Posts

Showing posts from June, 2026

CVE-2026-10513 - Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'photo'/'url' Author Properties

CVE ID : CVE-2026-10513 Published : June 30, 2026, 6:32 p.m. | 1 hour, 9 minutes ago Description : The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 via parser-derived 'avatar' and 'url' author metadata. This is due to insufficient input sanitization and output escaping on user-supplied MF2 author properties processed by the unauthenticated webmention REST endpoint and rendered directly into HTML 'value' attributes by the edit-comment-form template without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a privileged user (moderator or administrator) opens the affected comment edit screen. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/duDt1zP via IFTTT

CVE-2026-13580 - Edimax EW-7478APC POST Request formQoS buffer overflow

CVE ID : CVE-2026-13580 Published : June 29, 2026, 3 p.m. | 2 hours, 41 minutes ago Description : A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/HmKj5Xg via IFTTT

CVE-2026-13507 - volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 data authenticity

CVE ID : CVE-2026-13507 Published : June 28, 2026, 9:30 p.m. | 2 hours, 10 minutes ago Description : A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local VectorDB Primary-key Label Handler. The manipulation of the argument ID results in insufficient verification of data authenticity. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The pull request to fix this issue awaits acceptance. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/6monjst via IFTTT

CVE-2026-58049 - FFmpeg - Out-of-Bounds Write in RASC Decoder decode_dlta()

CVE ID : CVE-2026-58049 Published : June 28, 2026, 1:32 a.m. | 2 hours, 7 minutes ago Description : FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream using the RASC FourCC, decoded by libavcodec, triggers a bitstream-controlled out-of-bounds heap write and adjacent out-of-bounds read, leading to memory corruption. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/tlA1DKf via IFTTT

CVE-2026-8095 - Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion

CVE ID : CVE-2026-8095 Published : June 27, 2026, 11:28 p.m. | 2 hours, 11 minutes ago Description : The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase evades the unset check and is normalized to wpfm_dir_path by sanitize_key() during update_post_meta(), allowing an attacker to overwrite the stored file path with an arbitrary filesystem path that is then passed directly to unlink() in delete_file_locally() without any directory containment validation. This makes it possible for authenticated attackers with Subscriber-level access to delete arbitrary files on the server, including sensitive files such as wp-config.php, potentially leading to full site takeover. Severity: 0.0 | NA Visit the link for mor...

CVE-2026-10643 - Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)

CVE ID : CVE-2026-10643 Published : June 27, 2026, 10:59 p.m. | 41 minutes ago Description : Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg-msg_controllen Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/nAJhHBP via IFTTT

CVE-2023-20572 - ASP Hash MAC Brute-Force Vulnerability

CVE ID : CVE-2023-20572 Published : June 26, 2026, 3:53 p.m. | 1 hour, 46 minutes ago Description : An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the input of an arbitrary message, potentially leading to a loss of data integrity. Severity: 5.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/UL3FhWt via IFTTT

CVE-2026-55092 - Trivy: Path traversal via a crafted vulnerability database or other downloaded artifacts

CVE ID : CVE-2026-55092 Published : June 25, 2026, 4:26 p.m. | 1 hour, 12 minutes ago Description : Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifact can supply a crafted annotation that resolves to a path outside the intended destination, causing Trivy to write the layer content to an arbitrary location on the host filesystem. This vulnerability is fixed in 0.71.1. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/dz27xCg via IFTTT

CVE-2026-8660 - OS Command Injection in Rapid7 InsightConnect Ping Plugin

CVE ID : CVE-2026-8660 Published : June 25, 2026, 12:52 a.m. | 2 hours, 46 minutes ago Description : OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/u5NBeqD via IFTTT

CVE-2026-6458 - AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty

CVE ID : CVE-2026-6458 Published : June 23, 2026, 11:49 p.m. | 1 hour, 48 minutes ago Description : Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of processed ciphertext. Ciphertext produced by that call may be modified without the tag reflecting the change. This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Uf7AtCZ via IFTTT

CVE-2026-11833 - FAST/TOOLS CI Server Information Disclosure

CVE ID : CVE-2026-11833 Published : June 23, 2026, 12:53 a.m. | 2 hours, 43 minutes ago Description : Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting information. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 CI Server (All packages) R1.01 to R1.04 Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/v1KWYlk via IFTTT

