/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/vulners.csv
133 строки235 KB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
CVE-2026-4110
CVE-2026-4110 Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
NONE
0.00
NONE
2026-06-22 06:00:01+03:00
2026-06-22 06:00:01+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-4110']
['CVE-2026-4110']
0ed32423c14088d5da7248436d8ab4f542cb8441e19d960db4160a7647d0e2b3
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-4110', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-4110', 'type': 'cvelist', 'title': 'CVE-2026-4110 Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list', 'cvelist': ['CVE-2026-4110'], 'assigned': '2026-03-13T10:56:13', 'lastseen': '2026-06-22T17:20:51', 'modified': '2026-06-22T06:00:01', 'published': '2026-06-22T06:00:01', 'description': 'The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:FF547C51-1942-4CD2-B1C0-A95795119CB1']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-4110']}, {'type': 'cve', 'idList': ['CVE-2026-4110']}, {'type': 'euvd', 'idList': ['EUVD-2026-38211']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-4110']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51276']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-4110']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-4259
CVE-2026-4259 Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
NONE
0.00
NONE
2026-06-22 06:00:01+03:00
2026-06-22 06:00:01+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-4259']
['CVE-2026-4259']
dca7319f57b5b9890bc3fca86fa875e03194e09a4f3575a190c044028bd3c835
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-4259', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-4259', 'type': 'cvelist', 'title': 'CVE-2026-4259 Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions', 'cvelist': ['CVE-2026-4259'], 'assigned': '2026-03-16T10:30:53', 'lastseen': '2026-06-22T13:45:12', 'modified': '2026-06-22T06:00:01', 'published': '2026-06-22T06:00:01', 'description': 'The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F1B11E66-1334-43A8-9AEB-537B6646E14E']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-4259']}, {'type': 'cve', 'idList': ['CVE-2026-4259']}, {'type': 'euvd', 'idList': ['EUVD-2026-38212']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-4259']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51277']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-4259']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-6645
CVE-2026-6645 Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows
An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference. Because the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executable. Under specific conditions, a local attacker with the ability to modify directories within the system's search path could plant a malicious binary that mimics the expected utility. This could result in the malicious code being executed with SYSTEM privileges, leading to a full compromise of the affected host.
HIGH
7.30
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H
2026-06-22 03:24:06+03:00
2026-06-22 03:24:06+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-6645']
['CVE-2026-6645']
b1dea75c081b954e58111411035d17dc31cf79cbb0b0783d544b49485c8466ba
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-6645', 'cvss': {'score': 7.3, 'source': 'papercut', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-6645', 'type': 'cvelist', 'title': 'CVE-2026-6645 Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows', 'cvelist': ['CVE-2026-6645'], 'assigned': '2026-04-20T04:12:52', 'lastseen': '2026-06-23T05:14:40', 'modified': '2026-06-22T03:24:06', 'published': '2026-06-22T03:24:06', 'description': "An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference.\n\n\n\nBecause the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executable. Under specific conditions, a local attacker with the ability to modify directories within the system's search path could plant a malicious binary that mimics the expected utility. This could result in the malicious code being executed with SYSTEM privileges, leading to a full compromise of the affected host.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:93506F19-5C22-422D-925E-9E653F6DBABD']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-6645']}, {'type': 'cve', 'idList': ['CVE-2026-6645']}, {'type': 'euvd', 'idList': ['EUVD-2026-38209']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-6645']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51274']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-6645']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-7859
CVE-2026-7859 Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media
The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.
NONE
0.00
NONE
2026-06-22 06:00:02+03:00
2026-06-22 06:00:02+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-7859']
['CVE-2026-7859']
24ffdfaf1853e912f4f2b5a882dd7616280b4707ef5dfd180f27aaab7e8f7985
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-7859', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-7859', 'type': 'cvelist', 'title': 'CVE-2026-7859 Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media', 'cvelist': ['CVE-2026-7859'], 'assigned': '2026-05-05T11:51:07', 'lastseen': '2026-06-22T13:45:09', 'modified': '2026-06-22T06:00:02', 'published': '2026-06-22T06:00:02', 'description': 'The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:60E39E17-A3B8-45B0-9E72-797DD229D4A3']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-7859']}, {'type': 'cve', 'idList': ['CVE-2026-7859']}, {'type': 'euvd', 'idList': ['EUVD-2026-38214']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-7859']}, {'type': 'patchstack', 'idList': ['PATCHSTACK:F80C1FFB06324183D30A07CE934BAED4']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51279']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-7859']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-62198
CVE-2025-62198 Apache Atlas: Stored XSS in Create Entity page
An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which fixes the issue.
NONE
0.00
NONE
2026-06-22 07:47:11+03:00
2026-06-22 07:47:11+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-62198']
['CVE-2025-62198']
f69d40845f3491a0de5cb9e12f12551bafdf06bac0cabe31bba79ab48d70f2da
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2025-62198', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-62198', 'type': 'cvelist', 'title': 'CVE-2025-62198 Apache Atlas: Stored XSS in Create Entity page', 'cvelist': ['CVE-2025-62198'], 'assigned': '2025-10-08T19:44:39', 'lastseen': '2026-06-22T17:20:57', 'modified': '2026-06-22T07:47:11', 'published': '2026-06-22T07:47:11', 'description': 'An authenticated user can perform XSS.\n\nThis issue affects Apache Atlas versions 2.4.0 and earlier.\n\nUsers are recommended to upgrade to version 2.5.0, which fixes the issue.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F6971516-4396-4C18-AE10-94061C319005']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2025-62198']}, {'type': 'cve', 'idList': ['CVE-2025-62198']}, {'type': 'euvd', 'idList': ['EUVD-2025-210296']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-62198']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51187']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-62198']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-66336
CVE-2025-66336 Apache Doris MCP Server: SQL injection leading the authentication bypass
Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope. Affected users are recommended to upgrade to Doris version 0.6.1 or later, which fixes the issue.
NONE
0.00
NONE
2026-06-22 06:55:17+03:00
2026-06-22 06:55:17+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-66336']
['CVE-2025-66336']
c42b51653105bb7d2b1a046c301dd0b302ca64377e4c3c2e1417725d3651fbc7
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2025-66336', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-66336', 'type': 'cvelist', 'title': 'CVE-2025-66336 Apache Doris MCP Server: SQL injection leading the authentication bypass', 'cvelist': ['CVE-2025-66336'], 'assigned': '2025-11-27T03:24:32', 'lastseen': '2026-06-22T17:20:56', 'modified': '2026-06-22T06:55:17', 'published': '2026-06-22T06:55:17', 'description': "Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope.\n\nAffected users are recommended to upgrade to Doris version 0.6.1 or later, which fixes the issue.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:73BEB738-08D7-4878-BA5C-D61F9747B002']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2025-66336']}, {'type': 'cve', 'idList': ['CVE-2025-66336']}, {'type': 'euvd', 'idList': ['EUVD-2025-210295']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-66336']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51281']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-66336']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-10530
CVE-2026-10530 Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token
The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox.
