls allow info disclosure, impacting confidentiality, integrity, and availability. CVSS 9.9. Unpatched. Act now to mitigate risk. #CVE #SAP #infosec

valtersit.com/cve/CVE-2025-006

##

CVE-2021-4229
(5.0 MEDIUM)

EPSS: 0.86%

updated 2024-11-21T06:37:11.567000

1 posts

A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.

1 repos

https://github.com/corelight/CVE-2021-42292

CVE-2017-16054
(7.5 HIGH)

EPSS: 0.26%

updated 2024-11-21T03:15:44.050000

1 posts

`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

CVE-2024-45694
(9.8 CRITICAL)

EPSS: 2.49%

updated 2024-09-17T18:40:07.243000

1 posts

The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

hugovalters@mastodon.social at 2026-05-30T02:13:04.000Z ##

CVE-2024-45694 - Critical unpatched stack buffer overflow in D-Link routers. CVSS 9.8. Unauthenticated RCE possible. No patch available. Isolate affected devices immediately. #CVE #DLink #infosec

valtersit.com/cve/CVE-2024-456

##

CVE-2024-7261
(9.8 CRITICAL)

EPSS: 27.88%

updated 2024-09-13T19:39:40.570000

1 posts

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker t

hugovalters@mastodon.social at 2026-05-30T05:05:12.000Z ##

CVE-2024-7261 - Critical OS Command Injection in Zyxel devices. Unauthenticated RCE via crafted cookie. CVSS 9.8. No patch available yet. Isolate affected devices immediately. #CVE #Zyxel #cybersecurity

valtersit.com/cve/CVE-2024-726

##

CVE-2024-42395
(9.8 CRITICAL)

EPSS: 0.27%

updated 2024-08-12T18:23:57.077000

2 posts

There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

hugovalters@mastodon.social at 2026-05-30T09:05:15.000Z ##

CVE-2024-42395 - Critical RCE in AP Certificate Management Service. Unauthenticated RCE, CVSS 9.8. Exploitation leads to full system compromise. Patch status unknown, monitor for updates urgently. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2024-423

##

hugovalters@mastodon.social at 2026-05-30T09:05:15.000Z ##

CVE-2024-42395 - Critical RCE in AP Certificate Management Service. Unauthenticated RCE, CVSS 9.8. Exploitation leads to full system compromise. Patch status unknown, monitor for updates urgently. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2024-423

##

CVE-2023-25136
(9.8 CRITICAL)

EPSS: 88.33%

updated 2024-03-07T05:10:04

1 posts

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be triggered by an unauthenticated attacker in the default configuration; however, the vulnerability discoverer reports that "exploiting this vulnerability will not be easy."

11 repos

https://github.com/ticofookfook/CVE-2023-25136

https://github.com/malvika-thakur/CVE-2023-25136

https://github.com/Business1sg00d/CVE-2023-25136

https://github.com/nhakobyan685/CVE-2023-25136

https://github.com/Lane0218/CVE-2023-25136-PoC

https://github.com/mrmtwoj/CVE-2023-25136

https://github.com/jfrog/jfrog-CVE-2023-25136-OpenSSH_Double-Free

https://github.com/axylisdead/CVE-2023-25136_POC

https://github.com/adhikara13/CVE-2023-25136

https://github.com/H4K6/CVE-2023-25136

https://github.com/Christbowel/CVE-2023-25136

grawity@treehouse.systems at 2026-05-28T07:50:28.000Z ##

my approach to finding security bugs:

me in 2017: "hmm the directory is world-writable, and the sticky bit looks ugly in my colorized ls, I'll send a patch"
someone on IRC a week later: "hey you're named in CVE-2016-10156"

me in 2023: "ugh OpenSSH crashes when I'm connecting from my retro Win98 VM"
someone on IRC a week later: "hey did you know you're in CVE-2023-25136"

##

CVE-2021-24084
(5.5 MEDIUM)

EPSS: 3.49%

updated 2024-01-07T05:05:26

2 posts

Windows Mobile Device Management Information Disclosure Vulnerability

2 repos

https://github.com/exploitblizzard/WindowsMDM-LPE-0Day

https://github.com/Jeromeyoung/CVE-2021-24084

briankrebs at 2026-05-30T03:02:29.837Z ##

RE: c.im/@cdarwin/1166607696958375

One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.

Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.

On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.

For the record, I think @GossiTheDog called it that this person was a former MS employee.

x.com/ChaoticEclipse0/with_rep

##

briankrebs@infosec.exchange at 2026-05-30T03:02:29.000Z ##

RE: c.im/@cdarwin/1166607696958375

One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.

Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.

On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.

For the record, I think @GossiTheDog called it that this person was a former MS employee.

x.com/ChaoticEclipse0/with_rep

##

CVE-2025-60486
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel at 2026-05-30T08:19:16.458Z ##

Security Advisory: CVE-2025-60486 - Use-After-Free in GPAC/MP4Box

Processing a crafted MPEG-2 Transport Stream file with corrupted PMT descriptors triggers a heap use-after-free in `dasher_process`, causing MP4Box to crash and potentially enabling arbitrary code execution.