CVE-2026-10645 - fs: ext2: Missing structural validation of directory entries can cause out-of-bounds read and zero-progress directory traversal

CVE ID : CVE-2026-10645 Published : June 22, 2026, 11:48 p.m. | 1 hour, 49 minutes ago Description : Zephyr's ext2 directory-entry parser does not fully validate on-disk directory entry structure before copying the entry name and advancing traversal state. In ext2_fetch_direntry() (subsys/fs/ext2/ext2_diskops.c), the code only checks de_name_len Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/tbO0JKB via IFTTT

CVE-2026-12805 - OFFIS DCMTK ofxml.cc parseFile heap-based overflow

CVE ID : CVE-2026-12805 Published : June 21, 2026, 7:15 p.m. | 2 hours, 21 minutes ago Description : A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/fr3dc1m via IFTTT

CVE-2026-12804 - lemonldap-ng SAML Common Domain Cookie Endpoint CDC.pm redirect

CVE ID : CVE-2026-12804 Published : June 21, 2026, 6:30 p.m. | 1 hour, 6 minutes ago Description : A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/kKdt2gz via IFTTT

CVE-2025-71331 - Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows

CVE ID : CVE-2025-71331 Published : June 20, 2026, 3:24 p.m. | 4 hours, 11 minutes ago Description : Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScript by sending an iframe payload (e.g., ) in a chat box, or by having a custom agent function return an XSS payload from an external website. The injected script executes in the victim's browser, enabling theft of cookies and session data. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/8aM70wg via IFTTT

CVE-2017-20266 - Joomla SP Movie Database 1.3 SQL Injection via searchword

CVE ID : CVE-2017-20266 Published : June 19, 2026, 4:04 p.m. | 1 hour, 30 minutes ago Description : Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to extract sensitive database information. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/AStgW3J via IFTTT

CVE-2026-55205 - Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint

CVE ID : CVE-2026-55205 Published : June 18, 2026, 3:49 p.m. | 1 hour, 43 minutes ago Description : Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and thread resources, potentially triggering repeated outbound device-code requests to upstream OAuth providers. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/tW6Pb5N via IFTTT

CVE-2026-56024 - WordPress WP EasyPay plugin <= 4.4.0 - Cross Site Request Forgery (CSRF) vulnerability

CVE ID : CVE-2026-56024 Published : June 18, 2026, 3:27 p.m. | 2 hours, 5 minutes ago Description : Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.4.0. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/rJQ1Rse via IFTTT

CVE-2026-48814 - Network-AI: Empty default secret still authorizes all requests (Incomplete fix for CVE-2026-46701)

CVE ID : CVE-2026-48814 Published : June 17, 2026, 7:42 p.m. | 1 hour, 48 minutes ago Description : Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by closing the CORS flaw (with Access-Control-Allow-Origin now set only for localhost origins), but the empty-default-secret flaw described in the title remained: the SSE MCP server still defaulted to an empty secret, _isAuthorized() still returned true when the secret was empty, and a non-loopback bind only produced a warning. As a result, the server still ran fully unauthenticated by default. Any non-browser caller (for example, curl, SSRF, or a 0.0.0.0 bind) could invoke all 22 MCP tools (config_set, agent_spawn, blackboard_write, token_*) with no credentials. This issue was fixed in version 5.7.2. Sev...

CVE-2026-12447 - Google Chrome heap buffer overflow

CVE ID : CVE-2026-12447 Published : June 17, 2026, 1:38 a.m. | 1 hour, 51 minutes ago Description : Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/GCphHDc via IFTTT

CVE-2026-5038 - multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads

CVE ID : CVE-2026-5038 Published : June 15, 2026, 4:16 p.m. | 1 hour, 10 minutes ago Description : Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required. Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease). Both versions track in-flight write streams and clean them up on the abort path. Workarounds: None. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/F0v38Os via IFTTT

CVE-2026-10634 - Use-after-free in Zephyr native TCP net_tcp_foreach() due to dropping tcp_lock during the callback

CVE ID : CVE-2026-10634 Published : June 15, 2026, 4:16 p.m. | 1 hour, 10 minutes ago Description : Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_SLIST_FOR_EACH_CONTAINER_SAFE macro, which caches a pointer to the next list node. Prior to this fix the function released tcp_lock while invoking the per-connection callback and re-acquired it afterwards. During that window a concurrent tcp_conn_release(), running on the dedicated TCP work-queue thread when a connection's reference count drops to zero (e.g. a remote peer closing or resetting the connection), can remove and k_mem_slab_free() the cached next connection. When the iterator advances it dereferences the freed (and possibly reallocated) slab memory — a use-after-free that can crash the system (denial of service) and, if the slot has been reused, cause the callback to operate on an attacker-influenced object (potential information disclosu...

