Posts

Showing posts from July, 2026

CVE-2026-56567 - HCL iControl is affected by multiple security vulnerabilities.

CVE ID :CVE-2026-56567 Published : July 31, 2026, 4:17 p.m. Description :HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. Severity: 5.1 | MEDIUM

CVE-2026-66416 - Leantime CSRF Protection Globally Disabled by Omission of Laravel VerifyCsrfToken Middleware

CVE ID :CVE-2026-66416 Published : July 30, 2026, 5 p.m. Description :Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, PUT, and DELETE requests that create or delete projects, modify settings, and change permissions as any authenticated user. Severity: 8.8 | HIGH

CVE-2026-51992 - ClickHouse Server SQL Injection Vulnerability

CVE ID :CVE-2026-51992 Published : July 29, 2026, 5:16 p.m. | 1 hour, 10 minutes ago Description :SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function.

CVE-2026-20316 - Cisco Secure Firewall Management Center Software Static Credential Vulnerability

CVE ID : CVE-2026-20316 Published : July 29, 2026, 5:16 p.m. | 1 hour, 10 minutes ago Description : A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indi...

CVE-2026-15735 - Contact Form to Any API <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta

CVE ID : CVE-2026-15735 Published : July 29, 2026, 1:29 a.m. | 57 minutes ago Description : The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/rJGpAcs via IFTTT

CVE-2026-64646 - Next.js: Unbounded Server Action payload in Edge runtime

CVE ID : CVE-2026-64646 Published : July 27, 2026, 7:17 p.m. | 1 hour, 8 minutes ago Description : Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime. This issue has been fixed in versions 15.5.21 and 16.2.11. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/ZYmPrF3 via IFTTT

CVE-2026-17500 - ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereference

CVE ID : CVE-2026-17500 Published : July 27, 2026, 1:16 a.m. | 1 hour, 9 minutes ago Description : A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched remotely. The pull request to fix this issue awaits acceptance. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/VweKzoD via IFTTT

CVE-2026-57978 - Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE ID : CVE-2026-57978 Published : July 26, 2026, 5:17 p.m. | 1 hour, 8 minutes ago Description : None Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/KYczqFW via IFTTT

CVE-2026-17434 - nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization

CVE ID : CVE-2026-17434 Published : July 26, 2026, 3 a.m. | 1 hour, 25 minutes ago Description : A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. This patch is called e5b928783d5c485637565eb07d2967922dfbf8d8. A patch should be applied to remediate this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/FQ5KX8p via IFTTT

CVE-2026-17432 - NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control

CVE ID : CVE-2026-17432 Published : July 26, 2026, 1:16 a.m. | 1 hour, 8 minutes ago Description : A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitation appears to be difficult. The exploit is now public and may be used. The patch is identified as 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3. Applying a patch is advised to resolve this issue. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/jl2f57R via IFTTT

CVE-2026-65623 - Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit

CVE ID : CVE-2026-65623 Published : July 24, 2026, 5:17 p.m. | 1 hour, 6 minutes ago Description : Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly. The size guard 'Elixir.Bandit.WebSocket.Connection':oversize_message?/2 called from handle_frame/3 in lib/bandit/websocket/connection.ex appends each non-final continuation frame to a left-nested iolist and then re-measures the entire accumulated buffer with IO.iodata_length/1 on every frame. Because the buffer grows by one element per frame and is fully re-traversed each time, reassembly work is quadratic (O(n^2)) in the number of continuation frames. The max_fragmented_message_size limit (default 8 MB) bounds total bytes but not frame count, and each frame can carry as little as one payload byte, so an attacker can send millions of tiny continuation frames using modest bandwidth to pin a CPU co...

CVE-2026-65763 - Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9

CVE ID : CVE-2026-65763 Published : July 23, 2026, 4:57 p.m. | 1 hour, 26 minutes ago Description : Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9 - Improper validation of user inputs lead to a reflective XSS vulnerability. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/qGLlPXW via IFTTT

CVE-2026-16628 - oclif JIT Plugin Entry child_process.exec os command injection

CVE ID : CVE-2026-16628 Published : July 22, 2026, 9 p.m. | 1 hour, 23 minutes ago Description : A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a manipulation of the argument jitPlugins results in os command injection. The attack is only possible with local access. The exploit is now public and may be used. The patch is named 939b045725e065baebc4587b8bccfd56731eed3d. To fix this issue, it is recommended to deploy a patch. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/zG9A4VH via IFTTT

CVE-2026-47398 - PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

CVE ID : CVE-2026-47398 Published : July 21, 2026, 5:17 p.m. | 1 hour, 5 minutes ago Description : PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate to the tool_override.py sinks. However, two additional spec.loader.exec_module call sites in praisonai/agents_generator.py were missed and remain completely unguarded in versions prior to 4.6.40. Both functions accept a module_path parameter sourced from YAML configuration and execute it without validation, signature checking, or the env-var gate. Version 4.6.40 fixes the issue. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/3y0nlFR via IFTTT

