Posts

Showing posts from May, 2026

CVE-2026-10190 - Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service

CVE ID : CVE-2026-10190 Published : May 31, 2026, 4:16 p.m. | 1 hour, 36 minutes ago Description : A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The manipulation of the argument web_over_time results in denial of service. It is possible to launch the attack remotely. The exploit has been made public and could be used. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/d4vkTPF via IFTTT

CVE-2026-10123 - TRENDnet TEW-432BRP formSetDomainFilter stack-based overflow

CVE ID : CVE-2026-10123 Published : May 30, 2026, 4:17 p.m. | 1 hour, 35 minutes ago Description : A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_list/permitted_domain_list results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ihogLmt via IFTTT

CVE-2026-39276 - Emlog Pro PHP Remote Code Execution (RCE)

CVE ID : CVE-2026-39276 Published : May 29, 2026, 4:16 p.m. | 1 hour, 36 minutes ago Description : The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containing directory traversal sequences in filenames, an attacker can overwrite default template files or directly include malicious code files in the current template. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/odxBKOL via IFTTT

CVE-2026-44462 - Zed: Allowlist Bypass via Bash Variable Expansion Chain in Terminal Tool Permissions

CVE ID : CVE-2026-44462 Published : May 28, 2026, 5:16 p.m. | 35 minutes ago Description : Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution under an allowlisted command prefix. This vulnerability is fixed in 0.229.0. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/2JMCPKL via IFTTT

CVE-2026-44327 - free5GC: NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler

CVE ID : CVE-2026-44327 Published : May 27, 2026, 5:16 p.m. | 34 minutes ago Description : free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no Authorization header at all and the handler returns 200 OK. The current OAM handler is a stub that returns null, but the structural defect is route-group-scoped: the entire OAM route group has no inbound auth middleware, so every future OAM operation added to this group inherits the missing auth boundary by default. This vulnerability is fixed in 4.2.2. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/HPBeCdD via IFTTT

CVE-2026-44325 - free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Reflect.Set on incompatible types)

CVE ID : CVE-2026-44325 Published : May 27, 2026, 5:16 p.m. | 34 minutes ago Description : free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type-confusion bug family. The handler in NFs/nrf/internal/sbi/api_accesstoken.go reflects over models.NrfAccessTokenAccessTokenReq, special-cases only plain string and NrfNfManagementNfType fields, and treats every other field as if it were a single models.PlmnId. The parsed *models.PlmnId is then assigned with reflect.Value.Set() to whichever field name the attacker put in the form body, which panics whenever the destination field's real type is incompatible (slice, different struct, primitive). Gin recovery converts each panic into HTTP 500, but the endpoint remains remotely panicable from a single unauthenticated form-encoded request and is repeatedly triggerable. This vulnerability is fixed in 4.2.2. Severity: ...

CVE-2026-8676 - "Bluetooth LE Bond Spoofing Vulnerability in Vendor's Product"

CVE ID : CVE-2026-8676 Published : May 26, 2026, 9:16 p.m. | 33 minutes ago Description : An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a new bond. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/wqxB8OI via IFTTT

CVE-2026-24527 - WordPress Autoship Cloud for WooCommerce Subscription Products plugin <= 2.14.0 - Broken Access Control vulnerability

CVE ID : CVE-2026-24527 Published : May 25, 2026, 9:40 p.m. | 2 hours, 9 minutes ago Description : Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/m0K9iDF via IFTTT

CVE-2026-9395 - Besen BS20 EV Charging Station BLE/UDP insufficiently protected credentials

CVE ID : CVE-2026-9395 Published : May 24, 2026, 8 p.m. | 1 hour, 49 minutes ago Description : A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the component BLE/UDP. The manipulation leads to insufficiently protected credentials. The attack needs to be initiated within the local network. The original disclosure mentions, that "[t]hese vulnerabilities have been reported to Besen and we have received their acknowlegement that they are reviewing this as of April 2026." Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/iYadCjE via IFTTT

CVE-2026-9393 - H3C Magic B0 aspForm Edit_BasicSSID_5G buffer overflow

CVE ID : CVE-2026-9393 Published : May 24, 2026, 7 p.m. | 49 minutes ago Description : A vulnerability was found in H3C Magic B0 up to 100R002. This affects the function Edit_BasicSSID_5G of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/7OvlVyU via IFTTT