CVE-2025-15659 - WordPress Elizaibots plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability

CVE ID : CVE-2025-15659 Published : June 15, 2026, 4:16 p.m. | 1 hour, 10 minutes ago Description : Contributor Cross Site Scripting (XSS) in Elizaibots Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/TmfWU86 via IFTTT

CVE-2025-15658 - WordPress WP Emmet plugin <= 0.3.4 - Cross Site Scripting (XSS) vulnerability

CVE ID : CVE-2025-15658 Published : June 15, 2026, 4:16 p.m. | 1 hour, 10 minutes ago Description : Administrator Cross Site Scripting (XSS) in WP Emmet Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/vhVE5SA via IFTTT

CVE-2026-54410 - nanoMODBUS TCP Server Off-by-One Buffer Overflow

CVE ID : CVE-2026-54410 Published : June 14, 2026, 6:17 p.m. | 1 hour, 7 minutes ago Description : nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header() function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP frame whose Length field is set to 255. The overflow corrupts the adjacent buffer-index field of the nanoMODBUS state structure, resulting in denial of service through invalid memory accesses and, on bare-metal and RTOS targets without memory protection, one-byte information disclosure and writes to unintended register addresses on the Write Multiple Registers (FC16) handler path. Severity: 9.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/r5tUeQO via IFTTT

CVE-2026-12183 - Nefteprodukttekhnika BUK TS-G Improper Authentication

CVE ID : CVE-2026-12183 Published : June 13, 2026, 6:16 p.m. | 1 hour, 6 minutes ago Description : Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax-login.php endpoint returns userid=1 (administrator) in response to any HTTP POST request that supplies arbitrary credentials (e.g., action=dologin&login= &pwd= ), and subsequent privileged endpoints under /php/ajax-main.php and /modules/* do not validate a server-side session. A remote unauthenticated attacker can invoke any administrative action exposed by the configuration module, including reading and modifying user rules, fuel tank gauges, fuel dispensers, relays, cash registers, bank terminals, fuel cards, price and customer displays, cash collection, and pricing rules. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affect...

CVE-2026-6428 - Koha SQL Injection

CVE ID : CVE-2026-6428 Published : June 13, 2026, 4:34 p.m. | 48 minutes ago Description : SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/. The vulnerable sink in sub calculate concatenates the unmodified Filter request parameter directly into a LIKE clause of the auxiliary $strsth2 statement and executes it via DBI without bound parameters: my $f = @$filters[0]; $f =~ s/\*/%/g; $strsth2 .= " AND $column LIKE '$f' "; This enables error-based SQL injection (e.g., via EXTRACTVALUE) and full read access to sensitive tables including borrowers (password hashes, 2FA secrets, PII), borrower_p...

CVE-2025-14098 - Avira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS executable file

CVE ID : CVE-2025-14098 Published : June 12, 2026, 11:16 p.m. | 2 hours, 4 minutes ago Description : Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.104. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ANbC60D via IFTTT

CVE-2026-12027 - Google Chrome Headless Sandbox Escape

CVE ID : CVE-2026-12027 Published : June 11, 2026, 10:16 p.m. | 1 hour, 2 minutes ago Description : Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/2RxVhvj via IFTTT

CVE-2026-46669 - `openvm-pairing` pairing check missing proper subfield check on scaling factor

CVE ID : CVE-2026-46669 Published : June 10, 2026, 10:17 p.m. | 1 hour ago Description : OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library's try_honest_pairing_check function invokes Theorem 3 of https://ift.tt/H5ozv3M but does not check that the scaling factor s is in a proper subfield of Fp12. This allows incorrect results to the pairing check. This issue has been patched in version 1.6.0. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/vliRaCu via IFTTT

CVE-2026-47919 - Acrobat Reader | Use After Free (CWE-416)

