##
Updated at UTC 2026-05-27T05:03:45.585144
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-48962 | 0 | 0.00% | 2 | 0 | 2026-05-27T04:16:31.333000 | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File:: | |
| CVE-2026-49017 | None | 0.00% | 2 | 0 | 2026-05-27T03:30:36 | In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite | |
| CVE-2026-9632 | 8.8 | 0.00% | 2 | 0 | 2026-05-27T02:16:36.067000 | A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by | |
| CVE-2026-9631 | 8.8 | 0.00% | 2 | 0 | 2026-05-27T02:16:35.907000 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affe | |
| CVE-2026-9628 | 8.8 | 0.00% | 2 | 0 | 2026-05-27T02:16:35.747000 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected | |
| CVE-2026-9627 | 8.8 | 0.00% | 2 | 0 | 2026-05-27T02:16:35.583000 | A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This | |
| CVE-2026-9207 | 8.8 | 0.00% | 2 | 0 | 2026-05-27T02:16:35.130000 | Tanium addressed an unauthorized code execution vulnerability in Connect. | |
| CVE-2026-48689 | 9.8 | 0.00% | 1 | 0 | 2026-05-27T02:16:33.807000 | FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buf | |
| CVE-2025-43306 | 7.8 | 0.00% | 2 | 0 | 2026-05-27T02:16:32.963000 | A logic issue was addressed with improved checks. This issue is fixed in macOS S | |
| CVE-2026-42013 | 8.2 | 0.00% | 2 | 0 | 2026-05-27T00:31:34 | A flaw was found in gnutls. When validating certificates, an oversized Subject A | |
| CVE-2026-5260 | 8.2 | 0.00% | 2 | 0 | 2026-05-27T00:31:34 | A flaw was found in libgnutls. A remote attacker, by sending an extremely short | |
| CVE-2026-9312 | None | 0.00% | 2 | 0 | 2026-05-27T00:31:29 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Ente | |
| CVE-2026-44966 | 8.3 | 0.00% | 2 | 0 | 2026-05-26T22:16:43.293000 | Velocity.js is a JavaScript implementation of the Apache Velocity template engin | |
| CVE-2026-44900 | 8.1 | 0.00% | 2 | 0 | 2026-05-26T22:16:42.873000 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrast | |
| CVE-2026-43988 | 7.5 | 0.00% | 2 | 0 | 2026-05-26T22:16:42.303000 | Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26 | |
| CVE-2026-48686 | 9.8 | 0.00% | 1 | 0 | 2026-05-26T21:32:56 | FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflo | |
| CVE-2026-5426 | 7.5 | 0.08% | 1 | 1 | 2026-05-26T21:32:41 | Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver de | |
| CVE-2026-9642 | 9.8 | 0.00% | 2 | 0 | 2026-05-26T21:32:08 | There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthentica | |
| CVE-2026-8676 | 8.8 | 0.00% | 2 | 0 | 2026-05-26T21:32:07 | An attacker is able to downgrade the security of a Bluetooth LE connection by de | |
| CVE-2026-8854 | 7.5 | 0.00% | 2 | 0 | 2026-05-26T20:27:32.703000 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional | |
| CVE-2026-48172 | 9.8 | 0.01% | 6 | 2 | 2026-05-26T20:19:13.460000 | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possi | |
| CVE-2026-25104 | 7.8 | 0.01% | 2 | 0 | 2026-05-26T20:16:40.787000 | MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability | |
| CVE-2026-44469 | 7.8 | 0.01% | 1 | 0 | 2026-05-26T20:00:24.897000 | The affected product extracts installation files to a temporary directory with i | |
| CVE-2026-9058 | 0 | 0.04% | 2 | 0 | 2026-05-26T19:59:22.323000 | Szafir SDK returns a success status code from the cryptographic digital signatur | |
| CVE-2026-45247 | 9.8 | 0.00% | 1 | 0 | 2026-05-26T19:50:21.747000 | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a | |
| CVE-2026-42774 | 9.3 | 0.03% | 1 | 0 | 2026-05-26T19:31:20.323000 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-42497 | 0 | 0.02% | 1 | 0 | 2026-05-26T19:21:53.013000 | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker control | |
| CVE-2025-1782 | 9.9 | 0.00% | 1 | 0 | 2026-05-26T19:08:15.080000 | In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is n | |
| CVE-2026-7374 | 9.9 | 0.00% | 1 | 0 | 2026-05-26T19:08:15.080000 | A flaw was found in KubeVirt's virt-handler component. This vulnerability allows | |
| CVE-2026-5222 | 0 | 0.04% | 2 | 0 | 2026-05-26T19:08:15.080000 | Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party regis | |
| CVE-2026-5223 | 0 | 0.04% | 3 | 0 | 2026-05-26T19:08:15.080000 | Cargo incorrectly handled symlinks inside of crate tarballs downloaded from thir | |
| CVE-2026-8620 | 7.5 | 0.00% | 2 | 0 | 2026-05-26T19:06:14.330000 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8 | |
| CVE-2026-9435 | 9.8 | 0.89% | 1 | 0 | 2026-05-26T18:59:55.850000 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affect | |
| CVE-2026-9434 | 9.8 | 0.89% | 1 | 0 | 2026-05-26T18:59:55.850000 | A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b202005 | |
| CVE-2026-7454 | 7.8 | 0.00% | 2 | 0 | 2026-05-26T18:31:59 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force | |
| CVE-2026-8855 | 8.1 | 0.00% | 2 | 0 | 2026-05-26T18:31:59 | IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o | |
| CVE-2026-9170 | 7.5 | 0.00% | 2 | 0 | 2026-05-26T18:31:51 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8 | |
| CVE-2026-8856 | 7.7 | 0.00% | 2 | 0 | 2026-05-26T18:31:51 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration | |
| CVE-2026-25112 | 7.8 | 0.00% | 1 | 0 | 2026-05-26T18:31:42 | A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows | |
| CVE-2026-9496 | 7.5 | 0.04% | 1 | 0 | 2026-05-26T15:33:18 | Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service ( | |
| CVE-2026-46368 | 8.8 | 0.00% | 1 | 0 | 2026-05-26T15:32:17 | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on f | |
| CVE-2026-4480 | 8.5 | 0.00% | 1 | 0 | 2026-05-26T15:32:17 | A flaw was found in the Samba printing subsystem. Samba passes the client-contro | |
| CVE-2026-48131 | 8.1 | 0.00% | 1 | 0 | 2026-05-26T15:32:16 | The VPN service may mishandle an unexpected IKE fragment value received on the I | |
| CVE-2026-9543 | 9.8 | 0.00% | 1 | 0 | 2026-05-26T15:32:16 | A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected | |
| CVE-2026-44468 | 7.8 | 0.01% | 1 | 0 | 2026-05-26T13:31:03 | The affected product creates a directory with insecure default permissions durin | |
| CVE-2026-8047 | 7.5 | 0.07% | 1 | 0 | 2026-05-26T13:31:02 | The affected products perform improper length checking when parsing incoming HTT | |
| CVE-2026-8046 | 8.1 | 0.10% | 1 | 0 | 2026-05-26T13:31:02 | The affected products insufficiently verify authorization when deleting user acc | |
| CVE-2026-42773 | 9.3 | 0.03% | 1 | 0 | 2026-05-26T13:30:58 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-39661 | 7.5 | 0.11% | 1 | 0 | 2026-05-26T13:30:57 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP | |
| CVE-2026-25713 | 7.8 | 0.01% | 1 | 0 | 2026-05-26T13:30:56 | MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability | |
| CVE-2026-9478 | 9.8 | 0.89% | 1 | 0 | 2026-05-26T13:30:56 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted | |
| CVE-2026-42496 | None | 0.02% | 1 | 0 | 2026-05-26T13:30:54 | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker contro | |
| CVE-2026-9436 | 9.8 | 0.94% | 1 | 0 | 2026-05-26T13:30:46 | A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted elem | |
| CVE-2026-9404 | 9.8 | 0.89% | 1 | 0 | 2026-05-26T13:30:41 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This aff | |
| CVE-2026-45659 | 8.8 | 0.50% | 2 | 1 | 2026-05-26T13:30:30 | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho | |
| CVE-2026-45250 | 7.8 | 0.01% | 2 | 1 | 2026-05-22T08:16:14.847000 | The setcred(2) system call is only available to privileged users. However, befo | |