Summary:
The `dasher_configure_pid` function in `filters/dasher.c` frees a PID context structure at line 976 when reconfiguring a stream. The freed pointer is not cleared, and `dasher_process` subsequently accesses the same memory at line 9445 during the next processing cycle. A crafted MPEG-2 TS file with repeated sync marker violations, broken PMT descriptors, and conflicting PIDs triggers this reconfiguration sequence, leading to a READ of 4 bytes into freed heap memory.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filters/dasher.c:9445
Function: dasher_process()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1665-g3f20eb0cd-master; commit `3f20eb0cd22116367c036e6ffe6ace299b38d686`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a crafted MPEG-2 TS file containing missing sync markers, corrupted PMT descriptor sizes, and conflicting PID assignments. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers PID reconfiguration in the dasher module.

Impact:
The use-after-free (READ of size 4 at 316 bytes into a freed 1096-byte heap region) causes process termination, resulting in Denial of Service. Code execution cannot be ruled out; use-after-free vulnerabilities can allow an attacker to control freed memory contents and redirect execution flow.

Fix / mitigation status:
The fix ensures the stale PID context pointer in `dasher_configure_pid` is cleared after the region is freed so that `dasher_process` cannot access it. Users should upgrade to the release containing commit `e6d01820d7bf3967d931fedb379ee5f209bc133b` or apply that patch directly.

References

- Issue: github.com/gpac/gpac/issues/33
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/e6

Credit
@sigdevel

##

sigdevel@infosec.exchange at 2026-05-30T08:19:16.000Z ##

Security Advisory: CVE-2025-60486 - Use-After-Free in GPAC/MP4Box

Processing a crafted MPEG-2 Transport Stream file with corrupted PMT descriptors triggers a heap use-after-free in `dasher_process`, causing MP4Box to crash and potentially enabling arbitrary code execution.

Summary:
The `dasher_configure_pid` function in `filters/dasher.c` frees a PID context structure at line 976 when reconfiguring a stream. The freed pointer is not cleared, and `dasher_process` subsequently accesses the same memory at line 9445 during the next processing cycle. A crafted MPEG-2 TS file with repeated sync marker violations, broken PMT descriptors, and conflicting PIDs triggers this reconfiguration sequence, leading to a READ of 4 bytes into freed heap memory.

CWE:
CWE-416 - Use After Free

Affected Component:
```
filters/dasher.c:9445
Function: dasher_process()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1665-g3f20eb0cd-master; commit `3f20eb0cd22116367c036e6ffe6ace299b38d686`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a crafted MPEG-2 TS file containing missing sync markers, corrupted PMT descriptor sizes, and conflicting PID assignments. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers PID reconfiguration in the dasher module.

Impact:
The use-after-free (READ of size 4 at 316 bytes into a freed 1096-byte heap region) causes process termination, resulting in Denial of Service. Code execution cannot be ruled out; use-after-free vulnerabilities can allow an attacker to control freed memory contents and redirect execution flow.

Fix / mitigation status:
The fix ensures the stale PID context pointer in `dasher_configure_pid` is cleared after the region is freed so that `dasher_process` cannot access it. Users should upgrade to the release containing commit `e6d01820d7bf3967d931fedb379ee5f209bc133b` or apply that patch directly.

References

- Issue: github.com/gpac/gpac/issues/33
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/e6

Credit
@sigdevel

#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory

##

CVE-2025-60485
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel at 2026-05-30T08:07:33.564Z ##

Security Advisory: CVE-2025-60485 - NULL Pointer Dereference in GPAC/MP4Box

Processing a crafted MP4 file with corrupted `esds` boxes and incomplete box structures triggers a NULL pointer dereference in `gf_isom_apple_set_tag_ex`, causing MP4Box to crash.

Summary:
The `gf_isom_apple_set_tag_ex` function in `isomedia/isom_write.c` is called during muxer tag setup to write Apple metadata tags into the output file. When the input MP4 contains an invalid `esds` descriptor (tag 3, truncated size) and an incomplete box structure, the function receives an unvalidated NULL pointer and dereferences it (READ at address 0x0) without a prior NULL check, terminating the process with SIGSEGV.

CWE:
CWE-476 - NULL Pointer Dereference

Affected Component:
```
isomedia/isom_write.c:6309
Function: gf_isom_apple_set_tag_ex()

filters/mux_isom.c:841
Function: mp4_mux_set_tags()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1687-ge44a4e2b0-master; commit `e44a4e2b0d193566619ada71599e70255699da94`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a crafted MP4 file containing a corrupted `esds` box (invalid descriptor sizes) and incomplete box structures. Local access is required; the victim must invoke `MP4Box -add <crafted_file>` or any equivalent MP4Box operation that triggers the muxer PID setup and tag-writing path.

Impact:
The NULL pointer dereference (READ at address 0x000000000000) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a NULL read that is not exploitable for control-flow hijacking.

Fix / mitigation status:
The fix adds a NULL check for the tag pointer before dereferencing it in `gf_isom_apple_set_tag_ex`. Users should upgrade to the release containing commit `4860a1a6f128ccc9ae37b4b738d22029f9672457` or apply that patch directly.

References

- Issue: github.com/gpac/gpac/issues/33
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/48

Credit
@sigdevel

##

sigdevel@infosec.exchange at 2026-05-30T08:07:33.000Z ##

Security Advisory: CVE-2025-60485 - NULL Pointer Dereference in GPAC/MP4Box

Processing a crafted MP4 file with corrupted `esds` boxes and incomplete box structures triggers a NULL pointer dereference in `gf_isom_apple_set_tag_ex`, causing MP4Box to crash.