CVE ID : CVE-2026-47919 Published : June 9, 2026, 8:01 p.m. | 29 minutes ago Description : Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Bnb2mYO via IFTTT

CVE-2026-46291 - crypto: caam - guard HMAC key hex dumps in hash_digest_key

CVE ID : CVE-2026-46291 Published : June 8, 2026, 5:16 p.m. | 41 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: crypto: caam - guard HMAC key hex dumps in hash_digest_key Use print_hex_dump_devel() for dumping sensitive HMAC key bytes in hash_digest_key() to avoid leaking secrets at runtime when CONFIG_DYNAMIC_DEBUG is enabled. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/aQmVhBy via IFTTT

CVE-2026-11461 - NousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorization

CVE ID : CVE-2026-11461 Published : June 7, 2026, 10:16 p.m. | 1 hour, 41 minutes ago Description : A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume Endpoint. Such manipulation of the argument Title leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/3U6awkA via IFTTT

CVE-2026-11460 - Boost Serialization improper validation of specified type of input

CVE ID : CVE-2026-11460 Published : June 7, 2026, 8:16 p.m. | 1 hour, 41 minutes ago Description : A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input. It is possible to initiate the attack remotely. The exploit has been published and may be used. The maintainer was notified on Aug 2025 and a disclosure deadline was set for 90 days. The maintainer acknowledged but postponed indefinitely citing time concerns. No patch is currently available and the disclosure deadline has expired. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/mDVl3BR via IFTTT

CVE-2026-11436 - Mage AI Sign-in Flow index.tsx useMutation cross site scripting

CVE ID : CVE-2026-11436 Published : June 6, 2026, 4:16 p.m. | 1 hour, 40 minutes ago Description : A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai/frontend/components/Sessions/SignForm/index.tsx of the component Sign-in Flow. Performing a manipulation of the argument query.redirect_url results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/4LXDFYe via IFTTT

CVE-2026-6208 - IDOR in in HAVELSAN's Geographic Tracking System

CVE ID : CVE-2026-6208 Published : June 5, 2026, 3:16 p.m. | 2 hours, 39 minutes ago Description : Authorization bypass through User-Controlled key vulnerability in HAVELSAN Inc. Geographic Tracking System allows Exploitation of Trusted Identifiers. This issue affects Geographic Tracking System: before v0.0.2. Severity: 9.1 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/uG4DZ2b via IFTTT

CVE-2025-67447 - Neterbit Router OS Command Injection

CVE ID : CVE-2025-67447 Published : June 4, 2026, 6:16 p.m. | 1 hour, 39 minutes ago Description : The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does not properly sanitize user input in the IP address field before passing it to the system's ping command. An attacker can inject arbitrary OS commands, which will be executed with the privileges of the web server. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/svf7VJh via IFTTT

CVE-2026-46266 - inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP

CVE ID : CVE-2026-46266 Published : June 3, 2026, 3:50 p.m. | 2 hours, 5 minutes ago Description : In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having one RAW socket on protocol IPPROTO_RAW (255) was dangerous. socket(AF_INET, SOCK_RAW, 255); A malicious incoming ICMP packet can set the protocol field to 255 and match this socket, leading to FNHE cache changes. inner = IP(src="192.168.2.1", dst="8.8.8.8", proto=255)/Raw("TEST") pkt = IP(src="192.168.1.1", dst="192.168.2.1")/ICMP(type=3, code=4, nexthopmtu=576)/inner "man 7 raw" states: A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able to send any IP protocol that is specified in the passed header. Receiving of all IP protocols via IPPROTO_RAW is not possible using raw sockets. Make sure we drop these malicious packet...

CVE-2026-10690 - wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgery

CVE ID : CVE-2026-10690 Published : June 3, 2026, 12:16 a.m. | 1 hour, 38 minutes ago Description : A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The name of the patch is 53699bebba9950047bca16ac4dc8f0568f596aaa. It is best practice to apply a patch to resolve this issue. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/klUTZAD via IFTTT

CVE-2026-10529 - westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting

CVE ID : CVE-2026-10529 Published : June 2, 2026, 12:15 a.m. | 1 hour, 39 minutes ago Description : A weakness has been identified in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is an unknown function of the file src/main/java/com/zhiliao/module/web/system/ScheduleJobController.java of the component Task Scheduling Management Module. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/Wi6C7v3 via IFTTT