| CVE-2010-0249 | 8.8 | 88.68% | 2 | 0 | 2026-05-21T12:57:01.463000 | Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 o | |
| CVE-2026-9082 | 6.5 | 17.33% | 3 | 7 | template | 2026-05-20T21:32:36 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti |
| CVE-2026-41091 | 7.8 | 5.94% | 2 | 2 | 2026-05-20T18:31:35 | Improper link resolution before file access ('link following') in Microsoft Defe | |
| CVE-2026-42096 | None | 0.04% | 1 | 1 | 2026-05-19T15:31:29 | Sparx Pro Cloud Server is vulnerable to Broken Access Control within communicati | |
| CVE-2026-45829 | 0 | 0.17% | 1 | 2 | 2026-05-19T14:16:46.977000 | A pre-authentication, code injection vulnerability in version 1.0.0 or later of | |
| CVE-2026-45298 | 8.6 | 0.00% | 2 | 0 | 2026-05-18T16:41:41 | ## Summary In a default dozzle deploy (the documented quickstart, no `DOZZLE_AU | |
| CVE-2026-45574 | 8.1 | 0.00% | 2 | 0 | 2026-05-15T18:29:32 | ### Impact An attacker on the network path between the ePA service and the Konne | |
| CVE-2026-41089 | 9.8 | 0.13% | 1 | 0 | 2026-05-15T15:42:17.907000 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker | |
| CVE-2026-6637 | 8.8 | 0.04% | 1 | 0 | 2026-05-14T15:31:59 | Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged datab | |
| CVE-2026-0265 | None | 0.03% | 1 | 2 | 2026-05-13T18:31:07 | An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software en | |
| CVE-2026-28952 | 7.5 | 0.02% | 7 | 0 | 2026-05-13T14:08:26.420000 | An integer overflow was addressed with improved input validation. This issue is | |
| CVE-2026-28910 | 3.3 | 0.01% | 1 | 0 | 2026-05-13T00:49:16 | This issue was addressed with improved permissions checking. This issue is fixed | |
| CVE-2026-26980 | 9.4 | 63.49% | 4 | 3 | template | 2026-05-12T13:31:01 | ### Impact A SQL injection vulnerability existed in Ghost's Content API that al |
| CVE-2026-44895 | None | 0.00% | 2 | 0 | 2026-05-09T00:10:30 | ## SSE Transport Has No Authentication and Wildcard CORS, Exposing All 86 GitLab | |
| CVE-2026-44843 | 8.2 | 0.00% | 2 | 0 | 2026-05-08T23:07:34 | LangChain contains older runtime code paths that deserialize run inputs, run out | |
| CVE-2026-26928 | None | 0.01% | 2 | 0 | 2026-04-02T15:31:40 | SzafirHost downloads necessary files in the context of the initiating web page. | |
| CVE-2025-15284 | 3.7 | 0.07% | 1 | 0 | 2026-02-26T19:57:11.663000 | Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.Th | |
| CVE-2026-3172 | 8.1 | 0.06% | 1 | 0 | 2026-02-25T21:31:25 | Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 all | |
| CVE-2025-62582 | 9.8 | 0.03% | 3 | 0 | 2026-01-20T16:58:23.900000 | Delta Electronics DIAView has multiple vulnerabilities. | |
| CVE-2025-20286 | 9.9 | 0.18% | 1 | 0 | 2025-06-04T18:30:58 | A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud | |
| CVE-2025-46273 | 9.8 | 0.58% | 1 | 0 | 2025-04-25T00:32:07 | UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated at | |
| CVE-2025-27740 | 8.8 | 0.80% | 1 | 0 | 2025-04-08T18:35:03 | Weak authentication in Windows Active Directory Certificate Services allows an a | |
| CVE-2021-21735 | None | 0.17% | 1 | 1 | 2023-01-29T05:06:59 | A ZTE product has an information leak vulnerability. Due to improper permission | |
| CVE-2026-44905 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2025-70103 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-43935 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-33636 | 0 | 0.04% | 1 | 0 | N/A | ||
| CVE-2026-33416 | 0 | 0.02% | 1 | 0 | N/A | ||
| CVE-2026-40172 | 0 | 0.01% | 1 | 0 | N/A |
updated 2026-05-27T04:16:31.333000
2 posts
⚠️ HIGH severity: CVE-2026-48962 in PMQS IO::Compress (Perl <2.220) enables eval injection via crafted glob strings. Arbitrary Perl code may execute with process privileges. Restrict untrusted input & monitor for patches. https://radar.offseq.com/threat/cve-2026-48962-cwe-95-improper-neutralization-of-d-a4f0eb17 #OffSeq #Vuln #Perl #Infosec
##⚠️ HIGH severity: CVE-2026-48962 in PMQS IO::Compress (Perl <2.220) enables eval injection via crafted glob strings. Arbitrary Perl code may execute with process privileges. Restrict untrusted input & monitor for patches. https://radar.offseq.com/threat/cve-2026-48962-cwe-95-improper-neutralization-of-d-a4f0eb17 #OffSeq #Vuln #Perl #Infosec
##updated 2026-05-27T03:30:36
2 posts
CVE-2026-49017: HIGH-severity in OpenStack Swift 2.36.0 & 2.37.0. Infinite loop in s3api lets authenticated attackers exhaust proxy workers → DoS risk. Patch to 2.36.2 or 2.37.2+ now! 🔄 https://radar.offseq.com/threat/cve-2026-49017-cwe-835-loop-with-unreachable-exit--0557d1bf #OffSeq #OpenStack #Vuln #DoS
##CVE-2026-49017: HIGH-severity in OpenStack Swift 2.36.0 & 2.37.0. Infinite loop in s3api lets authenticated attackers exhaust proxy workers → DoS risk. Patch to 2.36.2 or 2.37.2+ now! 🔄 https://radar.offseq.com/threat/cve-2026-49017-cwe-835-loop-with-unreachable-exit--0557d1bf #OffSeq #OpenStack #Vuln #DoS
##updated 2026-05-27T02:16:36.067000
2 posts
🟠 CVE-2026-9632 - High (8.8)
A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web Management Interface. Executing a manipulation of the argument Profile can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9632/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-9632 - High (8.8)
A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web Management Interface. Executing a manipulation of the argument Profile can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9632/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T02:16:35.907000
2 posts
🟠 CVE-2026-9631 - High (8.8)
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the component Web Management Interface. Performing a manipulation of ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9631/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-9631 - High (8.8)
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the component Web Management Interface. Performing a manipulation of ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9631/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T02:16:35.747000
2 posts
🟠 CVE-2026-9628 - High (8.8)
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Management Interface. This manipulation of the argument PPTP server address/userna...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9628/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-9628 - High (8.8)
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Management Interface. This manipulation of the argument PPTP server address/userna...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9628/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T02:16:35.583000
2 posts
🟠 CVE-2026-9627 - High (8.8)
A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-9627 - High (8.8)
A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9627/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T02:16:35.130000
2 posts
🟠 CVE-2026-9207 - High (8.8)
Tanium addressed an unauthorized code execution vulnerability in Connect.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9207/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-9207 - High (8.8)
Tanium addressed an unauthorized code execution vulnerability in Connect.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9207/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T02:16:33.807000
1 posts
🚨 EUVD-2026-31950
📊 Score: n/a
📅 Updated: 2026-05-26
📝 FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31950
##updated 2026-05-27T02:16:32.963000
2 posts
🟠 CVE-2025-43306 - High (7.8)
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-43306/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2025-43306 - High (7.8)