NONE
0.00
NONE
2026-06-22 06:00:01+03:00
2026-06-22 06:00:01+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-10530']
['CVE-2026-10530']
e0d92375328c31ac7fdba17d4dc415b7c6f84c8ded4fa9d7934b69e83ea5b397
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-10530', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10530', 'type': 'cvelist', 'title': 'CVE-2026-10530 Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token', 'cvelist': ['CVE-2026-10530'], 'assigned': '2026-06-01T11:10:04', 'lastseen': '2026-06-22T17:20:56', 'modified': '2026-06-22T06:00:01', 'published': '2026-06-22T06:00:01', 'description': 'The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:45ECB853-3DC9-4F38-9CEA-C26AB8C2F318']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10530']}, {'type': 'cve', 'idList': ['CVE-2026-10530']}, {'type': 'euvd', 'idList': ['EUVD-2026-38210']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10530']}, {'type': 'patchstack', 'idList': ['PATCHSTACK:4DFA2728274A1C0089618E2656A115DC']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51275']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10530']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-6858
CVE-2026-6858 Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS
The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator
NONE
0.00
NONE
2026-06-22 06:00:02+03:00
2026-06-22 06:00:02+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-6858']
['CVE-2026-6858']
a6c757e7c2f8518b8eae61e3832f7357cf856320e437dafbb1abbf16764b8fb7
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-6858', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-6858', 'type': 'cvelist', 'title': 'CVE-2026-6858 Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS', 'cvelist': ['CVE-2026-6858'], 'assigned': '2026-04-22T12:53:03', 'lastseen': '2026-06-22T13:45:09', 'modified': '2026-06-22T06:00:02', 'published': '2026-06-22T06:00:02', 'description': 'The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:3677D938-A0A6-4D39-88A9-04A2BD052CF4']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-6858']}, {'type': 'cve', 'idList': ['CVE-2026-6858']}, {'type': 'euvd', 'idList': ['EUVD-2026-38213']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-6858']}, {'type': 'patchstack', 'idList': ['PATCHSTACK:28EC951852509AE923742B4B90A335A9']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51278']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-6858']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-11745
CVE-2026-11745
A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored repositories.
HIGH
8.80
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:N/SA:L
2026-06-22 02:33:08+03:00
2026-06-22 02:33:08+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-11745']
['CVE-2026-11745']
50ba2808d6505112f9c55e012e167e86a1ec490d7eadf5d968bdcbd35fb6e906
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-11745', 'cvss': {'score': 8.8, 'source': 'ly-corporation', 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:N/SA:L', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-11745', 'type': 'cvelist', 'title': 'CVE-2026-11745', 'cvelist': ['CVE-2026-11745'], 'assigned': '2026-06-09T06:46:10', 'lastseen': '2026-06-22T17:20:55', 'modified': '2026-06-22T02:33:08', 'published': '2026-06-22T02:33:08', 'description': 'A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored repositories.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:C1D827CC-671F-4390-8B70-34C72953B8EF']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-11745']}, {'type': 'cve', 'idList': ['CVE-2026-11745']}, {'type': 'euvd', 'idList': ['EUVD-2026-38206']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-11745']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51270']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-11745']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-11746
CVE-2026-11746
A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster.
CRITICAL
9.40
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H
2026-06-22 02:35:51+03:00
2026-06-22 02:35:51+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-11746']
['CVE-2026-11746']
2368dc6d209bd9044bb5db43250efd5598b2513809ec1794c5f9da58c13257b4
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-11746', 'cvss': {'score': 9.4, 'source': 'ly-corporation', 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H', 'version': '4.0', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-11746', 'type': 'cvelist', 'title': 'CVE-2026-11746', 'cvelist': ['CVE-2026-11746'], 'assigned': '2026-06-09T06:48:47', 'lastseen': '2026-06-22T17:20:55', 'modified': '2026-06-22T02:35:51', 'published': '2026-06-22T02:35:51', 'description': 'A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F4C234B1-88EE-4B98-970E-15B83EA668F6']}, {'type': 'cve', 'idList': ['CVE-2026-11746']}, {'type': 'euvd', 'idList': ['EUVD-2026-38207']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-11746']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51271']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-11746']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-11748
CVE-2026-11748
A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure.
MEDIUM
6.90
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:L/VI:L/SI:N/VA:N/SA:N
2026-06-22 02:37:35+03:00
2026-06-22 02:37:35+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-11748']
['CVE-2026-11748']
cf8b781e95ce5a34f1600c391139d9ab898deafbf421113f5603d6adda14654a
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-11748', 'cvss': {'score': 6.9, 'source': 'ly-corporation', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:L/VI:L/SI:N/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-11748', 'type': 'cvelist', 'title': 'CVE-2026-11748', 'cvelist': ['CVE-2026-11748'], 'assigned': '2026-06-09T06:50:03', 'lastseen': '2026-06-22T17:20:55', 'modified': '2026-06-22T02:37:35', 'published': '2026-06-22T02:37:35', 'description': 'A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F06A0281-2B2D-4735-BEF5-DB4524CE43D7']}, {'type': 'cve', 'idList': ['CVE-2026-11748']}, {'type': 'euvd', 'idList': ['EUVD-2026-38208']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-11748']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51272']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-11748']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-44911
CVE-2026-44911 Apache NiFi: Incorrect Authorization for Configuration Verification Requests
Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verification methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying component configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, requiring write access to submit configuration verification requests.
LOW
2.30
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/SC:L/VI:L/SI:L/VA:L/SA:L/AU:Y/U:Amber/R:U/V:C/RE:L
2026-06-22 07:37:10+03:00
2026-06-22 07:37:10+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-44911']
['CVE-2026-44911']
8846f1893cf5ba6191b0e8d7eb12fba1c112cdec966803bec05d0cd0d71f83fc
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-44911', 'cvss': {'score': 2.3, 'source': 'apache', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/SC:L/VI:L/SI:L/VA:L/SA:L/AU:Y/U:Amber/R:U/V:C/RE:L', 'version': '4.0', 'severity': 'LOW'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-44911', 'type': 'cvelist', 'title': 'CVE-2026-44911 Apache NiFi: Incorrect Authorization for Configuration Verification Requests', 'cvelist': ['CVE-2026-44911'], 'assigned': '2026-05-08T03:42:57', 'lastseen': '2026-06-22T13:45:11', 'modified': '2026-06-22T07:37:10', 'published': '2026-06-22T07:37:10', 'description': 'Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verification methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying component configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, requiring write access to submit configuration verification requests.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:2D3B3BB7-1A17-4912-BB66-1C540FE3E6B2']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-44911']}, {'type': 'cve', 'idList': ['CVE-2026-44911']}, {'type': 'euvd', 'idList': ['EUVD-2026-38218']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-44911']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51282']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-44911']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-44913
CVE-2026-44913 Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover additional strategies. Apache NiFi installations that do not use the CaptureChangeMySQL Processor are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which incorporates more robust identifier escaping.