CVE-2026-16336 - trinodb trino OAuth2/OIDC ExternalUriInfo.java redirect

CVE ID : CVE-2026-16336 Published : July 21, 2026, 2:30 a.m. | 1 hour, 52 minutes ago Description : A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/GgKtEiz via IFTTT

CVE-2026-44359 - Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow

CVE ID : CVE-2026-44359 Published : July 19, 2026, 11:06 p.m. | 1 hour, 15 minutes ago Description : Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and elevated GITHUB_TOKEN permissions. No approval gate exists. Pull requests from external users with author_association: "NONE" triggered the CI workflow automatically. The workflow directly executes attacker-controlled files from the fork checkout. This issue could have resulted in supply chain compromise, self-hosted runner compromise, and/or repository takeover for the repo. This issue is separate from GHSA-6mwm-v2vv-pp96, which addressed a command injection via github.head_ref in the setup job of the same workflow. That fix correctly moved to environment variables. Ho...

CVE-2026-12484 - Unsafe Deserialization in keras.layers.TorchModuleWrapper.from_config

CVE ID : CVE-2026-12484 Published : July 19, 2026, 7:47 p.m. | 34 minutes ago Description : A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)` without requiring an explicit unsafe opt-in, such as a `safe_mode=False` parameter. When called outside a `SafeModeScope(True)` context, the absence of an ambient safe mode state permits unsafe deserialization by default. This issue can lead to arbitrary code execution if untrusted Keras layer configurations are processed using this method. The vulnerability arises because the method does not enforce safe deserialization practices unless explicitly guarded by Keras safe mode. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities h...

CVE-2026-16150 - RobinHerbots Inputmask Internal Deep Merge Helper extend.js extendAliases prototype pollution

CVE ID : CVE-2026-16150 Published : July 18, 2026, 7:15 p.m. | 1 hour, 5 minutes ago Description : A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliases in the library lib/dependencyLibs/extend.js of the component Internal Deep Merge Helper. The manipulation results in improperly controlled modification of object prototype attributes. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/HLSBZk7 via IFTTT

CVE-2026-16130 - nearai ironclaw write_file path_utils.rs validate_path link following

CVE ID : CVE-2026-16130 Published : July 18, 2026, 5:15 p.m. | 1 hour, 5 minutes ago Description : A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of the file src/tools/builtin/path_utils.rs of the component write_file. The manipulation leads to link following. Local access is required to approach this attack. The exploit is publicly available and might be used. The identifier of the patch is 369ff3d240cf3c0787b50e1e9f182e1a06c71255. It is recommended to apply a patch to fix this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/sTdhbJP via IFTTT

CVE-2026-50163 - oras-go: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution in `oras-go` tar extraction

CVE ID : CVE-2026-50163 Published : July 17, 2026, 7:36 p.m. | 43 minutes ago Description : oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", " /payload.tar.gz/evil_cwd_link") to resolve header.Linkname against the process current working directory for a Typeflag=TypeLink entry such as Name=payload.tar.gz/evil_cwd_link and Linkname="victim.secret" with io.deis.oras.content.unpack: "true", which can expose or tamper with files such as .env, .git/config, .aws/credentials, and ~/.ssh/config. This issue is fixed in version 2.6.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/qCGlmyh via IFTTT

CVE-2026-13352 - Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion

CVE ID : CVE-2026-13352 Published : July 17, 2026, 5:16 a.m. | 1 hour, 2 minutes ago Description : The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due to the unconditional registration of an upload_mimes filter that adds executable file extensions (.exe, .apk, .msi) to the global WordPress MIME allowlist, without scoping the expansion to digital-product upload contexts. This makes it possible for authenticated attackers, with author-level access and above, to upload files that may be executable, which makes remote code execution possible. This filter is registered globally on every request regardless of whether the digital products feature is configured or in use, meaning the expanded MIME allowlist affects all WordPress upload contexts site-wide....