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-43306/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T00:31:34
2 posts
🟠 CVE-2026-42013 - High (8.2)
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42013/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-42013 - High (8.2)
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-42013/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T00:31:34
2 posts
🟠 CVE-2026-5260 - High (8.2)
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnera...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5260/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-5260 - High (8.2)
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnera...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5260/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-27T00:31:29
2 posts
🚨 CRITICAL: CVE-2026-9312 (SSRF) in GitHub Enterprise Server 3.16.0 – 3.21.0 lets unauth attackers access internal services via crafted uploads. Patch to 3.16.20+ ASAP! Details: https://radar.offseq.com/threat/cve-2026-9312-cwe-918-server-side-request-forgery--b1f49fcb #OffSeq #SSRF #GitHub #Vuln
##🚨 CRITICAL: CVE-2026-9312 (SSRF) in GitHub Enterprise Server 3.16.0 – 3.21.0 lets unauth attackers access internal services via crafted uploads. Patch to 3.16.20+ ASAP! Details: https://radar.offseq.com/threat/cve-2026-9312-cwe-918-server-side-request-forgery--b1f49fcb #OffSeq #SSRF #GitHub #Vuln
##updated 2026-05-26T22:16:43.293000
2 posts
🟠 CVE-2026-44966 - High (8.3)
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity templ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44966/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44966 - High (8.3)
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity templ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44966/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T22:16:42.873000
2 posts
🟠 CVE-2026-44900 - High (8.1)
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45 discards the boolean return value of Signature....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44900/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44900 - High (8.1)
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45 discards the boolean return value of Signature....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44900/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T22:16:42.303000
2 posts
🟠 CVE-2026-43988 - High (7.5)
Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When processing malformed network packets containing co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43988/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-43988 - High (7.5)
Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When processing malformed network packets containing co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43988/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T21:32:56
1 posts
🚨 EUVD-2026-31950
📊 Score: n/a
📅 Updated: 2026-05-26
📝 FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31950
##updated 2026-05-26T21:32:41
1 posts
1 repos
Hackers Exploit KnowledgeDeliver Flaw to Install Web Shells
Hackers have exploited a critical flaw in KnowledgeDeliver, using it as a zero-day to sneakily install a powerful .NET web shell called Godzilla on vulnerable servers. This sneaky attack was made possible by a deserialization vulnerability, CVE-2026-5426, that allowed threat actors to execute code at the operating-system level.
#Cve20265426 #ZeroDay #WebShell #ViewstateDeserialization #Net
##updated 2026-05-26T21:32:08
2 posts
🔴 CVE-2026-9642 - Critical (9.8)
There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access)
An unauthenticated remote attacker can access configured databases in a DIAView project.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9642/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-9642 - Critical (9.8)
There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access)
An unauthenticated remote attacker can access configured databases in a DIAView project.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9642/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T21:32:07
2 posts
🟠 CVE-2026-8676 - High (8.8)
An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8676/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-8676 - High (8.8)
An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8676/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T20:27:32.703000
2 posts
🟠 CVE-2026-8854 - High (7.5)
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8854/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-8854 - High (7.5)
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8854/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T20:19:13.460000
6 posts
2 repos
🏛️ CISA Adds LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
📝 CISA adds CVE-2026-48172 to KEV Catalog, affecting federal agencies.
📰 Alerts
##🚨 [CISA-2026:0526] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0526)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-48172 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48172)
- Name: LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: LiteSpeed
- Product: cPanel Plugin
- Notes: https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-48172
#SecDB #InfoSec #CVE #CISA_KEV #cisa_20260526 #cisa20260526 #cve_2026_48172 #cve202648172
##CVE ID: CVE-2026-48172
Vendor: LiteSpeed
Product: cPanel Plugin
Date Added: 2026-05-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48172
🏛️ CISA Adds LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
📝 CISA adds CVE-2026-48172 to KEV Catalog, affecting federal agencies.
📰 Alerts
##🚨 [CISA-2026:0526] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0526)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2026-48172 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48172)
- Name: LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: LiteSpeed
- Product: cPanel Plugin
- Notes: https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/ ; https://nvd.nist.gov/vuln/detail/CVE-2026-48172
#SecDB #InfoSec #CVE #CISA_KEV #cisa_20260526 #cisa20260526 #cve_2026_48172 #cve202648172
##CVE ID: CVE-2026-48172
Vendor: LiteSpeed
Product: cPanel Plugin
Date Added: 2026-05-26
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48172
updated 2026-05-26T20:16:40.787000
2 posts
🟠 CVE-2026-25104 - High (7.8)
MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-25104/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🚨 HIGH severity: CVE-2026-25104 impacts MediaArea MediaInfoLib 26.01. Integer underflow in LXF parsing can trigger heap-based buffer overflow. No patch yet — restrict untrusted LXF file parsing and monitor for updates. https://radar.offseq.com/threat/cve-2026-25104-cwe-191-integer-underflow-wrap-or-w-860fcfcf #OffSeq #Vulnerability #Infosec
##updated 2026-05-26T20:00:24.897000
1 posts
#OT #Advisory VDE-2026-055
CODESYS Development System - Incorrect Default Permissions
Two local privilege escalation vulnerabilities were identified in the CODESYS Development System. Specifically, the PackageManager and the IPM create temporary directories with insecure default permissions when executed with administrative privileges. This allows low-privileged local users to modify a temporary bootstrap file to force the deployment of arbitrary components, or to exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition to replace digitally verified installation files with malicious ones prior to installation. Both flaws bypass intended security boundaries during the installation of packages or add-ons.