Summary:
The `gf_isom_apple_set_tag_ex` function in `isomedia/isom_write.c` is called during muxer tag setup to write Apple metadata tags into the output file. When the input MP4 contains an invalid `esds` descriptor (tag 3, truncated size) and an incomplete box structure, the function receives an unvalidated NULL pointer and dereferences it (READ at address 0x0) without a prior NULL check, terminating the process with SIGSEGV.

CWE:
CWE-476 - NULL Pointer Dereference

Affected Component:
```
isomedia/isom_write.c:6309
Function: gf_isom_apple_set_tag_ex()

filters/mux_isom.c:841
Function: mp4_mux_set_tags()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1687-ge44a4e2b0-master; commit `e44a4e2b0d193566619ada71599e70255699da94`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a crafted MP4 file containing a corrupted `esds` box (invalid descriptor sizes) and incomplete box structures. Local access is required; the victim must invoke `MP4Box -add <crafted_file>` or any equivalent MP4Box operation that triggers the muxer PID setup and tag-writing path.

Impact:
The NULL pointer dereference (READ at address 0x000000000000) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a NULL read that is not exploitable for control-flow hijacking.

Fix / mitigation status:
The fix adds a NULL check for the tag pointer before dereferencing it in `gf_isom_apple_set_tag_ex`. Users should upgrade to the release containing commit `4860a1a6f128ccc9ae37b4b738d22029f9672457` or apply that patch directly.

References

- Issue: github.com/gpac/gpac/issues/33
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/48

Credit
@sigdevel

#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory

##

CVE-2026-45632
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-05-30T04:00:08.000Z ##

🔴 CVE-2026-45632 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belonging to othe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-30T04:00:08.000Z ##

🔴 CVE-2026-45632 - Critical (9.9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belonging to othe...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45631
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-05-30T03:00:24.000Z ##

🔴 CVE-2026-45631 - Critical (10)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger auto-sign...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-30T03:00:24.000Z ##

🔴 CVE-2026-45631 - Critical (10)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger auto-sign...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45630
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-05-30T03:00:11.000Z ##

🔴 CVE-2026-45630 - Critical (9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-30T03:00:11.000Z ##

🔴 CVE-2026-45630 - Critical (9)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47740
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-05-29T23:00:24.000Z ##

🟠 CVE-2026-47740 - High (8.1)

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T23:00:24.000Z ##

🟠 CVE-2026-47740 - High (8.1)

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44421
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-05-29T22:00:09.000Z ##

🟠 CVE-2026-44421 - High (8.8)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T22:00:09.000Z ##

🟠 CVE-2026-44421 - High (8.8)

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44285
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-05-29T21:01:10.000Z ##

🟠 CVE-2026-44285 - High (7.7)

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T21:01:10.000Z ##

🟠 CVE-2026-44285 - High (7.7)

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to ...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47123
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-05-29T21:00:03.000Z ##

🟠 CVE-2026-47123 - High (7.5)

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command has two code paths for identifying agent (user) replies based on In-Reply-To / Re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T21:00:03.000Z ##

🟠 CVE-2026-47123 - High (7.5)

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command has two code paths for identifying agent (user) replies based on In-Reply-To / Re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47744
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-05-29T20:01:03.000Z ##

🔴 CVE-2026-47744 - Critical (9.9)

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T20:01:03.000Z ##

🔴 CVE-2026-47744 - Critical (9.9)

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenti...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-55664
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel at 2026-05-29T18:20:23.119Z ##

Security Advisory: CVE-2025-55664 - Heap-based Buffer Overflow in GPAC/MP4Box

Processing a crafted MPEG-2 Transport Stream file with corrupted packet structures triggers a heap buffer overflow in `m2tsdmx_send_packet`, causing MP4Box to crash and potentially enabling arbitrary code execution.

Summary:
The `m2tsdmx_send_packet` function in `filters/dmx_m2ts.c` performs a `memcpy` whose size argument is derived from stream-controlled data without validation. A crafted MPEG-2 TS file with missing sync markers, corrupted PMT descriptors, and PID conflicts can cause the size to wrap to 4294967295 (0xFFFFFFFF), triggering a `memcpy` that reads and writes 4 GB of heap memory starting one byte past the end of a 183-byte allocated region.

CWE:
CWE-122 - Heap-based Buffer Overflow

Affected Component

```
filters/dmx_m2ts.c:916
Function: m2tsdmx_send_packet()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1644-g8e3b5e1dd-master; commit `8e3b5e1dde7b9ea041dbdc14456a5bb74a9851ea`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a specially crafted MPEG-2 TS file containing missing sync markers (0x47), corrupted PMT descriptor sizes, and conflicting PID assignments. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the MPEG-2 TS demuxer processing path.

Impact:
The heap buffer overflow (READ of size 4294967295, 1 byte past end of a 183-byte heap region) results in process termination, causing Denial of Service. Due to the write-capable nature of the oversized `memcpy`, arbitrary code execution cannot be ruled out.

Fix / mitigation status:
The fix adds size validation before the `memcpy` call in `m2tsdmx_send_packet` to reject stream-supplied sizes that exceed the allocated buffer. Users should upgrade to the release containing commit `9bd6a72c9efc0513dfd33b87498afc7658dabd26` or apply that patch directly.

