Skip to content

#unknown

138 articles

Security Alerts Jun 29, 2026

CVE-2026-13762: Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might...

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragm...

Security Alerts Jun 29, 2026

CVE-2026-13763: Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF...

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 request...

Security Alerts Jun 29, 2026

CVE-2026-37637: An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the...

An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component...

Security Alerts Jun 29, 2026

CVE-2026-56782: Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api...

Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_k...

Security Alerts Jun 27, 2026

CVE-2026-28701: Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated...

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths....

Security Alerts Jun 26, 2026

CVE-2025-11919: The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory...

The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/UserTemporaryFiles/`). The `-init` file for the the...

Security Alerts Jun 26, 2026

CVE-2025-71327: Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account...

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit...

Security Alerts Jun 26, 2026

CVE-2025-71334: Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access...

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in f...

Security Alerts Jun 26, 2026

CVE-2025-71336: Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote...

Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such ...

Security Alerts Jun 26, 2026

CVE-2025-71338: Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process...

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can ex...

Security Alerts Jun 26, 2026

CVE-2026-0685: Server side template inject (SSTI) in the expression evaluation component in Genshi Template...

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template e...

Security Alerts Jun 26, 2026

CVE-2026-40702: WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate...

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitiv...

Security Alerts Jun 26, 2026

CVE-2026-54820: Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions....

Security Alerts Jun 26, 2026

CVE-2026-54825: Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions....

Security Alerts Jun 26, 2026

CVE-2026-54831: Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions....

Security Alerts Jun 26, 2026

CVE-2026-56028: Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website...

Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions....

Security Alerts Jun 26, 2026

CVE-2026-56030: Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions....

Security Alerts Jun 26, 2026

CVE-2026-56036: Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.

Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions....

Security Alerts Jun 26, 2026

CVE-2026-56058: Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.

Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions....

Security Alerts Jun 26, 2026

CVE-2026-56067: Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions....

Security Alerts Jun 26, 2026

CVE-2026-56068: Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.

Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions....

Security Alerts Jun 26, 2026

CVE-2026-57658: Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.

Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions....

Security Alerts Jun 26, 2026

CVE-2026-57878: An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV...

An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when...

Security Alerts Jun 26, 2026

CVE-2026-57879: An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV...

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when p...

Security Alerts Jun 26, 2026

CVE-2026-57880: An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV...

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when p...

Security Alerts Jun 26, 2026

CVE-2026-57881: An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV...

An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation whe...

Security Alerts Jun 25, 2026

CVE-2026-12569: PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network....

Security Alerts Jun 25, 2026

CVE-2026-41120: Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous...

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potent...

Security Alerts Jun 25, 2026

CVE-2026-54836: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5....

Security Alerts Jun 25, 2026

CVE-2026-54843: Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.

Unauthenticated SQL Injection in MDTF <= 1.3.7 versions....

Security Alerts Jun 25, 2026

CVE-2026-56445: The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM...

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths....

Security Alerts Jun 25, 2026

CVE-2026-56786: RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function...

RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte overflow into fix...

Security Alerts Jun 25, 2026

CVE-2026-57700: Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using...

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6....

Security Alerts Jun 24, 2026

CVE-2026-12485: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled...

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP mes...

Security Alerts Jun 24, 2026

CVE-2026-12486: Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of...

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker ...

Security Alerts Jun 24, 2026

CVE-2026-12846: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled...

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP mes...

Security Alerts Jun 24, 2026

CVE-2026-12847: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled...

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP mes...

Security Alerts Jun 24, 2026

CVE-2026-12848: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled...

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP mes...

Security Alerts Jun 24, 2026

CVE-2026-12849: Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of...

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker ...

Security Alerts Jun 24, 2026

CVE-2026-12850: Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of...

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker ...

Security Alerts Jun 24, 2026

CVE-2026-12851: Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of...

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker ...

Security Alerts Jun 24, 2026

CVE-2026-56111: Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING...

Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in the M421 G-code handler that allows attackers to c...

Security Alerts Jun 24, 2026

CVE-2026-56121: Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated...

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the reg...

Security Alerts Jun 23, 2026

CVE-2025-67038: Lantronix EDS5000 Code Injection Vulnerability

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges....

Security Alerts Jun 23, 2026

CVE-2026-11374: In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus,...

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, le...

Security Alerts Jun 23, 2026

CVE-2026-12866: All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API...

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into ...

Security Alerts Jun 23, 2026

CVE-2026-56315: picklescan before 1.0.4 fails to block at least seven Python standard library modules (including...

picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functions that provide dir...

Security Alerts Jun 22, 2026

CVE-2026-10789: A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and...

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary co...