#CVE CVE-2026-44469, CVE-2026-44468
https://certvde.com/en/advisories/vde-2026-055/
#CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-09_vde-2026-055.json
##updated 2026-05-26T19:59:22.323000
2 posts
Na CONFidence 2026 Michał kończy właśnie opowieść o krytycznych lukach, które umożliwiały zalogowanie się na konto dowolnego obywatela w wielu kluczowych systemach administracji publicznej, a @zaufanatrzeciastrona opublikowała przed chwilą cykl artykułów jego autorstwa, dokładnie wyjaśniający problem. Zdecydowanie polecam (zarwałam noc, żeby je na czas skorygować ;-))
👉 Zdalne wykonanie kodu w SzafirHost – [CVE-2026-26928] [Badanie e-podpisów, cz. 1] – https://zaufanatrzeciastrona.pl/post/zdalne-wykonanie-kodu-w-szafirhost-cve-2026-26928-badanie-e-podpisow-cz-1/
👉 Hakowanie e-Sądu YubiKeyem – [Badanie e-podpisów, cz. 2] – https://zaufanatrzeciastrona.pl/post/hakowanie-e-sadu-yubikeyem-badanie-e-podpisow-cz-2/
👉 Ominięcie uwierzytelniania w ZUS-ie i systemach e-Zdrowia, czyli o krok od cyberchaosu – [CVE-2026-9058] [Badanie e-podpisów, cz. 3] – https://zaufanatrzeciastrona.pl/post/ominiecie-uwierzytelniania-w-zus-ie-i-systemach-e-zdrowia-czyli-o-krok-od-cyberchaosu-cve-2026-9058-badanie-e-podpisow-cz-3/
👉 Podsumowanie: Krytyczna podatność umożliwiająca całkowite ominięcie logowania w ZUS-ie, e-Sądzie i systemach e-Zdrowia – https://zaufanatrzeciastrona.pl/post/podsumowanie-krytyczna-podatnosc-umozliwiajaca-calkowite-ominiecie-logowania-w-zus-ie-e-sadzie-i-systemach-e-zdrowia/
Michał odkrył sposób na logowanie jako dowolny użytkownik do eZUS-u, E-Sądu, eZdrowia i innych rządowych systemów. Poczytajcie, bo to najgrubsze odkrycie tego roku w PL
1. https://zaufanatrzeciastrona.pl/post/zdalne-wykonanie-kodu-w-szafirhost-cve-2026-26928-badanie-e-podpisow-cz-1/
2. https://zaufanatrzeciastrona.pl/post/hakowanie-e-sadu-yubikeyem-badanie-e-podpisow-cz-2/
3. https://zaufanatrzeciastrona.pl/post/ominiecie-uwierzytelniania-w-zus-ie-i-systemach-e-zdrowia-czyli-o-krok-od-cyberchaosu-cve-2026-9058-badanie-e-podpisow-cz-3/
4. https://zaufanatrzeciastrona.pl/post/podsumowanie-krytyczna-podatnosc-umozliwiajaca-calkowite-ominiecie-logowania-w-zus-ie-e-sadzie-i-systemach-e-zdrowia/
updated 2026-05-26T19:50:21.747000
1 posts
🔴 CVE-2026-45247 - Critical (9.8)
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarm...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45247/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T19:31:20.323000
1 posts
🚨 CRITICAL SQL Injection (CVE-2026-42774) in Crocoblock JetEngine ≤ 3.8.8.1 (CVSS 9.3). Unauthenticated attackers could access sensitive DB data. No vendor patch yet — restrict access & monitor activity. More: https://radar.offseq.com/threat/cve-2026-42774-cwe-89-improper-neutralization-of-s-114434a4 #OffSeq #SQLInjection #WordPress
##updated 2026-05-26T19:21:53.013000
1 posts
🛡️ CVE-2026-42497 (HIGH): BINGOS Archive::Tar <3.08 lets attackers create hardlinks outside extraction dirs, risking file overwrite or privilege escalation. No patch yet — avoid untrusted tar files. Details: https://radar.offseq.com/threat/cve-2026-42497-cwe-59-improper-link-resolution-bef-91880c39 #OffSeq #Vulnerability #Perl #Security
##updated 2026-05-26T19:08:15.080000
1 posts
CVE-2025-1782 - Critical RCE in HylaFAX. Unpatched. CVSS 9.9. Authenticated users can exploit file inclusion for full server compromise. Isolate or disable immediately. #CVE #HylaFAX #infosec
##updated 2026-05-26T19:08:15.080000
1 posts
🔴 CVE-2026-7374 - Critical (9.9)
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7374/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T19:08:15.080000
2 posts
JUST IN: Security Advisory for Cargo (CVE-2026-5222)
>> Cargo CVE-2026-5222: Sparse registry URL normalization flaw lets attackers steal credentials from third-party registries under niche conditions. Fixed in Rust 1.96.
##updated 2026-05-26T19:08:15.080000
3 posts
JUST IN: Security Advisory for Cargo (CVE-2026-5223)
>> Cargo CVE-2026-5223: Malicious crates with symlinks can override other crates from the same third-party registry. Fixed in Rust 1.96.0.