CVE-2026-62172 - Rejected reason: ** REJECT ** DO NOT USE THIS CAND

CVE ID : CVE-2026-62172 Published : July 15, 2026, 5:16 p.m. | 1 hour ago Description : Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61436. Reason: This candidate is a duplicate of CVE-2026-61436. Notes: All CVE users should reference CVE-2026-61436 instead of this candidate. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/4KUvHPJ via IFTTT

CVE-2026-59885 - pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service

CVE ID : CVE-2026-59885 Published : July 14, 2026, 5:17 p.m. | 59 minutes ago Description : pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/8qbdFst via IFTTT

CVE-2026-13221 - Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk

CVE ID : CVE-2026-13221 Published : July 13, 2026, 5:16 p.m. | 58 minutes ago Description : Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/YghOvKN via IFTTT

CVE-2026-10663 - Use-after-free / double-free of the root USB device in the experimental USB host stack

CVE ID : CVE-2026-10663 Published : July 12, 2026, 5:16 p.m. | 58 minutes ago Description : In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) freed the root usb_device slab object without clearing the cached pointer ctx->root. The bus removal handler dev_removed_handler() (subsys/usb/host/usbh_core.c) decides what to tear down solely from ctx->root, checking only that it is non-NULL. Because UHC controller drivers (e.g. uhc_max3421e, uhc_mcux_common) synthesize UHC_EVT_DEV_REMOVED directly from physical bus line state with no debounce or state guard, an attacker with physical USB access (or a rogue device that bounces its connection) can deliver a second device-removed event after a root device disconnect. The handler then re-enters usbh_device_disconnect() with the dangling pointer, locking a mutex inside the freed object (use-after-free), removing the freed node from the device list, and ...

CVE-2026-15470 - Eleveo Call Recording Software group.jsp improper authorization

CVE ID : CVE-2026-15470 Published : July 12, 2026, 12:16 a.m. | 1 hour, 57 minutes ago Description : A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functionality of the file /callrec/group.jsp. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/gpPBV6x via IFTTT

CVE-2026-58281 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVE ID : CVE-2026-58281 Published : July 11, 2026, 9:16 p.m. | 56 minutes ago Description : Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/kbH2WFc via IFTTT

CVE-2026-10660 - Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruption

CVE ID : CVE-2026-10660 Published : July 11, 2026, 5:16 p.m. | 56 minutes ago Description : The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.c reassembled remote Broadcast Receive State data into a single file-static net_buf_simple (att_buf, BT_ATT_MAX_ATTRIBUTE_LEN = 512 bytes) shared by all connection instances, while the BUSY flag, long-read handle, and reset/offset state were per-connection. When the device acts as a Broadcast Assistant connected to multiple Scan Delegator peripherals, notification and long-read callbacks from different connections interleave on the shared buffer: the append in notify_handler (net_buf_simple_add_mem at the not-busy branch) performs no tailroom check, so receive-state notifications from two or more delegators accumulate on the same 512-byte buffer and, with a sufficiently large configured ATT MTU (BT_L2CAP_TX_MTU up to 2000) and two-to-three concurrent connections, write past the buff...

CVE-2026-11426 - UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter

CVE ID : CVE-2026-11426 Published : July 11, 2026, 2:16 a.m. | 1 hour, 55 minutes ago Description : The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to the plugin accepting arbitrary local file paths in the template_thumbnail parameter and copying their contents into a publicly accessible uploads file. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary files on the server, which can contain sensitive information. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/IxVM7Fa via IFTTT

CVE-2026-59218 - Open WebUI: Account enumeration via observable login timing discrepancy

CVE ID : CVE-2026-59218 Published : July 9, 2026, 5:17 p.m. | 52 minutes ago Description : Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the /api/v1/auths/signin endpoint looked users up by email and only ran bcrypt password verification when a credential existed, making registered-account attempts measurably slower than missing-email attempts and allowing unauthenticated account enumeration. This issue is fixed in version 0.10.0. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/tnd15Sq via IFTTT

CVE-2026-45045 - Fiber: X-Real-IP Spoofing via Header.Add() in BalancerForward

CVE ID : CVE-2026-45045 Published : July 8, 2026, 7:26 p.m. | 20 minutes ago Description : Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-supplied first X-Real-IP value to be forwarded to upstream servers for logging, rate limiting, and access control. This issue is fixed in version 3.3.0 and 2.52.14. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/wtEJnqo via IFTTT

CVE-2026-59938 - pypdf: Possible large memory usage for wrong image dimensions

CVE ID : CVE-2026-59938 Published : July 8, 2026, 6:16 p.m. | 1 hour, 30 minutes ago Description : pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in version 6.14.0. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/E2KB1fi via IFTTT

CVE-2026-50530 - DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshared Datasets

CVE ID : CVE-2026-50530 Published : July 7, 2026, 9:17 p.m. | 28 minutes ago Description : DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the resourceId in the link token and fails to validate whether tableId and field IDs in the request body belong to the shared resource, allowing an attacker with a valid share link token to replace dataset identifiers and retrieve unauthorized data through POST /de2api/chartData/getData. This issue is fixed in version 2.10.24. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/S0RJUL4 via IFTTT

CVE-2026-11405 - Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface

CVE ID : CVE-2026-11405 Published : July 6, 2026, 7:17 p.m. | 28 minutes ago Description : The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password. A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/mlRWgrJ via IFTTT