Security Alerts Jun 21, 2026

CVE-2026-56395: SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar...

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve ...

Security Alerts Jun 21, 2026

CVE-2026-56397: SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar...

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve ...

Security Alerts Jun 20, 2026

CVE-2024-58351: Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via...

Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction AP...

Security Alerts Jun 20, 2026

CVE-2026-56073: Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that...

Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP...

Security Alerts Jun 20, 2026

CVE-2026-56081: Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and...

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-fact...

Security Alerts Jun 19, 2026

CVE-2026-12046: Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/...

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only ro...

Security Alerts Jun 19, 2026

CVE-2026-40624: Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a...

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request....

Security Alerts Jun 19, 2026

CVE-2026-54414: FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api...

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. ...

Security Alerts Jun 18, 2026

CVE-2026-38714: InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were...

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function. This vulnera...

Security Alerts Jun 18, 2026

CVE-2026-38715: InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were...

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. This vulnerability al...

Security Alerts Jun 18, 2026

CVE-2026-38716: InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were...

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. This vu...

Security Alerts Jun 18, 2026

CVE-2026-38717: InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were...

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. The vulnerability all...

Security Alerts Jun 18, 2026

CVE-2026-54103: The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and...

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate passwor...

Security Alerts Jun 18, 2026

CVE-2026-54390: JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability...

JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied...

Security Alerts Jun 18, 2026

CVE-2026-55742: Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the...

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update')...

Security Alerts Jun 18, 2026

CVE-2026-8024: A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability...

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems....

Security Alerts Jun 17, 2026

CVE-2025-59554: Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.

Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions....

Security Alerts Jun 17, 2026

CVE-2025-69111: Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.

Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions....

Security Alerts Jun 17, 2026

CVE-2025-69127: Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.

Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions....

Security Alerts Jun 17, 2026

CVE-2025-71320: picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and...

picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks. Remote attackers can craft...

Security Alerts Jun 17, 2026

CVE-2025-71321: picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers...

picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malic...

Security Alerts Jun 17, 2026

CVE-2025-71323: picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote...

picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and accessing raw memory. Attackers can craft malicious pickl...

Security Alerts Jun 17, 2026

CVE-2025-71325: picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when...

picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle ...

Security Alerts Jun 17, 2026

CVE-2026-36418: JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper...

JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly...

Security Alerts Jun 17, 2026

CVE-2026-49108: Unauthenticated PHP Object Injection in Moderno < 1.43 versions.

Unauthenticated PHP Object Injection in Moderno < 1.43 versions....

Security Alerts Jun 17, 2026

CVE-2026-53805: NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution...

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deseria...

Security Alerts Jun 17, 2026

CVE-2026-53873: picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to...

picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing attackers to achieve arbitrary code execution via ...

Security Alerts Jun 17, 2026

CVE-2026-53874: picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated...

picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attack...

Security Alerts Jun 17, 2026

CVE-2026-54387: Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length...

Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Len...

Security Alerts Jun 17, 2026

CVE-2026-54388: Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple...

Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while usin...

Security Alerts Jun 17, 2026

CVE-2026-54808: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gut...

Security Alerts Jun 17, 2026

CVE-2026-54809: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: from n/a through 1.0.10....

Security Alerts Jun 17, 2026

CVE-2026-54812: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection. This issue affects Motors: from n/a through 1.4...

Security Alerts Jun 17, 2026

CVE-2026-54815: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects C...

Security Alerts Jun 17, 2026

CVE-2026-54819: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4...

Security Alerts Jun 16, 2026

CVE-2026-12087: Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs,...

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the...

Security Alerts Jun 16, 2026

CVE-2026-22313: The device has a webserver that exposes a REST API authenticated with a token on the management...

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrar...

Security Alerts Jun 16, 2026

CVE-2026-40750: Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store...

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8...

Security Alerts Jun 16, 2026

CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticate...

Security Alerts Jun 16, 2026

CVE-2026-49772: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Eve...

Security Alerts Jun 16, 2026

CVE-2026-49774: Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station...

Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0....

Security Alerts Jun 15, 2026

CVE-2026-48881: Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.

Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions....

Security Alerts Jun 15, 2026

CVE-2026-49085: Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor,...

Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions....

Security Alerts Jun 15, 2026

CVE-2026-49104: Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7,...

Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions....

Security Alerts Jun 15, 2026

CVE-2026-49105: Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor,...

Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions....

Security Alerts Jun 15, 2026

CVE-2026-49109: Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms,...

Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions....

Security Alerts Jun 15, 2026

CVE-2026-49764: Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.

Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions....

Security Alerts Jun 15, 2026

CVE-2026-49765: Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms,...

Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions....