##updated 2026-05-26T19:06:14.330000
2 posts
🟠 CVE-2026-8620 - High (7.5)
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a special...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8620/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-8620 - High (7.5)
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a special...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8620/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T18:59:55.850000
1 posts
🛡️ CVE-2026-9435: Critical OS command injection in Totolink A8000RU (fw 7.1cu.643_b20200521) allows unauthenticated remote code execution. No patch yet — restrict web UI & monitor advisories. Exploit is public! https://radar.offseq.com/threat/cve-2026-9435-os-command-injection-in-totolink-a80-a8a549f3 #OffSeq #CVE20269435 #IoTSecurity
##updated 2026-05-26T18:59:55.850000
1 posts
Totolink A8000RU (v7.1cu.643_b20200521) hit by CRITICAL OS command injection (CVE-2026-9434). Remote unauthenticated attackers may gain full control. No fix yet — restrict management access & monitor for updates. https://radar.offseq.com/threat/cve-2026-9434-os-command-injection-in-totolink-a80-c89a76b9 #OffSeq #Vulnerability #Router
##updated 2026-05-26T18:31:59
2 posts
🟠 CVE-2026-7454 - High (7.8)
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7454/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-7454 - High (7.8)
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7454/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T18:31:59
2 posts
🟠 CVE-2026-8855 - High (8.1)
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-8855 - High (8.1)
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T18:31:51
2 posts
🟠 CVE-2026-9170 - High (7.5)
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to denial of service and a potential remote code execution due to impr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-9170 - High (7.5)
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to denial of service and a potential remote code execution due to impr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9170/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T18:31:51
2 posts
🟠 CVE-2026-8856 - High (7.7)
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8856/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-8856 - High (7.7)
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8856/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T18:31:42
1 posts
🟠 CVE-2026-25112 - High (7.8)
A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-25112/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T15:33:18
1 posts
⚠️ HIGH severity: CVE-2026-9496 impacts pacote 11.2.7 in cloud-hosted setups. Crafted spec.rawSpec can trigger DoS via CPU exhaustion. Vendor patches are rolling out — verify your service is updated. No active exploitation seen. https://radar.offseq.com/threat/cve-2026-9496-denial-of-service-dos-in-pacote-27dd65a5 #OffSeq #DoS #CloudSec
##updated 2026-05-26T15:32:17
1 posts
🟠 CVE-2026-46368 - High (8.8)
luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-46368/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T15:32:17
1 posts
🟠 CVE-2026-4480 - High (8.5)
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J"
substitution character without escaping shell meta characters. A re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4480/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T15:32:16
1 posts
🟠 CVE-2026-48131 - High (8.1)
The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disrupt...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-48131/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T15:32:16
1 posts
🔴 CVE-2026-9543 - Critical (9.8)
A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os comman...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9543/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T13:31:03
1 posts
#OT #Advisory VDE-2026-055
CODESYS Development System - Incorrect Default Permissions
Two local privilege escalation vulnerabilities were identified in the CODESYS Development System. Specifically, the PackageManager and the IPM create temporary directories with insecure default permissions when executed with administrative privileges. This allows low-privileged local users to modify a temporary bootstrap file to force the deployment of arbitrary components, or to exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition to replace digitally verified installation files with malicious ones prior to installation. Both flaws bypass intended security boundaries during the installation of packages or add-ons.
#CVE CVE-2026-44469, CVE-2026-44468
https://certvde.com/en/advisories/vde-2026-055/
#CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-09_vde-2026-055.json
##updated 2026-05-26T13:31:02
1 posts
#OT #Advisory VDE-2026-057
CODESYS Control - Out-of-bounds Write
Successful exploitation allows an unauthenticated remote attacker to trigger an out-of-bounds write, causing the CODESYS Control Runtime to crash and resulting in a denial of service on the affected device.
#CVE CVE-2026-8047
https://certvde.com/en/advisories/vde-2026-057/
#CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-10_vde-2026-057.json
##updated 2026-05-26T13:31:02
1 posts
#OT #Advisory VDE-2026-056
CODESYS Control - Incorrect Authorization
The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups including the visualization administrators group, which is intended solely to manage visualization users.
#CVE CVE-2026-8046
https://certvde.com/en/advisories/vde-2026-056/
#CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-08_vde-2026-056.json
##updated 2026-05-26T13:30:58
1 posts
🚨 CRITICAL: CVE-2026-42773 in eMagicOne Store Manager (≤1.3.2) enables unauthenticated Blind SQL Injection (CVSS 9.3). No patch yet. Restrict app access & monitor databases. Details: https://radar.offseq.com/threat/cve-2026-42773-cwe-89-improper-neutralization-of-s-18afe907 #OffSeq #SQLInjection #Vuln #eMagicOne
##updated 2026-05-26T13:30:57
1 posts
🟠 CVE-2026-39661 - High (7.5)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion.
This issue affects SW Core: from n/a through 1.7.18.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39661/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T13:30:56
1 posts
🟠 CVE-2026-25713 - High (7.8)
MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-25713/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-26T13:30:56
1 posts
🛑 CRITICAL: Totolink A8000RU (7.1cu.643_b20200521) is vulnerable (CVE-2026-9478) to remote OS command injection via the web interface. Public exploit available. Restrict access & monitor for patches! https://radar.offseq.com/threat/cve-2026-9478-os-command-injection-in-totolink-a80-020b39d8 #OffSeq #CVE20269478 #IoTSecurity #Infosec
##updated 2026-05-26T13:30:54
1 posts
🚩 CVE-2026-42496: HIGH severity vuln in BINGOS Archive::Tar (<3.08). Symlinks in tar archives can escape extraction dir, risking unauthorized file access. No patch yet — avoid untrusted archives! https://radar.offseq.com/threat/cve-2026-42496-cwe-59-improper-link-resolution-bef-ae924259 #OffSeq #vuln #Perl #infosec
##updated 2026-05-26T13:30:46
1 posts
🔴 CRITICAL: Totolink A8000RU (7.1cu.643_b20200521) has an unauthenticated OS command injection bug (CVE-2026-9436). Exploit released, no patch yet. Restrict web management access and monitor closely. https://radar.offseq.com/threat/cve-2026-9436-os-command-injection-in-totolink-a80-126727b4 #OffSeq #Vulnerability #Security #Router
##updated 2026-05-26T13:30:41
1 posts
🚨 CRITICAL: Totolink A8000RU (7.1cu.643_b20200521) suffers OS command injection (CVE-2026-9404, CVSS 9.3). Exploit is public; no patch yet. Restrict web mgmt interface & watch for updates. https://radar.offseq.com/threat/cve-2026-9404-os-command-injection-in-totolink-a80-e697767b #OffSeq #infosec #CVE20269404 #routersecurity
##updated 2026-05-26T13:30:30
2 posts
1 repos
Microsoft SharePoint RCE Flaw Raises New Security Concerns as Attackers Continue Targeting Enterprise Servers
Introduction Microsoft has released urgent security updates to address a newly discovered remote code execution vulnerability affecting Microsoft SharePoint Server, once again putting enterprise collaboration platforms under the cybersecurity spotlight. The flaw, identified as CVE-2026-45659, carries a high CVSS severity score of 8.8 and could allow attackers…
##Faille RCE dans SharePoint : Microsoft publie un patch pour la CVE-2026-45659 https://www.it-connect.fr/faille-rce-sharepoint-patch-cve-2026-45659/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #SharePoint #Microsoft
##updated 2026-05-22T08:16:14.847000
2 posts
1 repos
@lattera How is autoloading zfs.ko related to CVE-2026-45250?
##@lattera How is autoloading zfs.ko related to CVE-2026-45250?
##updated 2026-05-21T12:57:01.463000
2 posts
Ok, CISA adding CVE-2010-0249 (Use-After-Free in checks notes Internet Explorer 6, 6 SP1, 7, and 8 for Server up to 2008 & Win7 to their KEV list... last week... has me giggle.