References

- Issue: github.com/gpac/gpac/issues/33
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/9b

Credit
@sigdevel

##

sigdevel@infosec.exchange at 2026-05-29T18:20:23.000Z ##

Security Advisory: CVE-2025-55664 - Heap-based Buffer Overflow in GPAC/MP4Box

Processing a crafted MPEG-2 Transport Stream file with corrupted packet structures triggers a heap buffer overflow in `m2tsdmx_send_packet`, causing MP4Box to crash and potentially enabling arbitrary code execution.

Summary:
The `m2tsdmx_send_packet` function in `filters/dmx_m2ts.c` performs a `memcpy` whose size argument is derived from stream-controlled data without validation. A crafted MPEG-2 TS file with missing sync markers, corrupted PMT descriptors, and PID conflicts can cause the size to wrap to 4294967295 (0xFFFFFFFF), triggering a `memcpy` that reads and writes 4 GB of heap memory starting one byte past the end of a 183-byte allocated region.

CWE:
CWE-122 - Heap-based Buffer Overflow

Affected Component

```
filters/dmx_m2ts.c:916
Function: m2tsdmx_send_packet()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1644-g8e3b5e1dd-master; commit `8e3b5e1dde7b9ea041dbdc14456a5bb74a9851ea`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a specially crafted MPEG-2 TS file containing missing sync markers (0x47), corrupted PMT descriptor sizes, and conflicting PID assignments. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the MPEG-2 TS demuxer processing path.

Impact:
The heap buffer overflow (READ of size 4294967295, 1 byte past end of a 183-byte heap region) results in process termination, causing Denial of Service. Due to the write-capable nature of the oversized `memcpy`, arbitrary code execution cannot be ruled out.

Fix / mitigation status:
The fix adds size validation before the `memcpy` call in `m2tsdmx_send_packet` to reject stream-supplied sizes that exceed the allocated buffer. Users should upgrade to the release containing commit `9bd6a72c9efc0513dfd33b87498afc7658dabd26` or apply that patch directly.

References

- Issue: github.com/gpac/gpac/issues/33
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/9b

Credit
@sigdevel

#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory

##

lobsters@mastodon.social at 2026-05-29T18:00:16.000Z ##

CVE-2026-48710: A Maintainer's Perspective lobste.rs/s/xvdvko #python #security
marcelotryle.com/blog/2026/05/

##

lobsters@mastodon.social at 2026-05-29T18:00:16.000Z ##

CVE-2026-48710: A Maintainer's Perspective lobste.rs/s/xvdvko #python #security
marcelotryle.com/blog/2026/05/

##

x41sec@infosec.exchange at 2026-05-28T07:30:41.000Z ##

There's an update for the Starlette issue: We've scanned thousands of hosts for CVE-2026-48710 and found something important: Being behind a proxy or CloudFlare isn't always a protection unlike previously stated!
When a reverse proxy or CDN (including Cloudflare) sits in front of the target and rejects malformed Host headers, the X-Forwarded-Host header can sometimes be used to bypass the protection! If the backend middleware reads X-Forwarded-Host and updates the ASGI scope, the malicious value can reach the ASGI and Starlette. #badhost

##

hackmag@infosec.exchange at 2026-05-28T05:30:04.000Z ##

⚪️ BadHost vulnerability in the Starlette framework poses a threat to AI agents

🗨️ Researchers are warning about a critical vulnerability, CVE-2026-48710, discovered in the open-source Starlette framework and dubbed BadHost. Since Starlette underpins FastAPI and many popular AI tools, the issue creates risks for millions of servers and AI agents, and exploiting the…

🔗 hackmag.com/news/badhost?utm_s

#news

##

CVE-2025-60481
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel at 2026-05-29T17:58:24.679Z ##

Security Advisory: CVE-2025-60481 - Out-of-Bounds Read in GPAC/MP4Box

Processing a crafted AC-4 stream with an invalid `frame_rate_index` triggers an out-of-bounds read in `gf_odf_ac4_cfg_dsi_v1`, causing MP4Box to crash.

Summary:
The `gf_odf_ac4_cfg_dsi_v1` function in `odf/descriptors.c` uses a stream-supplied `frame_rate_index` to index into fixed-size lookup tables (`AC4_SAMPLE_DELTA_TABLE_48`, `AC4_MEDIA_TIMESCALE_48`). The function does not validate that the index is within bounds before performing the table lookup. A crafted AC-4 file carrying an out-of-range index (e.g., 15) causes an out-of-bounds read, ultimately resulting in a NULL dereference and process crash.

CWE:
CWE-125 - Out-of-bounds Read

Affected Component:

```
odf/descriptors.c:2179
Function: gf_odf_ac4_cfg_dsi_v1()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1617-g856674b22-master; commit `856674b226d6cbe28a941ad223be38194cbf7d37`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a specially crafted AC-4 stream file containing an invalid `frame_rate_index` value. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the AC-4 configuration descriptor parsing path.

Impact:
The out-of-bounds read leads to an immediate process crash (SEGV READ at address 0x000000000000), resulting in Denial of Service. No evidence of arbitrary code execution was observed.

Fix / mitigation status:
The fix adds bounds validation for `frame_rate_index` before the fixed-size table lookups in `gf_odf_ac4_cfg_dsi_v1`. Users should upgrade to the release containing commit `13eb5b76560aaf7813b865a2ad433258478e2695` or apply that patch directly.