Security Alerts Jun 15, 2026

CVE-2026-49768: Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.

Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions....

Security Alerts Jun 15, 2026

CVE-2026-49781: Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions....

Security Alerts Jun 15, 2026

CVE-2026-52703: Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

Unauthenticated Path Traversal in FastDup <= 2.7.2 versions....

Security Alerts Jun 15, 2026

CVE-2026-52704: Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas...

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder...

Security Alerts Jun 15, 2026

CVE-2026-9691: Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7,...

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions....

Security Alerts Jun 15, 2026

CVE-2026-9862: Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in...

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to ca...

Security Alerts Jun 12, 2026

CVE-2026-10557: The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are...

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials are embedded in the application binary and are rea...

Security Alerts Jun 12, 2026

CVE-2026-28742: Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt...

Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an attacker can generate v...

Security Alerts Jun 12, 2026

CVE-2026-39494: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter b...

Security Alerts Jun 12, 2026

CVE-2026-42647: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7....

Security Alerts Jun 12, 2026

CVE-2026-47367: A malicious actor with access to the network and low privileges could exploit an Improper Input...

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device...

Security Alerts Jun 12, 2026

CVE-2026-47369: A malicious actor with access to the network and low privileges could exploit an Improper Input...

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such Un...

Security Alerts Jun 12, 2026

CVE-2026-47370: A malicious actor with access to the network and low privileges could exploit an Improper Input...

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within...

Security Alerts Jun 12, 2026

CVE-2026-48611: Improper authentication checks in the OAuth implementation allow account hijacking even when...

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations....

Security Alerts Jun 12, 2026

CVE-2026-50083: The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which...

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3....

Security Alerts Jun 12, 2026

CVE-2026-50084: The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid...

The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Authorization" with an es...

Security Alerts Jun 12, 2026

CVE-2026-50086: The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against...

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authenticatio...

Security Alerts Jun 12, 2026

CVE-2026-50090: The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to...

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper ...

Security Alerts Jun 12, 2026

CVE-2026-50091: Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same...

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-code...

Security Alerts Jun 12, 2026

CVE-2026-6853: Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food...

Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass. This issue a...

Security Alerts Jun 11, 2026

CVE-2026-11839: Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information...

Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.0...

Security Alerts Jun 11, 2026

CVE-2026-41005: Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as...

Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth...

Security Alerts Jun 11, 2026

CVE-2026-7852: Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC...

Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9....

Security Alerts Jun 11, 2026

CVE-2026-9648: The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS...

The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted ...

Security Alerts Jun 10, 2026

CVE-2026-53469: A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by...

A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. Th...

Security Alerts Jun 10, 2026

CVE-2026-53475: A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer...

A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Midd...

Security Alerts Jun 9, 2026

CVE-2025-10263: Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1,...

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, ...

Security Alerts Jun 9, 2026

CVE-2026-10045: Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2...

Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and LAN interfaces. T...

Security Alerts Jun 9, 2026

CVE-2026-47291: Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute...

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network....

Security Alerts Jun 9, 2026

CVE-2026-7486: Improper neutralization of special elements used in an SQL command ('SQL injection')...

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injection. This issue affects E-İmar: from 2.10.1.0 before...

Security Alerts Jun 9, 2026

CVE-2026-8025: Improper neutralization of special elements used in an SQL command ('SQL injection')...

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. This issue affects CBS Plat...

Security Alerts May 27, 2026

CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harveste...

Security Alerts May 8, 2026

CVE-2026-42208: BerriAI LiteLLM SQL Injection Vulnerability

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorised access to the proxy and the cre...

Security Alerts May 6, 2026

CVE-2026-0300: Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrar...

Security Alerts Apr 23, 2026

CVE-2026-39987: Marimo Remote Code Execution Vulnerability

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands....

Security Alerts Apr 14, 2026

CVE-2026-32201: Microsoft SharePoint Server Improper Input Validation Vulnerability

Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network....

Security Alerts Mar 13, 2026

CVE-2026-3055: Citrix NetScaler Out-of-Bounds Read Vulnerability

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP lead...

Security Alerts Feb 26, 2026

CVE-2026-33634: Aquasecurity Trivy Embedded Malicious Code Vulnerability

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentia...

Security Alerts Dec 19, 2025

CVE-2026-3909: Google Skia Out-of-Bounds Write Vulnerability

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome an...

Security Alerts Dec 18, 2025

CVE-2026-3910: Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a...

Security Alerts Jul 8, 2025

CVE-2025-15556: Notepad++ Download of Code Without Integrity Check Vulnerability

Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute ...

Security Alerts Feb 15, 2025

CVE-2006-10003: Critical buffer overflow in Perl XML::Parser - Immediate Update Required

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will ...