Yeah, I guess there may be EITW exploitation? But putting a "you got 2 weeks to fix your Server 2008 Internet Explorer NOW in 2 weeks!!!" is, like, seriously funny.
https://db.gcve.eu/known-exploited-vulnerabilities-catalog/378dd17e-1682-4b50-ad24-e7d16fbfb2fd
##Ok, CISA adding CVE-2010-0249 (Use-After-Free in checks notes Internet Explorer 6, 6 SP1, 7, and 8 for Server up to 2008 & Win7 to their KEV list... last week... has me giggle.
Yeah, I guess there may be EITW exploitation? But putting a "you got 2 weeks to fix your Server 2008 Internet Explorer NOW in 2 weeks!!!" is, like, seriously funny.
https://db.gcve.eu/known-exploited-vulnerabilities-catalog/378dd17e-1682-4b50-ad24-e7d16fbfb2fd
##updated 2026-05-20T21:32:36
3 posts
7 repos
https://github.com/ridhinva/CVE-2026-9082
https://github.com/HORKimhab/CVE-2026-9082
https://github.com/N45HT/drupal-cve-2026-9082-checker
https://github.com/lysophavin18/cve-2026-9082
https://github.com/7h30th3r0n3/CVE-2026-9082-Drupal-PoC
Drupal: kritische Sicherheitslücke (CVE-2026-9082). Der Patch steht zur Verfügung. Aktuell sind in Deutschland 61 Instanzen ungepatcht.
Interessiert das irgendjemenschen? Braucht es weitere Informationen? Oder ist der Beitrag flüssiger als Wasser?
Drupal: kritische Sicherheitslücke (CVE-2026-9082). Der Patch steht zur Verfügung. Aktuell sind in Deutschland 61 Instanzen ungepatcht.
Interessiert das irgendjemenschen? Braucht es weitere Informationen? Oder ist der Beitrag flüssiger als Wasser?
⚪️ Critical Drupal bug could lead to remote code execution
🗨️ The Drupal developers have released emergency patches for a “highly critical” vulnerability in Drupal Core that affects sites using PostgreSQL. The issue has been assigned the identifier CVE-2026-9082 and is related to an SQL injection, which in some scenarios may…
##updated 2026-05-20T18:31:35
2 posts
2 repos
The RedSun vulnerability was "officially fixed" on May 19, with the fix being "let's break the PoC by quarantining the affected .exe". The fix is just part of a Defender definition update. So, I guess the Red Sun no longer prevails.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091
@jhr77 @Hal_9000 Turns out my hunch was right: CVE-2026-41091 is RedSun.
##updated 2026-05-19T15:31:29
1 posts
1 repos
Sparx Systems has failed to patch five security issues in its Pro Cloud Server even after being contacted by CERT Poland
##updated 2026-05-19T14:16:46.977000
1 posts
2 repos
https://github.com/fevar54/FULL-ANALYSIS---CVE-2026-45829-ChromaDB-
NicFab Newsletter #22 is out.
→ Garante fines Ambrosetti €85k for late breach notification (Art. 34 GDPR)
→ Verizon DBIR 2026: vuln exploitation overtakes credentials as #1 vector
→ Commission opens first Article 112(1) AI Act review
→ Colorado CADMA replaces the 2024 AI Act
→ Unpatched RCE in ChromaDB (CVE-2026-45829)
Read: https://www.nicfab.eu/en/newsletter-issues/2026-05-26-issue-22/
Subscribe: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now
updated 2026-05-18T16:41:41
2 posts
🟠 CVE-2026-45298 - High (8.6)
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45298/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-45298 - High (8.6)
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45298/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-15T18:29:32
2 posts
🟠 CVE-2026-45574 - High (8.1)
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45574/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-45574 - High (8.1)
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45574/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-05-15T15:42:17.907000
1 posts
Micropatches released for Windows Netlogon Remote Code Execution Vulnerability (CVE-2026-41089)
#CVE_2026_41089
https://blog.0patch.com/2026/05/micropatches-released-for-windows_0304568783.html
updated 2026-05-14T15:31:59
1 posts
Blip blop, I'm a #mastobot.
Here is a summary (in beta) of the latest posts in #newsAtKukei https://masto.kukei.eu/browse/news category:
- **Russia's GPS jamming extends deep into Europe**, raising concerns over military and civilian impacts.
- **Citizenship controversies in Moldova**, with discussions on legal and political implications.
- **PostgreSQL security vulnerability (CVE-2026-6637)** in the `refint` module, urging immediate fixes.
- **AI and tech industry developments**, [1/3]
updated 2026-05-13T18:31:07
1 posts
2 repos
https://github.com/tstephens1080/palo-alto-cve-2026-0265-checker
I thought Palo was part of the Mythos seekrit cabal platform and also had their own advanced AI BS that protected enterprises from everything.
Given that, how does CVE-2026-0265 — an at-scale PAN-OS CAS Authentication Bypass — happen now?
Seems like Mythos isn't all its cracked up to be?
##updated 2026-05-13T14:08:26.420000
7 posts
CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude https://support.apple.com/en-us/127115
##CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude
https://news.ycombinator.com/item?id=48273169
CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude
Link: https://support.apple.com/en-us/127115
Discussion: https://news.ycombinator.com/item?id=48273169
CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude
Link: https://support.apple.com/en-us/127115
Discussion: https://news.ycombinator.com/item?id=48273169
CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude - https://support.apple.com/en-us/127115
##CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude
https://support.apple.com/en-us/127115
#HackerNews #CVE202628952 #Apple #macOS #Kernel #Vulnerability #CyberSecurity #Claude
##CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude
##updated 2026-05-13T00:49:16
1 posts
This macOS bug made it easy to exfiltrate WhatsApp chats. If it was encrypted , you'd need more tricks to decrypt the data:
##updated 2026-05-12T13:31:01
4 posts
3 repos
https://github.com/vognik/CVE-2026-26980
https://github.com/Kulik-Labs-Development/Ghost-CMS-Code-Injection-Audit-CVE-2026-26980
⚠️ Un CMS molto usato finisce nel mirino: siti legittimi possono diventare trappole invisibili. Aggiornare, monitorare, verificare. #Cybersecurity #CMS
🔗 https://www.tomshw.it/hardware/ghost-cms-clickfix-falla-sql-cve-2026-26980
##Critical Ghost CMS Vulnerability Exploited to Hack 700+ Websites
A critical Ghost CMS vulnerability identified as CVE-2026-26980 has been exploited in a widespread cyber campaign that compromised more than 700...
🔗️ [Thecyberexpress] https://link.is.it/FdS8KE
##Ghost CMS SQL Injection Flaw Exploited in Global ClickFix Malware Campaign
A critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) is being exploited to steal administrative keys and inject malicious 'ClickFix' scripts into over 700 websites. The campaign targets high-profile domains to deliver malware by tricking visitors into running malicious commands in their system terminal.
**If you run a Ghost CMS site, this is urgent. Check your version and update to version 6.19.1 or later. Then rotate all API keys and staff passwords since any credentials from before the patch may already be compromised. Also review your published articles for unauthorized scripts and check API logs for signs of suspicious activity.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/ghost-cms-sql-injection-flaw-exploited-in-global-clickfix-malware-campaign-d-m-c-f-3/gD2P6Ple2L
"A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.