MEDIUM
5.20
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/SC:H/VI:N/SI:H/VA:N/SA:H/S:P/AU:Y/U:Clear/R:U/V:C/RE:L
2026-06-22 07:36:40+03:00
2026-06-22 07:36:40+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-44913']
['CVE-2026-44913']
8737cc68e8882d96495c854dd4f297e39454e9fb618fa20b0200a8f8ec7c728a
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-44913', 'cvss': {'score': 5.2, 'source': 'apache', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/SC:H/VI:N/SI:H/VA:N/SA:H/S:P/AU:Y/U:Clear/R:U/V:C/RE:L', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-44913', 'type': 'cvelist', 'title': 'CVE-2026-44913 Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL', 'cvelist': ['CVE-2026-44913'], 'assigned': '2026-05-08T04:15:35', 'lastseen': '2026-06-22T13:45:11', 'modified': '2026-06-22T07:36:40', 'published': '2026-06-22T07:36:40', 'description': 'Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover additional strategies. Apache NiFi installations that do not use the CaptureChangeMySQL Processor are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which incorporates more robust identifier escaping.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:55F99D7B-D558-4A7D-AC4D-155EC90FF125']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-44913']}, {'type': 'cve', 'idList': ['CVE-2026-44913']}, {'type': 'euvd', 'idList': ['EUVD-2026-38217']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-44913']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51283']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-44913']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-44914
CVE-2026-44914 Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization permits a user with general write access to add components with Restricted status. Apache NiFi installations that do not implement specific authorization for Restricted components are not subject to this vulnerability because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, which removes the implementation of Restricted status authorization from the framework.
HIGH
7.50
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/SC:L/VI:H/SI:L/VA:H/SA:L/S:P/AU:Y/U:Clear/R:U/V:C/RE:L
2026-06-22 07:38:01+03:00
2026-06-22 07:38:01+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-44914']
['CVE-2026-44914']
39a30011c50b5da44a67996ec8385a0b5a6e08c6da5854df8f04a682e3cb63d3
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-44914', 'cvss': {'score': 7.5, 'source': 'apache', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/SC:L/VI:H/SI:L/VA:H/SA:L/S:P/AU:Y/U:Clear/R:U/V:C/RE:L', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-44914', 'type': 'cvelist', 'title': 'CVE-2026-44914 Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents', 'cvelist': ['CVE-2026-44914'], 'assigned': '2026-05-08T04:30:00', 'lastseen': '2026-06-22T13:45:12', 'modified': '2026-06-22T07:38:01', 'published': '2026-06-22T07:38:01', 'description': 'Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization permits a user with general write access to add components with Restricted status. Apache NiFi installations that do not implement specific authorization for Restricted components are not subject to this vulnerability because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, which removes the implementation of Restricted status authorization from the framework.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B711E1E7-B5E3-4CAE-9A8B-EB8224EE005E']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-44914']}, {'type': 'cve', 'idList': ['CVE-2026-44914']}, {'type': 'euvd', 'idList': ['EUVD-2026-38219']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-44914']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51284']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-44914']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-54665
CVE-2026-54665 Apache NiFi: Missing Validation for Proxy Host Headers
Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict values provided in the HTTP Host header, but did not apply the validation to alternative Proxy and Forwarded headers. The absence of proxy host header validation allowed a client to instruct Apache NiFi web services to construct invalid qualified URLs for redirection or data references. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which implements validation for the X-ProxyHost and X-Forwarded-Host HTTP request headers based on the nifi.web.proxy.host property. Enabling header validation requires configuring the application with HTTPS. Reverse proxy servers in front of Apache NiFi are responsible for filtering input request headers and providing allowed values to the application.
MEDIUM
6.30
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N/S:N/AU:Y/U:Green/R:A/V:D/RE:L
2026-06-22 07:34:13+03:00
2026-06-22 07:34:13+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-54665']
['CVE-2026-54665']
9d90d6808684a8d9910384504693a9661c1634ffb0e62901aea7bb527e0ccfb0
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-54665', 'cvss': {'score': 6.3, 'source': 'apache', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N/S:N/AU:Y/U:Green/R:A/V:D/RE:L', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-54665', 'type': 'cvelist', 'title': 'CVE-2026-54665 Apache NiFi: Missing Validation for Proxy Host Headers', 'cvelist': ['CVE-2026-54665'], 'assigned': '2026-06-15T20:22:59', 'lastseen': '2026-06-22T17:20:44', 'modified': '2026-06-22T07:34:13', 'published': '2026-06-22T07:34:13', 'description': 'Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict values provided in the HTTP Host header, but did not apply the validation to alternative Proxy and Forwarded headers. The absence of proxy host header validation allowed a client to instruct Apache NiFi web services to construct invalid qualified URLs for redirection or data references. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which implements validation for the X-ProxyHost and X-Forwarded-Host HTTP request headers based on the nifi.web.proxy.host property. Enabling header validation requires configuring the application with HTTPS. Reverse proxy servers in front of Apache NiFi are responsible for filtering input request headers and providing allowed values to the application.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:7DAA55DD-2A66-4747-9AC5-E2FF48A55015']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-54665']}, {'type': 'cve', 'idList': ['CVE-2026-54665']}, {'type': 'euvd', 'idList': ['EUVD-2026-38216']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-54665']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51195']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-54665']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-8157
CVE-2026-8157 Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation
The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.
NONE
0.00
NONE
2026-06-22 06:00:02+03:00
2026-06-22 06:00:02+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-8157']
['CVE-2026-8157']
704c6bebce05e709f005b7c453d4eb55cf841f0287768ff3b806d0cfa8907889
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-8157', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-8157', 'type': 'cvelist', 'title': 'CVE-2026-8157 Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation', 'cvelist': ['CVE-2026-8157'], 'assigned': '2026-05-08T09:14:33', 'lastseen': '2026-06-22T13:45:08', 'modified': '2026-06-22T06:00:02', 'published': '2026-06-22T06:00:02', 'description': 'The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:E3C9FF3B-9249-4CDB-8DEA-E944BB87734F']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-8157']}, {'type': 'cve', 'idList': ['CVE-2026-8157']}, {'type': 'euvd', 'idList': ['EUVD-2026-38215']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-8157']}, {'type': 'patchstack', 'idList': ['PATCHSTACK:2CBF2A1F1BE08EFFD66ACBEAF4394A1C']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51280']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-8157']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-8918
CVE-2026-8918
A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
HIGH
7.10
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
2026-06-22 02:00:12+03:00
2026-06-22 02:00:12+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-8918']
['CVE-2026-8918']
367663285dfd53f92345d056c176058b73e09662e97aa02f5c603ff9e5f0a347
2026-06-23 15:06:55.636806+03:00
2026-06-23 15:06:55.636806+03:00
{'id': 'CVELIST:CVE-2026-8918', 'cvss': {'score': 7.1, 'source': 'asus', 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-8918', 'type': 'cvelist', 'title': 'CVE-2026-8918', 'cvelist': ['CVE-2026-8918'], 'assigned': '2026-05-19T05:57:37', 'lastseen': '2026-06-22T13:45:08', 'modified': '2026-06-22T02:00:12', 'published': '2026-06-22T02:00:12', 'description': "A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the '\nSecurity Update for Armoury Crate App\xa0' section on the ASUS Security Advisory for more information.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B1F7AB83-9015-4B72-9A64-5580C1984EAD']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-8918']}, {'type': 'cve', 'idList': ['CVE-2026-8918']}, {'type': 'euvd', 'idList': ['EUVD-2026-38205']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-8918']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51273']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-8918']}]}}, 'bulletinFamily': 'cve'}
CVE-2020-37256
CVE-2020-37256 Grav - Cross-Site Scripting in Admin Plugin Page Editor
Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.