References

- Issue: github.com/gpac/gpac/issues/33
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/13

Credit
@sigdevel

##

sigdevel@infosec.exchange at 2026-05-29T17:58:24.000Z ##

Security Advisory: CVE-2025-60481 - Out-of-Bounds Read in GPAC/MP4Box

Processing a crafted AC-4 stream with an invalid `frame_rate_index` triggers an out-of-bounds read in `gf_odf_ac4_cfg_dsi_v1`, causing MP4Box to crash.

Summary:
The `gf_odf_ac4_cfg_dsi_v1` function in `odf/descriptors.c` uses a stream-supplied `frame_rate_index` to index into fixed-size lookup tables (`AC4_SAMPLE_DELTA_TABLE_48`, `AC4_MEDIA_TIMESCALE_48`). The function does not validate that the index is within bounds before performing the table lookup. A crafted AC-4 file carrying an out-of-range index (e.g., 15) causes an out-of-bounds read, ultimately resulting in a NULL dereference and process crash.

CWE:
CWE-125 - Out-of-bounds Read

Affected Component:

```
odf/descriptors.c:2179
Function: gf_odf_ac4_cfg_dsi_v1()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1617-g856674b22-master; commit `856674b226d6cbe28a941ad223be38194cbf7d37`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a specially crafted AC-4 stream file containing an invalid `frame_rate_index` value. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the AC-4 configuration descriptor parsing path.

Impact:
The out-of-bounds read leads to an immediate process crash (SEGV READ at address 0x000000000000), resulting in Denial of Service. No evidence of arbitrary code execution was observed.

Fix / mitigation status:
The fix adds bounds validation for `frame_rate_index` before the fixed-size table lookups in `gf_odf_ac4_cfg_dsi_v1`. Users should upgrade to the release containing commit `13eb5b76560aaf7813b865a2ad433258478e2695` or apply that patch directly.

References

- Issue: github.com/gpac/gpac/issues/33
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/13

Credit
@sigdevel

#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory

##

CVE-2025-60483
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel at 2026-05-29T17:46:14.921Z ##

Security Advisory: CVE-2025-60483 - NULL Pointer Dereference in GPAC/MP4Box

Processing a crafted AC-4 stream triggers a NULL pointer dereference in `gf_ac4_pres_b_4_back_channels_present` when accessing presentation data with an invalid substream group index, causing MP4Box to crash.

Summary:
The `gf_ac4_pres_b_4_back_channels_present` function in `media_tools/av_parsers.c` accesses `pres->substream_groups` using an index derived from the stream. When a crafted AC-4 file specifies an invalid group index (e.g., group 4 that does not exist for presentation 0), the parser dereferences a NULL or near-NULL pointer at address 0x48 (72-byte struct offset) without first validating the pointer or the group index bounds. The process terminates with SIGSEGV.

CWE:
CWE-476 - NULL Pointer Dereference

Affected Component

```
media_tools/av_parsers.c:15703
Function: gf_ac4_pres_b_4_back_channels_present()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1617-g856674b22-master; commit `856674b226d6cbe28a941ad223be38194cbf7d37`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a specially crafted AC-4 stream file containing an invalid substream group reference. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the AC-4 demuxer and presentation parsing path.

Impact:
The near-NULL pointer dereference (READ at address 0x000000000048) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a near-NULL read that is not exploitable for control-flow hijacking.

Fix / mitigation status:
The fix adds bounds validation for the substream group index and a NULL check for the presentation pointer in `gf_ac4_pres_b_4_back_channels_present`. Users should upgrade to the release containing commit `13eb5b76560aaf7813b865a2ad433258478e2695` or apply that patch directly.

References

- Issue: github.com/gpac/gpac/issues/33
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/13

Credit
@sigdevel

##

sigdevel@infosec.exchange at 2026-05-29T17:46:14.000Z ##

Security Advisory: CVE-2025-60483 - NULL Pointer Dereference in GPAC/MP4Box

Processing a crafted AC-4 stream triggers a NULL pointer dereference in `gf_ac4_pres_b_4_back_channels_present` when accessing presentation data with an invalid substream group index, causing MP4Box to crash.

Summary:
The `gf_ac4_pres_b_4_back_channels_present` function in `media_tools/av_parsers.c` accesses `pres->substream_groups` using an index derived from the stream. When a crafted AC-4 file specifies an invalid group index (e.g., group 4 that does not exist for presentation 0), the parser dereferences a NULL or near-NULL pointer at address 0x48 (72-byte struct offset) without first validating the pointer or the group index bounds. The process terminates with SIGSEGV.