CVE-2018-25340 - Smartshop 1 SQL Injection via category.php

CVE ID : CVE-2018-25340 Published : May 23, 2026, 6:30 p.m. | 1 hour, 18 minutes ago Description : Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to category.php with UNION-based SQL injection payloads in the id parameter to extract sensitive database information including usernames and other data. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/wVyci69 via IFTTT

CVE-2026-9255 - Tool Execution Without Authorization via Piped Stdin in Kiro CLI

CVE ID : CVE-2026-9255 Published : May 22, 2026, 4:38 p.m. | 1 hour, 9 minutes ago Description : Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1.28.0 or later. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ldogyzT via IFTTT

CVE-2026-28735 - GitHub OAuth Scope Validation

CVE ID : CVE-2026-28735 Published : May 22, 2026, 4:26 p.m. | 1 hour, 22 minutes ago Description : Mattermost versions 11.6.x Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/pwxFbvh via IFTTT

CVE-2026-28445 - Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Preview

CVE ID : CVE-2026-28445 Published : May 22, 2026, 4:12 p.m. | 1 hour, 35 minutes ago Description : Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg field directly via Solid's innerHTML directive without any sanitization, even though DOMPurify is already a dependency and is used elsewhere in the codebase (e.g., StreamingBubble.tsx). Because rating blocks are not flagged as isUnsafe by the import sanitizer and the builder preview renders bots inline on the builder's own origin (builder.typebot.io) under a CSP permitting 'unsafe-inline', a malicious imported or collaborator-crafted typebot can execute arbitrary HTML/JS in the builder's authenticated context, bypassing the Web Worker sandbox that protects Script blocks during preview. This allows session hijacking and privilege escalation within the builder application. This issue has been fixed in ve...

CVE-2026-28444 - Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure

CVE ID : CVE-2026-28444 Published : May 22, 2026, 4 p.m. | 1 hour, 47 minutes ago Description : Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller against the provided typebotId but fetches logs solely by resultId without verifying that the result belongs to the authorized typebot, leading to IDOR. An authenticated attacker can supply their own typebotId alongside any victim's resultId to read execution logs from other workspaces, leaking sensitive data including HTTP response bodies, AI model outputs, and webhook payloads. Every other result-scoped endpoint in the same router properly validates that the resultId belongs to the authorized typebotId. This confirms the missing check is an oversight, not a design choice. This issue has been fixed in version 3.15.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest V...

CVE-2026-48228 - Open ISES Tickets < 3.44.2 Reflected XSS via patient_w.php id and ticket_id Parameters

CVE ID : CVE-2026-48228 Published : May 21, 2026, 5:10 p.m. | 35 minutes ago Description : Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the id and ticket_id GET parameters directly into an HTML form action URL. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/nCOeV0f via IFTTT

CVE-2026-48227 - Open ISES Tickets < 3.44.2 Reflected XSS via patient.php id and ticket_id Parameters

CVE ID : CVE-2026-48227 Published : May 21, 2026, 5:10 p.m. | 35 minutes ago Description : Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the id and ticket_id GET parameters directly into an HTML form action URL. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/RIG51nO via IFTTT

CVE-2026-20199 - Cisco ThousandEyes Virtual Appliance SSL Certificate Command Execution Vulnerability

CVE ID : CVE-2026-20199 Published : May 20, 2026, 5:16 p.m. | 28 minutes ago Description : A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials. Severity: 4.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Ur4T0en via IFTTT

CVE-2026-20171 - Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vulnerability

CVE ID : CVE-2026-20171 Published : May 20, 2026, 5:16 p.m. | 28 minutes ago Description : A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect parsing of a transitive BGP attribute. An attacker could exploit this vulnerability by sending a crafted BGP update through an established BGP peer session. If the update propagates to an affected device, it could cause the device to drop the BGP session and flap with the BGP peer that is forwarding this update, resulting in a DoS condition. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ON7RnDk via IFTTT

CVE-2026-39047 - EPSON L14150 Buffer Overflow Remote Code Execution

CVE ID : CVE-2026-39047 Published : May 20, 2026, 4:16 p.m. | 1 hour, 28 minutes ago Description : Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100 Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Wklx71R via IFTTT