MEDIUM
5.40
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
2026-06-25 21:41:00+03:00
2026-06-25 21:41:00+03:00
['https://www.cve.org/CVERecord?id=CVE-2020-37256']
['CVE-2020-37256']
f1d8af1a6c821e1b9230d173fc73424d3dbd85e204cae6b630d4e8538c3903b9
2026-06-26 15:06:33.367280+03:00
2026-06-26 15:06:33.367280+03:00
{'id': 'CVELIST:CVE-2020-37256', 'cvss': {'score': 5.4, 'source': 'vulncheck', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2020-37256', 'type': 'cvelist', 'title': 'CVE-2020-37256 Grav - Cross-Site Scripting in Admin Plugin Page Editor', 'cvelist': ['CVE-2020-37256'], 'assigned': '2026-06-22T21:55:13', 'lastseen': '2026-06-25T21:59:22', 'modified': '2026-06-25T21:41:00', 'published': '2026-06-25T21:41:00', 'description': 'Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:1BEE21E6-5D18-4BFB-81CC-43999B31DAD2']}, {'type': 'cve', 'idList': ['CVE-2020-37256']}, {'type': 'euvd', 'idList': ['EUVD-2020-31260']}, {'type': 'nvd', 'idList': ['NVD:CVE-2020-37256']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52606']}]}}, 'bulletinFamily': 'cve'}
CVE-2023-54365
CVE-2023-54365 Traefik - Denial of Service via HTTP/2 Request Handling
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.
HIGH
8.70
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N
2026-06-23 12:12:51+03:00
2026-06-23 12:12:51+03:00
['https://www.cve.org/CVERecord?id=CVE-2023-54365']
['CVE-2023-54365']
403a6819bd2287927a7c9885a7080a5dd7592ad010ae8506db6d4f4d76da587d
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2023-54365', 'cvss': {'score': 8.7, 'source': 'vulncheck', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2023-54365', 'type': 'cvelist', 'title': 'CVE-2023-54365 Traefik - Denial of Service via HTTP/2 Request Handling', 'cvelist': ['CVE-2023-54365'], 'assigned': '2026-06-22T21:54:30', 'lastseen': '2026-06-23T18:50:59', 'modified': '2026-06-23T12:12:51', 'published': '2026-06-23T12:12:51', 'description': "Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:ADB6030A-3F7E-4FE2-B825-0D60A828CEBD']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2023-54365']}, {'type': 'cve', 'idList': ['CVE-2023-54365']}, {'type': 'euvd', 'idList': ['EUVD-2023-60596']}, {'type': 'nvd', 'idList': ['NVD:CVE-2023-54365']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51489']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2023-54365']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-13162
CVE-2025-13162 Advant Master Online Builder DLL vulnerability
Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1.
MEDIUM
4.40
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
2026-06-23 16:12:54+03:00
2026-06-23 16:19:27+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-13162']
['CVE-2025-13162']
3aad640ebb3c0a4c2777aeaf7f91954c1dd9b7dc40bea990c94da924bccf09e4
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-13162', 'cvss': {'score': 4.4, 'source': 'abb', 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-13162', 'type': 'cvelist', 'title': 'CVE-2025-13162 Advant Master Online Builder DLL vulnerability', 'cvelist': ['CVE-2025-13162'], 'assigned': '2025-11-14T03:20:45', 'lastseen': '2026-06-23T17:21:07', 'modified': '2026-06-23T16:19:27', 'published': '2026-06-23T16:12:54', 'description': 'Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master.\n\nThis issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F1184D30-E4EE-49F9-B722-76828C59BAAA']}, {'type': 'cve', 'idList': ['CVE-2025-13162']}, {'type': 'euvd', 'idList': ['EUVD-2025-210312']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-13162']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51536']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-13162']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-33128
CVE-2025-33128 IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observed
IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
MEDIUM
5.40
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
2026-06-22 13:20:14+03:00
2026-06-22 13:20:14+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-33128']
['CVE-2025-33128']
0f4d97a14767b874bf290ae56566e6ba321221d20157df68370e03b05c59be12
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-33128', 'cvss': {'score': 5.4, 'source': 'ibm', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-33128', 'type': 'cvelist', 'title': 'CVE-2025-33128 IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observed', 'cvelist': ['CVE-2025-33128'], 'assigned': '2025-04-15T17:51:11', 'lastseen': '2026-06-23T14:38:45', 'modified': '2026-06-22T13:20:14', 'published': '2026-06-22T13:20:14', 'description': 'IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:EEAAC1BC-D6E8-4E02-A3AC-D59F1FD378EA']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2025-33128']}, {'type': 'cve', 'idList': ['CVE-2025-33128']}, {'type': 'euvd', 'idList': ['EUVD-2025-210300']}, {'type': 'ibm', 'idList': ['7566794E33524AD01D321DA9156E41999550443F03430173A12658C8D2FF4C6D']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-33128']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51296']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-33128']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-4994
CVE-2025-4994 Authentication Bypass for SafeLine SL6 and SL6+
The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an attacker within wireless range can gain unauthorized administrative access to the device configuration.
HIGH
8.70
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
2026-06-22 08:10:29+03:00
2026-06-22 08:10:29+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-4994']
['CVE-2025-4994']
55b15578149fe218e9314e5a06a5d5f89de06600b54a651fc027151f7ee55385
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-4994', 'cvss': {'score': 8.7, 'source': 'schutzwerk', 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-4994', 'type': 'cvelist', 'title': 'CVE-2025-4994 Authentication Bypass for SafeLine SL6 and SL6+', 'cvelist': ['CVE-2025-4994'], 'assigned': '2025-05-20T08:40:34', 'lastseen': '2026-06-22T13:45:16', 'modified': '2026-06-22T08:10:29', 'published': '2026-06-22T08:10:29', 'description': "The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an attacker within wireless range can gain unauthorized administrative access to the device configuration.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:16BB0AD7-954A-41DA-9321-F28520B10EAD']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2025-4994']}, {'type': 'cve', 'idList': ['CVE-2025-4994']}, {'type': 'euvd', 'idList': ['EUVD-2025-210297']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-4994']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51287']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-4994']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-61018
CVE-2025-61018
An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
NONE
0.00
NONE
2026-06-23 00:00:00+03:00
2026-06-23 16:27:47+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-61018']
['CVE-2025-61018']
6b2010e147b3c5cafc7061469c2f182e835f6474c779b922dc444e122acc291c
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-61018', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61018', 'type': 'cvelist', 'title': 'CVE-2025-61018', 'cvelist': ['CVE-2025-61018'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T17:09:05', 'modified': '2026-06-23T16:27:47', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F6573896-9423-47E3-98B5-8AAEDE8DC9D4']}, {'type': 'cve', 'idList': ['CVE-2025-61018']}, {'type': 'euvd', 'idList': ['EUVD-2025-210313']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61018']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51537']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61018']}]}}, 'bulletinFamily': 'cve'}
CVE-2021-47986
CVE-2021-47986 Parse Server - Unreviewed Code Execution via Malicious Version Tags
Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.