CVE-2026-13753 - CVE-2026-13753

CVE ID : CVE-2026-13753 Published : July 6, 2026, 7:16 p.m. | 28 minutes ago Description : A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmware version Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/D4U5vOw via IFTTT

CVE-2026-58404 - Hugo security.http.urls deny rules bypassed by alternate IPv4 encodings

CVE ID : CVE-2026-58404 Published : July 6, 2026, 7:16 p.m. | 29 minutes ago Description : Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but the deny rule only matched dotted-decimal notation, so alternate IPv4 encodings of the same addresses, including integer, hex, or octal, passed the policy. When a template passes an untrusted or data-derived URL to resources.GetRemote and the host platform uses the cgo system resolver, these encodings resolve to the blocked address, allowing build-time server-side requests to loopback and internal services, including the cloud-metadata endpoint in hosted or CI builds; the same check is reused on redirects, so the gap also applies to each redirect hop. This issue is fixed in v0.163.1. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more.....

CVE-2026-41514 - OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery

CVE ID : CVE-2026-41514 Published : July 6, 2026, 7:06 p.m. | 38 minutes ago Description : OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the Hisilicon HPRE crypto driver uses non-constant-time `memcmp()` for label hash verification and has multiple distinguishable error paths. This creates a Manger-style padding oracle that allows an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext queries. Only affects plat-d06 with `CFG_HISILICON_ACC_V3=y`, which seems to be disabled by default. Version 4.11.0 contains a patch. As a workaround, disable Hisilicon HPRE RSA driver with `CFG_HISILICON_ACC_V3=n`. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more... ...

CVE-2026-14761 - radareorg radare2 str.c r_str_append integer overflow

CVE ID : CVE-2026-14761 Published : July 5, 2026, 4:19 p.m. | 1 hour, 25 minutes ago Description : A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. The manipulation leads to integer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The identifier of the patch is a20a56917ae85d732e683f8d9078bdcfee92446c. Applying a patch is the recommended action to fix this issue. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/kMYm6qN via IFTTT

CVE-2026-12195 - myVesta is affected by an authenticated remote cod

CVE ID : CVE-2026-12195 Published : July 4, 2026, 12:16 p.m. | 7 hours, 27 minutes ago Description : myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of commands as the admin user or takevoer of the admin user in myVesta. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/UqYpB9Q via IFTTT

CVE-2026-14612 - Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorization

CVE ID : CVE-2026-14612 Published : July 3, 2026, 3:11 p.m. | 2 hours, 32 minutes ago Description : Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/eNMiyKd via IFTTT

CVE-2026-13768 - Gardyn IoT Hub Use of Hard-coded Credentials

CVE ID : CVE-2026-13768 Published : July 2, 2026, 11:40 p.m. | 2 hours, 2 minutes ago Description : Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network. Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/0Zv4W2A via IFTTT

CVE-2026-13743 - Improper verification of cryptographic signature in CubeSpace CW0057 Reaction Wheel

CVE ID : CVE-2026-13743 Published : July 2, 2026, 6:35 p.m. | 1 hour, 7 minutes ago Description : CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Verification of Cryptographic Signature vulnerability. This could allow an attacker with physical access to the product to upload arbitrary malicious firmware to the device without authentication. Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/qMHDfY6 via IFTTT

CVE-2026-58465 - Eclipse Wakaama CoAP Block1 Handler Unbounded Memory Allocation DoS

CVE ID : CVE-2026-58465 Published : July 2, 2026, 5:55 p.m. | 1 hour, 48 minutes ago Description : Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that allows unauthenticated remote attackers to exhaust server memory by sending a sequence of Block1 PUT requests with incrementing block numbers. Attackers can target the registration endpoint over UDP without authentication, causing the server to repeatedly reallocate a growing accumulation buffer by appending each block payload without enforcing any maximum total size limit, resulting in denial of service through memory exhaustion. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... from Latest Vulnerabilities https://ift.tt/TZJfNCK via IFTTT

CVE-2026-55791 - Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

CVE ID : CVE-2026-55791 Published : July 1, 2026, 11:13 p.m. | 2 hours, 28 minutes ago Description : Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /actions/app/resource-js endpoint. By exploiting the default permissive trustedHosts configuration, an attacker can poison the Host or X-Forwarded-Host header to manipulate the application’s $baseUrl. This bypasses the endpoint’s internal URL validation, forcing the backend Guzzle client to fetch a malicious payload from an attacker-controlled server and reflect it to the client with a Content-Type: application/javascript header. The vulnerability manifests when assetManager.cacheSourcePaths is set to false. This issue has been fixed in versions 4.18.0 and 5.10.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS d...