CVE-2026-8624 - LJ comments import: reloaded <= 0.97.1 - Reflected Cross-Site Scripting via PHP_SELF Parameter

CVE ID : CVE-2026-8624 Published : May 20, 2026, 2:16 a.m. | 3 hours, 26 minutes ago Description : The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability arises specifically because PHP_SELF includes attacker-controllable PATH_INFO appended to the script name, and there are two distinct unsanitized echo points for this value in the same function. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Wraj8qS via IFTTT

CVE-2026-38719 - OpENer ENIP/CPF Out-of-Bounds Read Vulnerability

CVE ID : CVE-2026-38719 Published : May 18, 2026, 5:16 p.m. | 2 hours, 13 minutes ago Description : OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonPacketFormatStructure() in source/src/enet_encap/cpf.c. A crafted ENIP/CPF message can supply an attacker-controlled item_count value that is not consistently validated against the remaining data_length of the CPF slice Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/cZ5Shga via IFTTT

CVE-2026-8765 - Kilo-Org kilocode File Diff API Endpoint worktree-diff.ts Bun.file path traversal

CVE ID : CVE-2026-8765 Published : May 17, 2026, 10 p.m. | 1 hour, 29 minutes ago Description : A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component File Diff API Endpoint. Performing a manipulation of the argument File results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/F8AUBCn via IFTTT

CVE-2026-46720 - Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections

CVE ID : CVE-2026-46720 Published : May 17, 2026, 6:16 p.m. | 1 hour, 12 minutes ago Description : Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/tSF9cbN via IFTTT

CVE-2026-8724 - Dataease Data Dashboard SqlparserUtils.java SqlparserUtils.transFilter sql injection

CVE ID : CVE-2026-8724 Published : May 17, 2026, 2:16 a.m. | 1 hour, 11 minutes ago Description : A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The manipulation results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/daWfkHi via IFTTT

CVE-2026-6050 - CVE-2019-11510 - Apache Struts Remote Code Execution

CVE ID : CVE-2026-6050 Published : May 16, 2026, 11:16 p.m. | 2 hours, 11 minutes ago Description : Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/4c0hsST via IFTTT

CVE-2026-46728 - Das U-Boot FIT Signature Verification Bypass

CVE ID : CVE-2026-46728 Published : May 16, 2026, 10:16 p.m. | 1 hour, 12 minutes ago Description : Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/dFwGLSB via IFTTT

CVE-2026-34253 - Vorbis-tools Ogg123 Buffer Underflow Vulnerability

CVE ID : CVE-2026-34253 Published : May 15, 2026, 3:16 p.m. | 1 hour, 51 minutes ago Description : A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/sEaB7XZ via IFTTT

CVE-2025-14972 - Insufficient DPA countermeasure reseeding

CVE ID : CVE-2025-14972 Published : May 15, 2026, 3:16 p.m. | 1 hour, 51 minutes ago Description : * Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually repeat. * KSU keys using SYMCRYPTO will be impacted by this vulnerability. Severity: 4.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/KpXZvFy via IFTTT

CVE-2026-42159 - Flowsint: Stored XSS in description of node

CVE ID : CVE-2026-42159 Published : May 14, 2026, 4:16 p.m. | 51 minutes ago Description : Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and relationships. The sketches contain information on an OSINT target (usernames, websites, etc) within these nodes and relationships. A remote attacker can create a node with a malicious description that contains arbitrary HTML. When the node is selected, it will render the arbitrary HTML, potentially triggering stored XSS. This vulnerability is fixed in 1.2.3. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/nCIR7O8 via IFTTT

CVE-2026-44002 - vm2: Host File Path Disclosure via Stack Trace Information Leak

CVE ID : CVE-2026-44002 Published : May 13, 2026, 6:16 p.m. | 50 minutes ago Description : vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, library paths, and framework versions of the host server. This vulnerability is fixed in 3.11.0. Severity: 5.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/yreBaIv via IFTTT

CVE-2026-42156 - Flowsint: Cypher query injection in node type on node creation

CVE ID : CVE-2026-42156 Published : May 12, 2026, 11:16 p.m. | 1 hour, 50 minutes ago Description : Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a remote attacker can create a node with a malicious type that can escape an existing Cypher query and an adversary can execute an arbitrary Cypher query. This vulnerability is fixed in 1.2.3. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/eyJBLTh via IFTTT

CVE-2026-42608 - Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.