HIGH
7.70
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
2026-06-25 21:41:01+03:00
2026-06-25 21:41:01+03:00
['https://www.cve.org/CVERecord?id=CVE-2021-47986']
['CVE-2021-47986']
cd301c70359ee23ebef2c6b9a7e3c83e4a50041675c3492d6560a31b7573f4f7
2026-06-26 15:06:33.367280+03:00
2026-06-26 15:06:33.367280+03:00
{'id': 'CVELIST:CVE-2021-47986', 'cvss': {'score': 7.7, 'source': 'vulncheck', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2021-47986', 'type': 'cvelist', 'title': 'CVE-2021-47986 Parse Server - Unreviewed Code Execution via Malicious Version Tags', 'cvelist': ['CVE-2021-47986'], 'assigned': '2026-06-21T02:08:33', 'lastseen': '2026-06-26T11:02:41', 'modified': '2026-06-25T21:41:01', 'published': '2026-06-25T21:41:01', 'description': 'Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:2F9390AC-E9D6-47EA-B782-500C41AD4324']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2021-47986']}, {'type': 'cve', 'idList': ['CVE-2021-47986']}, {'type': 'euvd', 'idList': ['EUVD-2021-34852']}, {'type': 'nvd', 'idList': ['NVD:CVE-2021-47986']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52607']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2021-47986']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-61019
CVE-2025-61019
An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
NONE
0.00
NONE
2026-06-23 00:00:00+03:00
2026-06-23 16:05:10+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-61019']
['CVE-2025-61019']
d437b9e1eb0fd07f2661c7a72baef69965fbf685e45e0ef4b56b974cee3563a1
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-61019', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61019', 'type': 'cvelist', 'title': 'CVE-2025-61019', 'cvelist': ['CVE-2025-61019'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:39:09', 'modified': '2026-06-23T16:05:10', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F0B3C4B0-78E4-4979-B40A-53F46F8F79FA']}, {'type': 'cve', 'idList': ['CVE-2025-61019']}, {'type': 'euvd', 'idList': ['EUVD-2025-210314']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61019']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51538']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-61020
CVE-2025-61020
An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
NONE
0.00
NONE
2026-06-23 00:00:00+03:00
2026-06-23 16:31:26+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-61020']
['CVE-2025-61020']
3fd2ef71290fb0cb1c9507e13e88f4f710bdff0f5ca3778edf1b809cb7aee11c
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-61020', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61020', 'type': 'cvelist', 'title': 'CVE-2025-61020', 'cvelist': ['CVE-2025-61020'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T17:03:05', 'modified': '2026-06-23T16:31:26', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:E6975176-4C1D-4D44-9264-FE005D4F8F3D']}, {'type': 'cve', 'idList': ['CVE-2025-61020']}, {'type': 'euvd', 'idList': ['EUVD-2025-210315']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61020']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51539']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61020']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-61021
CVE-2025-61021
An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
NONE
0.00
NONE
2026-06-23 00:00:00+03:00
2026-06-23 16:02:27+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-61021']
['CVE-2025-61021']
5f842f0d7e4ad70ea751f70179e892c37c1c0333c6b1306c8bca7d5273a8a1c1
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-61021', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61021', 'type': 'cvelist', 'title': 'CVE-2025-61021', 'cvelist': ['CVE-2025-61021'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:39:09', 'modified': '2026-06-23T16:02:27', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B0AE8D9A-C526-431A-B3E3-8036DDADF379']}, {'type': 'cve', 'idList': ['CVE-2025-61021']}, {'type': 'euvd', 'idList': ['EUVD-2025-210316']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61021']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51540']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-61022
CVE-2025-61022
An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
NONE
0.00
NONE
2026-06-23 00:00:00+03:00
2026-06-23 16:34:07+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-61022']
['CVE-2025-61022']
70172505b0ecb86ca70c58d2c2a1b5131ca91cc9458dc1d399267038ba889c2c
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-61022', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61022', 'type': 'cvelist', 'title': 'CVE-2025-61022', 'cvelist': ['CVE-2025-61022'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T17:03:05', 'modified': '2026-06-23T16:34:07', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:AB2CB8A1-9532-4188-A25A-8A38F8A16C50']}, {'type': 'cve', 'idList': ['CVE-2025-61022']}, {'type': 'euvd', 'idList': ['EUVD-2025-210317']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61022']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51541']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2025-61022']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61022']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-61023
CVE-2025-61023
An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
NONE
0.00
NONE
2026-06-23 00:00:00+03:00
2026-06-23 16:19:19+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-61023']
['CVE-2025-61023']
3724850f174f674170915f3a0969f7cebfe099e970b4ecfb48eacd1d41f5abbb
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-61023', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61023', 'type': 'cvelist', 'title': 'CVE-2025-61023', 'cvelist': ['CVE-2025-61023'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:39:09', 'modified': '2026-06-23T16:19:19', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:019EE181-A0F5-4A15-8629-64DB742ADEC4']}, {'type': 'cve', 'idList': ['CVE-2025-61023']}, {'type': 'euvd', 'idList': ['EUVD-2025-210318']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61023']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51542']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-61024
CVE-2025-61024
An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
NONE
0.00
NONE
2026-06-23 00:00:00+03:00
2026-06-23 16:40:30+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-61024']
['CVE-2025-61024']
6053c2ee5461122e1a2f8781853bd65d1d6f71db32ea50f94235cc6ecb2af4b5
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-61024', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61024', 'type': 'cvelist', 'title': 'CVE-2025-61024', 'cvelist': ['CVE-2025-61024'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T17:56:42', 'modified': '2026-06-23T16:40:30', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F6F6CDA0-278E-4DCF-880C-E14550D43D21']}, {'type': 'cve', 'idList': ['CVE-2025-61024']}, {'type': 'euvd', 'idList': ['EUVD-2025-210323']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61024']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51569']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2025-61024']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61024']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-61025
CVE-2025-61025
An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
NONE
0.00
NONE
2026-06-23 00:00:00+03:00
2026-06-23 16:36:40+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-61025']
['CVE-2025-61025']
7d6d87ab9ba2c774bf316e06fb06d419d62999ef8e3e840597f5f8279fa0994c
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-61025', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61025', 'type': 'cvelist', 'title': 'CVE-2025-61025', 'cvelist': ['CVE-2025-61025'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:57:05', 'modified': '2026-06-23T16:36:40', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:29035747-D3AC-41FF-9E3F-13545641B123']}, {'type': 'cve', 'idList': ['CVE-2025-61025']}, {'type': 'euvd', 'idList': ['EUVD-2025-210319']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61025']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51543']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61025']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-61027
CVE-2025-61027
An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
NONE
0.00
NONE
2026-06-23 00:00:00+03:00
2026-06-23 16:24:33+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-61027']
['CVE-2025-61027']
c80a4982ce907c94bdb1e32872238020be948382cee459a8888b3cde28f80bfe
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-61027', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61027', 'type': 'cvelist', 'title': 'CVE-2025-61027', 'cvelist': ['CVE-2025-61027'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:39:09', 'modified': '2026-06-23T16:24:33', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:7340418F-BA84-4EC2-B301-7A63C5021D1E']}, {'type': 'cve', 'idList': ['CVE-2025-61027']}, {'type': 'euvd', 'idList': ['EUVD-2025-210320']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61027']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51544']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-61028
CVE-2025-61028
An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
NONE
0.00
NONE
2026-06-23 00:00:00+03:00
2026-06-23 16:12:07+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-61028']
['CVE-2025-61028']
d13b545d7b9544d25af309051bf9ae5bff888d8c82bba4b22ba75f6f6f6897ed
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-61028', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61028', 'type': 'cvelist', 'title': 'CVE-2025-61028', 'cvelist': ['CVE-2025-61028'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:39:09', 'modified': '2026-06-23T16:12:07', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:684D1D37-A747-419F-BFD0-FDCC7A5FB870']}, {'type': 'cve', 'idList': ['CVE-2025-61028']}, {'type': 'euvd', 'idList': ['EUVD-2025-210321']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61028']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51545']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-61029
CVE-2025-61029
An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
NONE
0.00
NONE
2026-06-23 00:00:00+03:00
2026-06-23 16:38:50+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-61029']
['CVE-2025-61029']
086e2f66788fa941b2a9e10c971051ae3beb3f5b194da710a7d17072583332c0
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-61029', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61029', 'type': 'cvelist', 'title': 'CVE-2025-61029', 'cvelist': ['CVE-2025-61029'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T17:56:42', 'modified': '2026-06-23T16:38:50', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:A2C21E4F-B91A-4936-94CB-5032AD3F3D9A']}, {'type': 'cve', 'idList': ['CVE-2025-61029']}, {'type': 'euvd', 'idList': ['EUVD-2025-210324']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61029']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51570']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61029']}]}}, 'bulletinFamily': 'cve'}
CVE-2025-66389
CVE-2025-66389
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.