The campaign was discovered by XLab threat intelligence researchers at Chinese cybersecurity company Qianxin, who confirmed impact on more than 700 domains, including university portals, AI/SaaS companies, media outlets, fintech firms, security sites, and personal blogs.
According to the researchers, threat actors planted malicious code on the websites of Harvard University, Oxford University, Auburn University, and DuckDuckGo."
##updated 2026-05-09T00:10:30
2 posts
🚨 CRITICAL: CVE-2026-44895 in yoda-digital mcp-gitlab-server (<0.6.0) allows unauthenticated access to a mutation-capable RPC endpoint, risking full GitLab resource compromise. Upgrade to 0.6.0+ ASAP. https://radar.offseq.com/threat/cve-2026-44895-cwe-306-missing-authentication-for--bc836ac6 #OffSeq #Vuln #GitLab #CVE202644895
##🚨 CRITICAL: CVE-2026-44895 in yoda-digital mcp-gitlab-server (<0.6.0) allows unauthenticated access to a mutation-capable RPC endpoint, risking full GitLab resource compromise. Upgrade to 0.6.0+ ASAP. https://radar.offseq.com/threat/cve-2026-44895-cwe-306-missing-authentication-for--bc836ac6 #OffSeq #Vuln #GitLab #CVE202644895
##updated 2026-05-08T23:07:34
2 posts
🟠 CVE-2026-44843 - High (8.2)
LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44843/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44843 - High (8.2)
LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44843/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-04-02T15:31:40
2 posts
Na CONFidence 2026 Michał kończy właśnie opowieść o krytycznych lukach, które umożliwiały zalogowanie się na konto dowolnego obywatela w wielu kluczowych systemach administracji publicznej, a @zaufanatrzeciastrona opublikowała przed chwilą cykl artykułów jego autorstwa, dokładnie wyjaśniający problem. Zdecydowanie polecam (zarwałam noc, żeby je na czas skorygować ;-))
👉 Zdalne wykonanie kodu w SzafirHost – [CVE-2026-26928] [Badanie e-podpisów, cz. 1] – https://zaufanatrzeciastrona.pl/post/zdalne-wykonanie-kodu-w-szafirhost-cve-2026-26928-badanie-e-podpisow-cz-1/
👉 Hakowanie e-Sądu YubiKeyem – [Badanie e-podpisów, cz. 2] – https://zaufanatrzeciastrona.pl/post/hakowanie-e-sadu-yubikeyem-badanie-e-podpisow-cz-2/
👉 Ominięcie uwierzytelniania w ZUS-ie i systemach e-Zdrowia, czyli o krok od cyberchaosu – [CVE-2026-9058] [Badanie e-podpisów, cz. 3] – https://zaufanatrzeciastrona.pl/post/ominiecie-uwierzytelniania-w-zus-ie-i-systemach-e-zdrowia-czyli-o-krok-od-cyberchaosu-cve-2026-9058-badanie-e-podpisow-cz-3/
👉 Podsumowanie: Krytyczna podatność umożliwiająca całkowite ominięcie logowania w ZUS-ie, e-Sądzie i systemach e-Zdrowia – https://zaufanatrzeciastrona.pl/post/podsumowanie-krytyczna-podatnosc-umozliwiajaca-calkowite-ominiecie-logowania-w-zus-ie-e-sadzie-i-systemach-e-zdrowia/
Michał odkrył sposób na logowanie jako dowolny użytkownik do eZUS-u, E-Sądu, eZdrowia i innych rządowych systemów. Poczytajcie, bo to najgrubsze odkrycie tego roku w PL
1. https://zaufanatrzeciastrona.pl/post/zdalne-wykonanie-kodu-w-szafirhost-cve-2026-26928-badanie-e-podpisow-cz-1/
2. https://zaufanatrzeciastrona.pl/post/hakowanie-e-sadu-yubikeyem-badanie-e-podpisow-cz-2/
3. https://zaufanatrzeciastrona.pl/post/ominiecie-uwierzytelniania-w-zus-ie-i-systemach-e-zdrowia-czyli-o-krok-od-cyberchaosu-cve-2026-9058-badanie-e-podpisow-cz-3/
4. https://zaufanatrzeciastrona.pl/post/podsumowanie-krytyczna-podatnosc-umozliwiajaca-calkowite-ominiecie-logowania-w-zus-ie-e-sadzie-i-systemach-e-zdrowia/
updated 2026-02-26T19:57:11.663000
1 posts
#OT #Advisory VDE-2026-009
JUMO: Multiple products affected by nodejs vulnerability
A vulnerability in the REST API of the JUMO device allows an attacker to trigger a denial‑of‑service (DoS) condition. Due to an incorrect implementation of the arrayLimit option in the Node.js qs module, limits for incoming request parameters are not properly enforced. As a result, an attacker can send specially crafted requests containing excessively large or deeply nested arrays, causing the web server to become unresponsive. This condition leads to a crash of the web server, followed by an automatic restart of the device.
#CVE CVE-2025-15284
https://certvde.com/en/advisories/vde-2026-009/
#CSAF https://jumo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-009.json
##updated 2026-02-25T21:31:25
1 posts
Blip blop, I'm a #mastobot.
Here is a summary (in beta) of the latest posts in #programmingAtKukei https://masto.kukei.eu/browse/programming category:
- **AI coding tools & agentic workflows**: GitHub Copilot, Claude Code, Cursor, DeepSeek Reasonix, and debates on AI’s impact on development (e.g., token efficiency, security risks).
- **PostgreSQL & pgvector**: Security patches (CVE-2026-3172), parallel HNSW index fixes, and pgBackRest’s multi-vendor funding model.
- **Open-source security [1/3]
updated 2026-01-20T16:58:23.900000
3 posts
🚨 EUVD-2026-31970
📊 Score: 9.8/10 (CVSS v3.1)
📦 Product: DIAView
🏢 Vendor: Delta Electronics
📅 Updated: 2026-05-26
📝 There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access)
An unauthenticated remote attacker can access configured databases in a DIAView project.