CVE ID : CVE-2026-42608 Published : May 11, 2026, 4:17 p.m. | 48 minutes ago Description : Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST requests), an unauthenticated attacker can traverse the filesystem to create arbitrary directories and write an index.yaml file containing attacker-controlled data. This vulnerability can lead to unauthorized modification of application behavior, potential data integrity issues, and service disruption in production environments. This vulnerability is fixed in 2.0.0-beta.2. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/6Aar9FB via IFTTT

CVE-2026-45180 - Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids

CVE ID : CVE-2026-45180 Published : May 10, 2026, 8:03 p.m. | 1 hour, 1 minute ago Description : Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' session ids may be leaked. This may allow an attacker to use session ids as authentication tokens. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/IaFQKmu via IFTTT

CVE-2026-8191 - Wavlink NU516U1 adm.cgi wifi_region os command injection

CVE ID : CVE-2026-8191 Published : May 9, 2026, 6:15 p.m. | 49 minutes ago Description : A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulation of the argument skiplist1/skiplist2 leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ty8DJzV via IFTTT

CVE-2026-8189 - Wavlink NU516U1 adm.cgi wzdrepeater os command injection

CVE ID : CVE-2026-8189 Published : May 9, 2026, 4:15 p.m. | 49 minutes ago Description : A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Automode/sel_EncrypTyp results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/LN0PvrU via IFTTT

CVE-2026-41495 - n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests

CVE ID : CVE-2026-41495 Published : May 8, 2026, 8:16 p.m. | 47 minutes ago Description : n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.11, when n8n-mcp runs in HTTP transport mode, incoming requests to the POST /mcp endpoint had their request metadata written to server logs regardless of the authentication outcome. In deployments where logs are collected, forwarded to external systems, or viewable outside the request trust boundary (shared log storage, SIEM pipelines, support/ops access), this can result in disclosure of: bearer tokens from the Authorization header, per-tenant API keys from the, x-n8n-key header in multi-tenant setups, JSON-RPC request payloads sent to the MCP endpoint. Access control itself was not bypassed — unauthenticated requests were correctly rejected with 401 Unauthorized — but sensitive values from those rejected requests could still be persisted in logs. ...

CVE-2026-41903 - FreeScout IDOR Vulnerability: PERM_EDIT_USERS allows modifying any user's notification subscriptions (incomplete fix of CVE-2025-48472)

CVE ID : CVE-2026-41903 Published : May 7, 2026, 6:02 p.m. | 1 hour, 1 minute ago Description : FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user holding the PERM_EDIT_USERS permission (intended for general user-profile editing) can read and modify the notification subscriptions of any other user, including admins, by sending a single POST request. This is a sibling of CVE-2025-48472's notification authorization bypass — the prior fix did not cover this code path. A non-admin attacker can silently disable an admin's email/browser/mobile notifications, suppressing security alerts and conversation-assignment notices. This issue has been patched in version 1.8.217. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Ti9sOj1 via IFTTT

CVE-2026-40195 - Incus nil-pointer dereference in storage bucket import allows denial of service

CVE ID : CVE-2026-40195 Published : May 6, 2026, 9:16 p.m. | 1 hour, 39 minutes ago Description : Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon to crash. The vulnerability is present in the backup metadata handling logic, where the daemon processes the index.yaml file from an imported archive and accesses members of the parsed backup configuration without first verifying that the configuration object was initialized. A malicious or malformed index.yaml that omits the config block causes a nil-pointer dereference during bucket import operations and terminates the daemon. Repeated use of this issue can be used to keep Incus offline, causing a denial of service. This issue is fixed in version 7.0.0. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details,...