NONE
0.00
NONE
2026-06-22 00:00:00+03:00
2026-06-22 13:38:54+03:00
['https://www.cve.org/CVERecord?id=CVE-2025-66389']
['CVE-2025-66389']
9377522ea971ca9045efba3eeb1ccabc0d71fffe84fd19813562c3e22a7dd3f9
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2025-66389', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-66389', 'type': 'cvelist', 'title': 'CVE-2025-66389', 'cvelist': ['CVE-2025-66389'], 'assigned': '2025-11-28T00:00:00', 'lastseen': '2026-06-22T17:20:56', 'modified': '2026-06-22T13:38:54', 'published': '2026-06-22T00:00:00', 'description': 'GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:D062C4C0-6FDD-475F-B400-00C5BC73499E']}, {'type': 'cve', 'idList': ['CVE-2025-66389']}, {'type': 'euvd', 'idList': ['EUVD-2025-210298']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-66389']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51297']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-66389']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-10521
CVE-2026-10521 Authenticated unintended access to critical program parameters
An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.
HIGH
8.60
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
2026-06-23 07:34:10+03:00
2026-06-23 07:34:10+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-10521']
['CVE-2026-10521']
8f3ea93e5eeeb3e2cec5a088c83f6ecd99b953223bb298ae553270598e4f59b7
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-10521', 'cvss': {'score': 8.6, 'source': 'certvde', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10521', 'type': 'cvelist', 'title': 'CVE-2026-10521 Authenticated unintended access to critical program parameters', 'cvelist': ['CVE-2026-10521'], 'assigned': '2026-06-01T08:47:49', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-23T07:34:10', 'published': '2026-06-23T07:34:10', 'description': 'An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:80A4FB9C-5E22-4BD6-B40C-0010A2E077D8']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10521']}, {'type': 'cve', 'idList': ['CVE-2026-10521']}, {'type': 'euvd', 'idList': ['EUVD-2026-38422']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10521']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51480']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-10561
CVE-2026-10561 Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
CRITICAL
10.00
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
2026-06-22 13:22:07+03:00
2026-06-22 13:22:07+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-10561']
['CVE-2026-10561']
f343c2a8fe163aab613cb8f9c2a404389cb5858bcdbc1c8682b349e00c309f02
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-10561', 'cvss': {'score': 10.0, 'source': 'ibm', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'version': '3.1', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10561', 'type': 'cvelist', 'title': 'CVE-2026-10561 Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection', 'cvelist': ['CVE-2026-10561'], 'assigned': '2026-06-01T15:41:38', 'lastseen': '2026-06-23T18:50:58', 'modified': '2026-06-22T13:22:07', 'published': '2026-06-22T13:22:07', 'description': 'IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:618952DE-56B2-41CA-B0B8-711278BD4702']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10561']}, {'type': 'cve', 'idList': ['CVE-2026-10561']}, {'type': 'euvd', 'idList': ['EUVD-2026-38245']}, {'type': 'ibm', 'idList': ['56013D9C8566ACFFEE8029C83F51DFCEBD6F884B6E5E543D37F9E207D84E86A2']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10561']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51298']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10561']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-10601
CVE-2026-10601 Path Traversal in Tempo and Loki Data Source Plugins — Credential Leakage and Admin Endpoint Access
The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling path traversal. A Viewer-role user can: (1) capture admin-configured datasource credentials (secureJsonData custom headers) by traversing to an attacker-controlled endpoint, (2) invoke state-changing admin endpoints on Tempo (e.g. /flush, /shutdown), and (3) exfiltrate internal service data via Loki's CallResource which returns full HTTP response bodies.
MEDIUM
5.40
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
2026-06-22 13:18:31+03:00
2026-06-22 13:18:31+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-10601']
['CVE-2026-10601']
82d46fd6a7ad05f1e90469a225b5b18d522afb50893fc537c943fbf96ab4f5f1
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-10601', 'cvss': {'score': 5.4, 'source': 'grafana', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10601', 'type': 'cvelist', 'title': 'CVE-2026-10601 Path Traversal in Tempo and Loki Data Source Plugins — Credential Leakage and Admin Endpoint Access', 'cvelist': ['CVE-2026-10601'], 'assigned': '2026-06-02T09:57:26', 'lastseen': '2026-06-22T15:44:33', 'modified': '2026-06-22T13:18:31', 'published': '2026-06-22T13:18:31', 'description': "The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling path traversal. A Viewer-role user can: (1) capture admin-configured datasource credentials (secureJsonData custom headers) by traversing to an attacker-controlled endpoint, (2) invoke state-changing admin endpoints on Tempo (e.g. /flush, /shutdown), and (3) exfiltrate internal service data via Loki's CallResource which returns full HTTP response bodies.", 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-10601']}, {'type': 'attackerkb', 'idList': ['AKB:3797A643-C112-4546-B357-4EE065C21121']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10601']}, {'type': 'cve', 'idList': ['CVE-2026-10601']}, {'type': 'euvd', 'idList': ['EUVD-2026-38242']}, {'type': 'nessus', 'idList': ['UNPATCHED_CVE_2026_10601.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10601']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51299']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2026-10601']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10601']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-10609
CVE-2026-10609 Openshift/cluster-logging-operator: cluster logging operator creates and forwards serviceaccount tokens without verifying clf creator authorization
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.
MEDIUM
6.80
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
2026-06-23 13:26:43+03:00
2026-06-23 13:26:43+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-10609']
['CVE-2026-10609']
60fa6b63b95782a923f7249eab58c8e40ea27d6cf4122727bf73f6830028317b
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-10609', 'cvss': {'score': 6.8, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10609', 'type': 'cvelist', 'title': 'CVE-2026-10609 Openshift/cluster-logging-operator: cluster logging operator creates and forwards serviceaccount tokens without verifying clf creator authorization', 'cvelist': ['CVE-2026-10609'], 'assigned': '2026-06-02T11:48:09', 'lastseen': '2026-06-23T14:02:41', 'modified': '2026-06-23T13:26:43', 'published': '2026-06-23T13:26:43', 'description': 'A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:84A99022-2AAE-4BCB-AD22-84F720E878A6']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10609']}, {'type': 'cve', 'idList': ['CVE-2026-10609']}, {'type': 'euvd', 'idList': ['EUVD-2026-38448']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10609']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51518']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2026-10609']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10609']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-10645
CVE-2026-10645 fs: ext2: Missing structural validation of directory entries can cause out-of-bounds read and zero-progress directory traversal
Zephyr's ext2 directory-entry parser does not fully validate on-disk directory entry structure before copying the entry name and advancing traversal state. In ext2_fetch_direntry() (subsys/fs/ext2/ext2_diskops.c), the code only checks de_name_len <= EXT2_MAX_FILE_NAME and then copies the name with memcpy without validating the structural relationship between de_rec_len, de_name_len, and the directory block boundary (for example that de_rec_len is non-zero, at least the size of the entry header, and that the record fits within the block). Callers such as find_dir_entry() and ext2_get_direntry() (subsys/fs/ext2/ext2_impl.c) then advance traversal using the unvalidated de_rec_len. A crafted ext2 image can therefore cause an out-of-bounds read from the directory block buffer when a malformed entry near the end of a block triggers an oversized name copy, or a zero-progress infinite loop when de_rec_len == 0. The issue is not reached at mount time but later through directory traversal paths such as pathname lookup, stat/open/unlink/rename, and readdir. The primary impact is denial of service and out-of-bounds reads under attacker-controlled ext2 images mounted from untrusted media.