CWE:
CWE-476 - NULL Pointer Dereference

Affected Component

```
media_tools/av_parsers.c:15703
Function: gf_ac4_pres_b_4_back_channels_present()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1617-g856674b22-master; commit `856674b226d6cbe28a941ad223be38194cbf7d37`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a specially crafted AC-4 stream file containing an invalid substream group reference. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers the AC-4 demuxer and presentation parsing path.

Impact:
The near-NULL pointer dereference (READ at address 0x000000000048) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a near-NULL read that is not exploitable for control-flow hijacking.

Fix / mitigation status:
The fix adds bounds validation for the substream group index and a NULL check for the presentation pointer in `gf_ac4_pres_b_4_back_channels_present`. Users should upgrade to the release containing commit `13eb5b76560aaf7813b865a2ad433258478e2695` or apply that patch directly.

References

- Issue: github.com/gpac/gpac/issues/33
- PoC: github.com/sigdevel/pocs/blob/
- Fix: github.com/gpac/gpac/commit/13

Credit
@sigdevel

#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory

##

CVE-2026-48778
(0 None)

EPSS: 0.00%

1 posts

N/A

1 repos

https://github.com/atiilla/Notepad-8.9.6-PoC

sayzard@mastodon.sayzard.org at 2026-05-29T17:43:38.000Z ##

Two RCE vulnerabilities in Notepad++ (CVE-2026-48778, CVE-2026-48800)

Notepad++ v8.9.5에서 XML 설정 파일(config.xml, shortcuts.xml)을 통해 Windows ShellExecute API를 검증 없이 호출하는 두 건의 원격 코드 실행(RCE) 취약점(CVE-2026-48778, CVE-2026-48800)이 발견되었다. 공격자는 동일 사용자 권한으로 설정 파일을 조작해 임의 명령어 실행이 가능하며, -settingsDir 옵션을 통한 은밀한 공격도 가능하다. 취약점은 v8.9.6.1에서 패치되었으며, Semgrep 기반 정적 분석과 수동 검증을 통해 확인되었다. 이 취약점은 Windo...

ringzeropirate.github.io/en/ar

##

CVE-2026-48800
(0 None)

EPSS: 0.00%

1 posts

N/A

1 repos

https://github.com/atiilla/Notepad-8.9.6-PoC

sayzard@mastodon.sayzard.org at 2026-05-29T17:43:38.000Z ##

Two RCE vulnerabilities in Notepad++ (CVE-2026-48778, CVE-2026-48800)

Notepad++ v8.9.5에서 XML 설정 파일(config.xml, shortcuts.xml)을 통해 Windows ShellExecute API를 검증 없이 호출하는 두 건의 원격 코드 실행(RCE) 취약점(CVE-2026-48778, CVE-2026-48800)이 발견되었다. 공격자는 동일 사용자 권한으로 설정 파일을 조작해 임의 명령어 실행이 가능하며, -settingsDir 옵션을 통한 은밀한 공격도 가능하다. 취약점은 v8.9.6.1에서 패치되었으며, Semgrep 기반 정적 분석과 수동 검증을 통해 확인되었다. 이 취약점은 Windo...

ringzeropirate.github.io/en/ar

##

CVE-2025-60495
(0 None)

EPSS: 0.00%

2 posts

N/A

sigdevel at 2026-05-29T17:32:43.155Z ##

Security Advisory: CVE-2025-60495 - NULL Pointer Dereference in GPAC/MP4Box

Processing a crafted MP4 file with an inconsistent video sample entry triggers a NULL pointer dereference in `gf_media_get_color_info`, causing MP4Box to crash.

Summary:
The `gf_media_get_color_info` function in `media_tools/isom_tools.c` inspects codec-specific boxes nested inside a video sample entry. When a sample entry type (e.g., `v210`) unexpectedly contains an unrelated box (e.g., an `avcC` AVC Decoder Configuration Box), the function dereferences a near-NULL pointer (READ at address 0x000000000008). No NULL-check is performed before the dereference, and the process terminates with SIGSEGV.

CWE:
CWE-476 - NULL Pointer Dereference

Affected Component

```
media_tools/isom_tools.c:979
Function: gf_media_get_color_info()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1780-g50b5741f2-master; commit `50b5741f291126b610c59db433fc02e8a17f0c5d`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a specially crafted MP4 file containing a video sample entry whose type (e.g., `v210`) holds an incompatible child box (e.g., `avcC`). Local access is required; the victim must process the file with `MP4Box -split-size 8000 <crafted_file>` or any equivalent MP4Box operation that triggers muxer PID setup.

Impact:
The NULL pointer dereference (READ at address 0x8) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a near-NULL read that is not exploitable for control-flow hijacking.

Fix / mitigation status:
The fix adds the missing NULL check in `gf_media_get_color_info` before dereferencing the color-info pointer. Users should upgrade to the release containing commit `9beed3c0a2f38505c745e5376234e7ed66e8e0b1` or apply that patch directly.

References

- PoC: github.com/sigdevel/pocs/blob/
- Issue: github.com/gpac/gpac/issues/33
- Fix: github.com/gpac/gpac/commit/9b

Credit
@sigdevel

##

sigdevel@infosec.exchange at 2026-05-29T17:32:43.000Z ##

Security Advisory: CVE-2025-60495 - NULL Pointer Dereference in GPAC/MP4Box

Processing a crafted MP4 file with an inconsistent video sample entry triggers a NULL pointer dereference in `gf_media_get_color_info`, causing MP4Box to crash.

Summary:
The `gf_media_get_color_info` function in `media_tools/isom_tools.c` inspects codec-specific boxes nested inside a video sample entry. When a sample entry type (e.g., `v210`) unexpectedly contains an unrelated box (e.g., an `avcC` AVC Decoder Configuration Box), the function dereferences a near-NULL pointer (READ at address 0x000000000008). No NULL-check is performed before the dereference, and the process terminates with SIGSEGV.