CVE-2025-71251 - Apache IMS Remote Denial of Service Vulnerability

CVE ID : CVE-2025-71251 Published : May 6, 2026, 1:42 a.m. | 45 minutes ago Description : In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/zj2mUPB via IFTTT

CVE-2026-44405 - Paramiko RSA Key SHA-1 Vulnerability

CVE ID : CVE-2026-44405 Published : May 5, 2026, 11:50 p.m. | 37 minutes ago Description : In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm. Severity: 3.4 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/7XF1lfY via IFTTT

CVE-2025-67796 - IKUS Rdiffweb Improper Authorization Vulnerability

CVE ID : CVE-2025-67796 Published : May 4, 2026, 8:16 p.m. | 1 hour, 54 minutes ago Description : IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/JnSH0DQ via IFTTT

CVE-2026-7710 - YunaiV yudao-cloud Ruoyi-Vue-Pro JwtAuthenticationTokenFilter.java doFilterInternal improper authentication

CVE ID : CVE-2026-7710 Published : May 3, 2026, 11:15 p.m. | 53 minutes ago Description : A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenFilter.java of the component Ruoyi-Vue-Pro. Performing a manipulation of the argument mock-token results in improper authentication. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/DOGedSL via IFTTT

CVE-2026-7702 - toeverything AFFiNE Public Markdown Preview Endpoint :docId allowDocPreview authorization

CVE ID : CVE-2026-7702 Published : May 3, 2026, 4:15 p.m. | 1 hour, 53 minutes ago Description : A vulnerability was detected in toeverything AFFiNE up to 0.26.3. This issue affects the function allowDocPreview of the file /workspace/:workspaceId/:docId of the component Public Markdown Preview Endpoint. The manipulation results in authorization bypass. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/6xcMkIC via IFTTT

CVE-2026-7669 - sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer deserialization

CVE ID : CVE-2026-7669 Published : May 2, 2026, 10:16 p.m. | 1 hour, 52 minutes ago Description : A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation results in deserialization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/dkD7yal via IFTTT

CVE-2026-7668 - MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds

CVE ID : CVE-2026-7668 Published : May 2, 2026, 9:16 p.m. | 52 minutes ago Description : A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/4Ifri23 via IFTTT

CVE-2026-41940 ~ Critical Zero Day in Cpanel & WHM

Image
A critical, actively exploited zero-day vulnerability ( CVE-2026-41940 ) in cPanel & WHM allows unauthenticated remote attackers to bypass login and gain root-level access.  Affecting all versions after 11.40, this critical vulnerability (CVSS score 9.8) has been exploited since February/March 2026. Patch immediately to the latest versions. Key Details and Mitigation: Vulnerability Type: Authentication Bypass via CRLF injection, allowing remote attackers to manipulate session files and take control of servers. Impact: Full control over web hosting accounts, databases, and server configuration. Status: Actively exploited in the wild; urgent action is required. Mitigation: Update to the patched versions immediately (11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5 or newer). Action for Admins: Run /scripts/upcp --force and review access logs for suspicious activity. Emergency Measure: Block public access to cPanel/WHM ports (2082, 2083, 2086, 2087) if p...

CVE-2026-6378 - Maxi Blocks <= 2.1.9 - Authenticated (Author+) Stored Cross-Site Scripting via Style Card REST API

CVE ID : CVE-2026-6378 Published : May 2, 2026, 4:16 a.m. | 1 hour, 50 minutes ago Description : The Maxi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `/wp-json/maxi-blocks/v1.0/style-card` REST API endpoint in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping of the `sc_styles` parameter. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts that execute on every page where the plugin's style card styles are loaded, including across the entire WordPress admin panel. Severity: 6.4 | MEDIUM

CVE-2026-7601 - Open5GS AMF gmm-handler.c denial of service

CVE ID : CVE-2026-7601 Published : May 2, 2026, 3:15 a.m. | 51 minutes ago Description : A vulnerability has been found in Open5GS up to 2.7.6. Affected is an unknown function of the file src/amf/gmm-handler.c of the component AMF. The manipulation of the argument reg_type leads to denial of service. The attack is possible to be carried out remotely. Upgrading to version 2.7.7 is able to address this issue. The identifier of the patch is ebc66942b6f8f1fab2d640e71cf4e9f1a423b426. It is advisable to upgrade the affected component. Severity: 5.3 | MEDIUM

CVE-2026-7600 - ArtMin96 yii2-mcp-server MCP index.ts yii_execute_command os command injection

CVE ID : CVE-2026-7600 Published : May 2, 2026, 1:16 a.m. | 51 minutes ago Description : A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP Interface. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/d6ZfyhB via IFTTT