MEDIUM
4.90
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
2026-06-22 23:48:11+03:00
2026-06-22 23:48:11+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-10645']
['CVE-2026-10645']
9931b8a7e72ad83e30c74b1d82ff99eebfc616856ecda8fbaaf529396f5726f9
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-10645', 'cvss': {'score': 4.9, 'source': 'zephyr', 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10645', 'type': 'cvelist', 'title': 'CVE-2026-10645 fs: ext2: Missing structural validation of directory entries can cause out-of-bounds read and zero-progress directory traversal', 'cvelist': ['CVE-2026-10645'], 'assigned': '2026-06-02T15:11:47', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-22T23:48:11', 'published': '2026-06-22T23:48:11', 'description': "Zephyr's ext2 directory-entry parser does not fully validate on-disk directory entry structure before copying the entry name and advancing traversal state. In ext2_fetch_direntry() (subsys/fs/ext2/ext2_diskops.c), the code only checks de_name_len <= EXT2_MAX_FILE_NAME and then copies the name with memcpy without validating the structural relationship between de_rec_len, de_name_len, and the directory block boundary (for example that de_rec_len is non-zero, at least the size of the entry header, and that the record fits within the block). Callers such as find_dir_entry() and ext2_get_direntry() (subsys/fs/ext2/ext2_impl.c) then advance traversal using the unvalidated de_rec_len. A crafted ext2 image can therefore cause an out-of-bounds read from the directory block buffer when a malformed entry near the end of a block triggers an oversized name copy, or a zero-progress infinite loop when de_rec_len == 0. The issue is not reached at mount time but later through directory traversal paths such as pathname lookup, stat/open/unlink/rename, and readdir. The primary impact is denial of service and out-of-bounds reads under attacker-controlled ext2 images mounted from untrusted media.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:410B4A8A-2E8F-4E1F-8C8B-BD2A216AF00E']}, {'type': 'cve', 'idList': ['CVE-2026-10645']}, {'type': 'euvd', 'idList': ['EUVD-2026-38408']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10645']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-10645']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51425']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10645']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-10651
CVE-2026-10651 Bluetooth Classic SDP parser truncation bug in bt_sdp_parse_attribute() leads to reachable assertion and possible out-of-bounds read
A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser. In subsys/bluetooth/host/classic/sdp.c, bt_sdp_parse_attribute() accepts an input buffer once it contains the 1-byte attribute type and 2-byte attribute id, but then unconditionally pulls an additional byte for the value type without verifying that the byte is present. A truncated 3-byte attribute (for example 09 00 09) therefore reaches net_buf_simple_pull() with insufficient remaining length, triggering the __ASSERT_NO_MSG(buf->len >= len) check and a kernel panic in assert-enabled builds (denial of service). In builds where assertions are disabled, parsing may continue past the end of the available buffer, leading to an out-of-bounds read and undefined behavior.
HIGH
7.10
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
2026-06-22 23:54:36+03:00
2026-06-22 23:54:36+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-10651']
['CVE-2026-10651']
3a6fa7da5f3ba0103d8272fcb191af57a8dbdcfee3757689632949bfe12bbc80
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-10651', 'cvss': {'score': 7.1, 'source': 'zephyr', 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10651', 'type': 'cvelist', 'title': 'CVE-2026-10651 Bluetooth Classic SDP parser truncation bug in bt_sdp_parse_attribute() leads to reachable assertion and possible out-of-bounds read', 'cvelist': ['CVE-2026-10651'], 'assigned': '2026-06-02T15:24:24', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-22T23:54:36', 'published': '2026-06-22T23:54:36', 'description': "A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser. In subsys/bluetooth/host/classic/sdp.c, bt_sdp_parse_attribute() accepts an input buffer once it contains the 1-byte attribute type and 2-byte attribute id, but then unconditionally pulls an additional byte for the value type without verifying that the byte is present. A truncated 3-byte attribute (for example 09 00 09) therefore reaches net_buf_simple_pull() with insufficient remaining length, triggering the __ASSERT_NO_MSG(buf->len >= len) check and a kernel panic in assert-enabled builds (denial of service). In builds where assertions are disabled, parsing may continue past the end of the available buffer, leading to an out-of-bounds read and undefined behavior.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:A523E1B0-EDCD-4F27-9F32-04032D408748']}, {'type': 'cve', 'idList': ['CVE-2026-10651']}, {'type': 'euvd', 'idList': ['EUVD-2026-38409']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10651']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-10651']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51426']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10651']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-10658
CVE-2026-10658 Bluetooth Host ISO RX Missing SDU Header Length Validation in bt_iso_recv() Leads to DoS
A missing length validation in the Zephyr Bluetooth Host ISO receive path can be triggered by malformed HCI ISO data. In bt_iso_recv() (subsys/bluetooth/host/iso.c), when processing PB=START/SINGLE fragments, the code pulls a TS SDU header (8 bytes, ts=1) or a non-TS SDU header (4 bytes, ts=0) without first verifying that buf->len contains at least that many bytes. The outer HCI ISO length check in hci_iso() validates payload length consistency but not the minimum inner SDU header size, so a packet with payload length 1 passes hci_iso() and then reaches net_buf_pull_mem(), which asserts buf->len >= len. As a result, malformed ISO traffic deterministically triggers a kernel assert (denial of service) in assert-enabled builds, and in non-assert builds the same path may proceed with an undersized buffer, leading to out-of-bounds read behavior. The issue affects products using the Zephyr Host with CONFIG_BT_ISO_RX enabled, particularly where incoming HCI data can be influenced by a malicious or compromised controller or malformed forwarded ISO traffic.