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31970
##🔴 CVE-2026-9642 - Critical (9.8)
There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access)
An unauthenticated remote attacker can access configured databases in a DIAView project.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9642/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-9642 - Critical (9.8)
There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access)
An unauthenticated remote attacker can access configured databases in a DIAView project.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9642/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2025-06-04T18:30:58
1 posts
CVE-2025-20286 Critical flaw in Cisco ISE cloud deployments on AWS, Azure, OCI. Unauthenticated remote access to sensitive data, admin ops, config changes, or DoS. CVSS 9.9. No patch yet. Monitor immediately. #CVE #Cisco #infosec
##updated 2025-04-25T00:32:07
1 posts
CVE-2025-46273 - Critical Supply Chain Attack in Uni. Hard-coded credentials expose all managed devices to admin takeover. CVSS 9.8. No patch available yet. Isolate systems now. #CVE #infosec #supplychain
##updated 2025-04-08T18:35:03
1 posts
CVE-2025-27740 - Critical auth bypass in Microsoft AD CS. Allows privilege escalation over network. CVSS 8.8. No patch yet. Mitigate immediately. #CVE #Microsoft #infosec
##updated 2023-01-29T05:06:59
1 posts
1 repos
https://github.com/minanagehsalalma/cve-2021-21735-zte-zxhn-h168n-admin-compromise
CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth https://minanagehsalalma.github.io/cve-2021-21735-zte-zxhn-h168n-admin-compromise/
##🟠 CVE-2026-44905 - High (7.5)
Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza. When processing incoming V2X messages, the ASN...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44905/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-44905 - High (7.5)
Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza. When processing incoming V2X messages, the ASN...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-44905/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Security Advisory: CVE-2025-70103 - Heap-Based Buffer Overflow in libjxl / cjxl
A heap-based buffer overflow vulnerability was identified in JPEG XL libjxl when processing crafted PBM/PNM images.
Summary:
The vulnerability exists in `jxl::extras::DecodeImagePNM()` in `lib/extras/dec/pnm.cc`. When processing a specially crafted PBM/PNM image, insufficient validation of buffer sizes before memory copy operations may cause `memcpy()` to write past the end of an allocated heap buffer.
The issue was observed as a WRITE of 24 bytes at the end of a 16-byte heap region.
CWE:
CWE-122 - Heap-based Buffer Overflow
CWE-787 - Out-of-bounds Write
Affected product:
JPEG XL / libjxl
Affected component:
`lib/extras/dec/pnm.cc`
Function: `jxl::extras::DecodeImagePNM()`
Affected line: `pnm.cc:554`
Affected version:
The issue was reproduced in `cjxl v0.12.0` at commit `24357f189c233c03fb46368a142a0b2c1a949f9d`.
Attack conditions:
Exploitation requires the vulnerable application or library consumer to process a crafted PBM/PNM image. This can be triggered locally via `cjxl` or through software that exposes the `DecodeImagePNM` decoding path to attacker-controlled input.
Example reproduction command:
`./cjxl ./2_PBM_lib_extras_dec_pnm_cc_554 --disable_output`
Impact:
Successful exploitation may cause memory corruption and process termination. The confirmed impact is denial of service (DoS) due to a crash during image processing. No evidence of reliable arbitrary code execution has been identified.
Fix / mitigation status:
The upstream issue is closed. A mitigation/fix proposal was provided in PR `#4338`, adding additional buffer-size, row-boundary, pixel-size, offset, and extra-channel checks. Users are advised to update to a libjxl build that contains the relevant fix once available, or review and apply the mitigation from PR `#4338` where appropriate.
References:
Issue:
https://github.com/libjxl/libjxl/issues/4337
Fix / mitigation PR:
https://github.com/libjxl/libjxl/pull/4338
https://github.com/libjxl/libjxl/commit/49fb89f23473e57fa1dac416adce7c7679e5d051
PoC:
https://github.com/sigdevel/pocs/blob/main/res/libjxl/2025/2/2_PBM_lib_extras_dec_pnm_cc_554
Credit:
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##Security Advisory: CVE-2025-70103 - Heap-Based Buffer Overflow in libjxl / cjxl
A heap-based buffer overflow vulnerability was identified in JPEG XL libjxl when processing crafted PBM/PNM images.
Summary:
The vulnerability exists in `jxl::extras::DecodeImagePNM()` in `lib/extras/dec/pnm.cc`. When processing a specially crafted PBM/PNM image, insufficient validation of buffer sizes before memory copy operations may cause `memcpy()` to write past the end of an allocated heap buffer.
The issue was observed as a WRITE of 24 bytes at the end of a 16-byte heap region.
CWE:
CWE-122 - Heap-based Buffer Overflow
CWE-787 - Out-of-bounds Write
Affected product:
JPEG XL / libjxl
Affected component:
`lib/extras/dec/pnm.cc`
Function: `jxl::extras::DecodeImagePNM()`
Affected line: `pnm.cc:554`
Affected version:
The issue was reproduced in `cjxl v0.12.0` at commit `24357f189c233c03fb46368a142a0b2c1a949f9d`.
Attack conditions:
Exploitation requires the vulnerable application or library consumer to process a crafted PBM/PNM image. This can be triggered locally via `cjxl` or through software that exposes the `DecodeImagePNM` decoding path to attacker-controlled input.
Example reproduction command:
`./cjxl ./2_PBM_lib_extras_dec_pnm_cc_554 --disable_output`
Impact:
Successful exploitation may cause memory corruption and process termination. The confirmed impact is denial of service (DoS) due to a crash during image processing. No evidence of reliable arbitrary code execution has been identified.
Fix / mitigation status:
The upstream issue is closed. A mitigation/fix proposal was provided in PR `#4338`, adding additional buffer-size, row-boundary, pixel-size, offset, and extra-channel checks. Users are advised to update to a libjxl build that contains the relevant fix once available, or review and apply the mitigation from PR `#4338` where appropriate.
References:
Issue:
https://github.com/libjxl/libjxl/issues/4337
Fix / mitigation PR:
https://github.com/libjxl/libjxl/pull/4338
https://github.com/libjxl/libjxl/commit/49fb89f23473e57fa1dac416adce7c7679e5d051
PoC:
https://github.com/sigdevel/pocs/blob/main/res/libjxl/2025/2/2_PBM_lib_extras_dec_pnm_cc_554
Credit:
@sigdevel
#fuzzing #infosec #security #afl #revers #cybersecurity #bugbounty #vulnerability #opensource #linux #cve #advisory
##🟠 CVE-2026-43935 - High (8.1)
e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset links pointing to attacker-controlled domains. Th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
###OT #Advisory VDE-2026-053
METTLER TOLEDO: EVA Karl Fischer titrators affected by libpng vulnerabilities
Titration software versions prior to 2.0.2.6 are affected by libpng vulnerabilities CVE-2026-33416 and CVE-2026-33636.
#CVE CVE-2026-33636, CVE-2026-33416
https://certvde.com/en/advisories/vde-2026-053/
#CSAF https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-053.json
###OT #Advisory VDE-2026-053
METTLER TOLEDO: EVA Karl Fischer titrators affected by libpng vulnerabilities
Titration software versions prior to 2.0.2.6 are affected by libpng vulnerabilities CVE-2026-33416 and CVE-2026-33636.
#CVE CVE-2026-33636, CVE-2026-33416
https://certvde.com/en/advisories/vde-2026-053/
#CSAF https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-053.json
##Is your self-hosted network actually secure?
A brand new CVE-2026-40172 just dropped for Authentik, targeting Single Sign-On (SSO) gateways. Don't let hackers compromise your Proxmox cluster.More https://ww.valtersit.com/ #infosec #devops #proxmox #valtersit #CVE #CVEAlert #devsecops #hackers #sysadmins #sysadmin #developers