CWE:
CWE-476 - NULL Pointer Dereference

Affected Component

```
media_tools/isom_tools.c:979
Function: gf_media_get_color_info()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected Version:
2.5-DEV-rev1780-g50b5741f2-master; commit `50b5741f291126b610c59db433fc02e8a17f0c5d`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a specially crafted MP4 file containing a video sample entry whose type (e.g., `v210`) holds an incompatible child box (e.g., `avcC`). Local access is required; the victim must process the file with `MP4Box -split-size 8000 <crafted_file>` or any equivalent MP4Box operation that triggers muxer PID setup.

Impact:
The NULL pointer dereference (READ at address 0x8) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a near-NULL read that is not exploitable for control-flow hijacking.

Fix / mitigation status:
The fix adds the missing NULL check in `gf_media_get_color_info` before dereferencing the color-info pointer. Users should upgrade to the release containing commit `9beed3c0a2f38505c745e5376234e7ed66e8e0b1` or apply that patch directly.

References

- PoC: github.com/sigdevel/pocs/blob/
- Issue: github.com/gpac/gpac/issues/33
- Fix: github.com/gpac/gpac/commit/9b

Credit
@sigdevel

#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory

##

CVE-2026-45662
(0 None)

EPSS: 0.00%

2 posts

N/A

thehackerwire@mastodon.social at 2026-05-29T17:00:04.000Z ##

🟠 CVE-2026-45662 - High (8.8)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-05-29T17:00:04.000Z ##

🟠 CVE-2026-45662 - High (8.8)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the s...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2025-60477
(0 None)

EPSS: 0.00%

1 posts

N/A

sigdevel@infosec.exchange at 2026-05-29T15:07:16.000Z ##

Security Advisory: CVE-2025-60477 - NULL Pointer Dereference in GPAC/MP4Box

Processing a crafted MP4 file containing specially crafted metadata with special characters triggers a NULL pointer dereference in `gf_filter_pid_resolve_file_template_ex`, causing MP4Box to crash during DASH segmentation.

Summary:
The `gf_filter_pid_resolve_file_template_ex` function in `filter_core/filter_pid.c` resolves output file name templates during DASH packaging. When input file metadata contains excessively long URLs or HTML-like special characters, the function reaches a `strncmp()` call without verifying that one of its arguments is non-NULL. The resulting dereference of a NULL pointer (READ at address 0x0) terminates the process immediately.

CWE:
CWE-476 - NULL Pointer Dereference

Affected component:
```
filter_core/filter_pid.c:9045
Function: gf_filter_pid_resolve_file_template_ex()
```

Affected Product:
MP4Box (GPAC Multimedia Open Source Project)

Affected version:
2.5-DEV-rev1617-g856674b22-master; commit `856674b226d6cbe28a941ad223be38194cbf7d37`. Any codebase equivalent to this commit that has not applied the fix commit is affected.

Attack Conditions:
An attacker supplies a specially crafted MP4 file whose metadata contains long URLs or HTML-like tags as embedded strings. Local access is required; the victim must invoke `MP4Box -dash 100 <crafted_file>` or any equivalent DASH segmentation command that triggers `dasher_setup_sources` and the subsequent template resolution path.

Impact:
The NULL pointer dereference (READ at address 0x000000000000) causes an immediate process crash, resulting in Denial of Service. No evidence of arbitrary code execution was observed; the faulting access is a NULL read that is not exploitable for control-flow hijacking.

Fix / mitigation status:
The fix adds the missing NULL check before the `strncmp()` call in `gf_filter_pid_resolve_file_template_ex`. Users should upgrade to the release containing commit `13eb5b76560aaf7813b865a2ad433258478e2695` or apply that patch directly.

References:
- Issue:github.com/gpac/gpac/issues/33
- Fix: github.com/gpac/gpac/commit/13
- PoC: github.com/sigdevel/pocs/blob/

Credit
@sigdevel

#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory

##

CVE-2026-44698
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-29T15:01:16.000Z ##

🟠 CVE-2026-44698 - High (8.3)

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app Web...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45555
(0 None)

EPSS: 0.00%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-29T15:00:19.000Z ##

🟠 CVE-2026-45555 - High (7.8)

Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAnalyzer assemblies referenced by the target solut...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45344
(0 None)

EPSS: 0.16%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-28T23:00:19.000Z ##

🟠 CVE-2026-45344 - High (8.1)

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on uninitialized LinkAce instances accepts attacker-controlled database credential fields and writes them back into .env without escap...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48116
(0 None)

EPSS: 0.05%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-28T23:00:10.000Z ##

🟠 CVE-2026-48116 - High (7.5)

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-controlled pattern parameter to ripgrep as a positi...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45039
(0 None)

EPSS: 0.04%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-28T20:01:47.000Z ##

🔴 CVE-2026-45039 - Critical (9.8)

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a shared secret. The function that produces this secret, get_shared_secret(...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45296
(0 None)

EPSS: 0.03%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-28T19:01:48.000Z ##

🟠 CVE-2026-45296 - High (7.7)

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey routes that trust a caller-provided projectKey after validating only that the API key itself is valid and that the target project...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45323
(0 None)

EPSS: 0.04%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-28T19:00:27.000Z ##

🔴 CVE-2026-45323 - Critical (9.6)

MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect (repeated) radio range to execute arbitrary java...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-47761
(0 None)

EPSS: 0.03%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-28T17:00:50.000Z ##

🟠 CVE-2026-47761 - High (8.7)

TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is re...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-42197
(0 None)

EPSS: 0.03%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-28T16:01:12.000Z ##

🟠 CVE-2026-42197 - High (8.7)

RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execute arbitrary JavaScript in an administrator's bro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

forgejo@floss.social at 2026-05-28T14:24:22.000Z ##

A security vulnerability labelled CVE-2026-27771 affecting Forgejo and Gitea is being widely reported recently.

Packages in Forgejo are visible to unauthenticated users if they are published under a public owner, as designed. It is not a security vulnerability, but a misunderstanding about the permissions and a good opportunity for users to review that they are not in a misconfigured state.

Please see the statement issued by the security team here for more details: codeberg.org/forgejo/website/i

##

CVE-2026-48095
(0 None)

EPSS: 0.00%

2 posts

N/A

1 repos

https://github.com/HORKimhab/CVE-2026-48095

tomshw@mastodon.social at 2026-05-28T12:10:12.000Z ##

🔒 7-Zip ha corretto una falla critica, ma chi non aggiorna resta esposto: verifica la versione e installa subito l’ultima release. #Cybersecurity #7Zip

🔗 tomshw.it/hardware/7-zip-falla

##

beyondmachines1@infosec.exchange at 2026-05-28T08:01:07.000Z ##

Critical 7-Zip Vulnerability Allows Remote Code Execution via NTFS Handler

7-Zip version 26.00 and earlier contain a critical heap buffer overflow (CVE-2026-48095) in the NTFS handler that allows attackers to execute arbitrary code via a crafted archive. The flaw is extension-agnostic and can be triggered simply by opening a malicious file.

**If you use 7-Zip, update to version 26.01 or later immediately. Versions 26.00 and earlier let attackers take over your system just by opening a malicious archive. Until you've updated, do not open any archive or disk image files from untrusted or unexpected sources, regardless of the file extension.**
#cybersecurity #infosec #advisory #vulnerability
beyondmachines.net/event_detai

##

CVE-2026-46402
(0 None)

EPSS: 0.06%

2 posts

N/A

offseq@infosec.exchange at 2026-05-28T06:00:26.000Z ##

⚠️ HIGH severity: Microsoft UFO 3.0.1-4-ge2626659 has a path traversal vuln (CVE-2026-46402). Authenticated users can write files outside logs/. No patch yet — restrict access & monitor input. radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #PathTraversal #CVE202646402

##

thehackerwire@mastodon.social at 2026-05-28T00:00:12.000Z ##

🟠 CVE-2026-46402 - High (8.1)

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can sup...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44590
(0 None)

EPSS: 0.85%

1 posts

N/A

1 repos

https://github.com/Astaruf/CVE-2026-44590

thehackerwire@mastodon.social at 2026-05-28T05:00:38.000Z ##

🔴 CVE-2026-44590 - Critical (9.3)

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can ex...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-45102
(0 None)

EPSS: 0.06%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-28T03:01:14.000Z ##

🔴 CVE-2026-45102 - Critical (9.9)

OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm module as an isolation primitive. This API was not designed for that and can be escaped via error objects and infinite recursion. T...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44888
(0 None)

EPSS: 0.05%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-28T03:01:04.000Z ##

🔴 CVE-2026-44888 - Critical (9.8)

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplied numeric config values (e.g., SMTP_PORT) directly into
pialert.conf without validation. Since pia...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48064
(0 None)

EPSS: 0.06%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-28T00:01:16.000Z ##

🟠 CVE-2026-48064 - High (8.1)

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is configured with deny_remote=false in pam_usb (commonly done for display managers such as gdm-password or lightdm to bypass pro...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44713
(0 None)

EPSS: 0.02%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-27T22:00:51.000Z ##

🟠 CVE-2026-44713 - High (8.8)

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the user's $TMUX environment variable, splits it on commas, and interpolates the socket-path component directly into a shell comman...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-44712
(0 None)

EPSS: 0.02%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-27T22:00:42.000Z ##

🟠 CVE-2026-44712 - High (8.2)

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the config causes root RCE when pamusb-conf --reset-pads is run. A USB device with a crafted filesystem UUI...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-46425
(0 None)

EPSS: 0.04%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-27T19:01:42.000Z ##

🔴 CVE-2026-46425 - Critical (9.9)

Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCIM router: requireSCIM (checks the Enterprise feature flag and SCIM config) and doInScimContext (se...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48152
(0 None)

EPSS: 0.04%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-27T19:01:22.000Z ##

🟠 CVE-2026-48152 - High (8.1)

Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by generic TABLE READ, not by Builder/Admin permission or datasource-specific ownership/resource checks. The built-in Basic app use...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48150
(0 None)

EPSS: 0.05%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-27T19:00:20.000Z ##

🔴 CVE-2026-48150 - Critical (9)

Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAdmin middleware, which passes any user who is a builder for the app id in the x-budibase-app-id header. That check admits both g...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48149
(0 None)

EPSS: 0.03%

1 posts

N/A

thehackerwire@mastodon.social at 2026-05-27T19:00:10.000Z ##

🟠 CVE-2026-48149 - High (8.1)

Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text component renders markdown by assigning marked.parse(markdown) straight to innerHTML with no sanitizer (packages/bbui/src/Markdown/MarkdownViewer.svelte:22). Any colu...

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

Visit counter For Websites