HIGH
7.10
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
2026-06-22 23:58:47+03:00
2026-06-22 23:58:47+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-10658']
['CVE-2026-10658']
7fdab092e867a55ae9f77b5c7b90a722b19dd0b1bc7fbf50e90afc4fe5e1a2f0
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-10658', 'cvss': {'score': 7.1, 'source': 'zephyr', 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10658', 'type': 'cvelist', 'title': 'CVE-2026-10658 Bluetooth Host ISO RX Missing SDU Header Length Validation in bt_iso_recv() Leads to DoS', 'cvelist': ['CVE-2026-10658'], 'assigned': '2026-06-02T15:24:35', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-22T23:58:47', 'published': '2026-06-22T23:58:47', 'description': 'A missing length validation in the Zephyr Bluetooth Host ISO receive path can be triggered by malformed HCI ISO data. In bt_iso_recv() (subsys/bluetooth/host/iso.c), when processing PB=START/SINGLE fragments, the code pulls a TS SDU header (8 bytes, ts=1) or a non-TS SDU header (4 bytes, ts=0) without first verifying that buf->len contains at least that many bytes. The outer HCI ISO length check in hci_iso() validates payload length consistency but not the minimum inner SDU header size, so a packet with payload length 1 passes hci_iso() and then reaches net_buf_pull_mem(), which asserts buf->len >= len. As a result, malformed ISO traffic deterministically triggers a kernel assert (denial of service) in assert-enabled builds, and in non-assert builds the same path may proceed with an undersized buffer, leading to out-of-bounds read behavior. The issue affects products using the Zephyr Host with CONFIG_BT_ISO_RX enabled, particularly where incoming HCI data can be influenced by a malicious or compromised controller or malformed forwarded ISO traffic.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B0B795A3-2C8C-4ED3-A0D3-215FED5BF494']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10658']}, {'type': 'cve', 'idList': ['CVE-2026-10658']}, {'type': 'euvd', 'idList': ['EUVD-2026-38410']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10658']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-10658']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51427']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10658']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-10711
CVE-2026-10711 RCE in Akınsoft's CafePlus
Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects CafePlus: from 12.05.03 before 12.05.04.
HIGH
8.80
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2026-06-23 12:08:33+03:00
2026-06-23 12:08:33+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-10711']
['CVE-2026-10711']
b8286ba6e28c113f0c7a87061b002670d0b90652a8cd2a21dcf5391f28eee9ec
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-10711', 'cvss': {'score': 8.8, 'source': 'tr-cert', 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10711', 'type': 'cvelist', 'title': "CVE-2026-10711 RCE in Akınsoft's CafePlus", 'cvelist': ['CVE-2026-10711'], 'assigned': '2026-06-02T18:23:11', 'lastseen': '2026-06-23T13:40:43', 'modified': '2026-06-23T12:08:33', 'published': '2026-06-23T12:08:33', 'description': 'Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessing Functionality Not Properly Constrained by ACLs.\n\nThis issue affects CafePlus: from 12.05.03 before 12.05.04.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:92E458C2-DC59-4439-9B88-A6BDC5BCDA0B']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10711']}, {'type': 'cve', 'idList': ['CVE-2026-10711']}, {'type': 'euvd', 'idList': ['EUVD-2026-38426']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10711']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51495']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10711']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12479
CVE-2026-12479 Path Traversal in keras-team/keras
A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method within the Keras 3 model saving and loading library. This vulnerability arises from the improper handling of user-provided layer names, which are used to construct directory paths without sanitizing for parent directory components (`..`). While forward slashes (`/`) are restricted in layer names, directory traversal sequences are not. This allows an attacker to craft a malicious Keras model that, when saved or loaded, can escape the intended temporary working directory and perform unauthorized file system operations, such as creating directories or writing files in arbitrary locations.
MEDIUM
6.10
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
2026-06-22 15:21:19+03:00
2026-06-22 15:21:19+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12479']
['CVE-2026-12479']
c8d216643576e168ce46c6a8ebcad6656dc0827c0fcae930b0f6d10025334892
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12479', 'cvss': {'score': 6.1, 'source': '@huntr_ai', 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L', 'version': '3.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12479', 'type': 'cvelist', 'title': 'CVE-2026-12479 Path Traversal in keras-team/keras', 'cvelist': ['CVE-2026-12479'], 'assigned': '2026-06-17T00:28:44', 'lastseen': '2026-06-22T16:32:44', 'modified': '2026-06-22T15:21:19', 'published': '2026-06-22T15:21:19', 'description': 'A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method within the Keras 3 model saving and loading library. This vulnerability arises from the improper handling of user-provided layer names, which are used to construct directory paths without sanitizing for parent directory components (`..`). While forward slashes (`/`) are restricted in layer names, directory traversal sequences are not. This allows an attacker to craft a malicious Keras model that, when saved or loaded, can escape the intended temporary working directory and perform unauthorized file system operations, such as creating directories or writing files in arbitrary locations.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:88689AE2-5FBA-4B36-A2C1-4B1F331A617D']}, {'type': 'cve', 'idList': ['CVE-2026-12479']}, {'type': 'euvd', 'idList': ['EUVD-2026-38265']}, {'type': 'huntr', 'idList': ['188836B9-12FC-49C7-8DBF-04F60FE33743']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12479']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-12479']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51329']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12479']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12549
CVE-2026-12549 Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
MEDIUM
4.80
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
2026-06-22 13:55:06+03:00
2026-06-22 13:55:06+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12549']
['CVE-2026-12549']
0fe15d89bea64fc03131faec8451892514037344bfcd7495505b1797e6d00709
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12549', 'cvss': {'score': 4.8, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12549', 'type': 'cvelist', 'title': 'CVE-2026-12549 Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver', 'cvelist': ['CVE-2026-12549'], 'assigned': '2026-06-17T18:40:22', 'lastseen': '2026-06-23T14:38:44', 'modified': '2026-06-22T13:55:06', 'published': '2026-06-22T13:55:06', 'description': 'The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:3F015C39-8E5D-460C-9C04-E0E033BE27A5']}, {'type': 'cve', 'idList': ['CVE-2026-12549']}, {'type': 'euvd', 'idList': ['EUVD-2026-38279']}, {'type': 'nessus', 'idList': ['UNPATCHED_CVE_2026_12549.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12549']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-12549']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51330']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12549']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12580
CVE-2026-12580 Digiwin|EasyFlow .NET - Stored Cross-Site Scripting
EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.
MEDIUM
5.40
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
2026-06-22 09:26:04+03:00
2026-06-22 09:26:04+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12580']
['CVE-2026-12580']
419c4d5aa396f71806b20f613efb35c09877e4e0dec25e7cfaf09c31d4fe20f2
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12580', 'cvss': {'score': 5.4, 'source': 'twcert', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12580', 'type': 'cvelist', 'title': 'CVE-2026-12580 Digiwin|EasyFlow .NET - Stored Cross-Site Scripting', 'cvelist': ['CVE-2026-12580'], 'assigned': '2026-06-18T06:51:12', 'lastseen': '2026-06-22T10:32:40', 'modified': '2026-06-22T09:26:04', 'published': '2026-06-22T09:26:04', 'description': "EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:0F303076-B2C0-40A8-A597-5A38A49C507B']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12580']}, {'type': 'cve', 'idList': ['CVE-2026-12580']}, {'type': 'euvd', 'idList': ['EUVD-2026-38222']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12580']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51288']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12580']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12581
CVE-2026-12581 Digiwin|EasyFlow .NET - Session Fixation
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.
HIGH
7.70
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
2026-06-22 09:30:38+03:00
2026-06-22 09:30:38+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12581']
['CVE-2026-12581']
959d19ae1562a763272b10723208351d26d195668a46bd4b5ad6199bafad4932
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12581', 'cvss': {'score': 7.7, 'source': 'twcert', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12581', 'type': 'cvelist', 'title': 'CVE-2026-12581 Digiwin|EasyFlow .NET - Session Fixation', 'cvelist': ['CVE-2026-12581'], 'assigned': '2026-06-18T06:51:13', 'lastseen': '2026-06-22T10:26:40', 'modified': '2026-06-22T09:30:38', 'published': '2026-06-22T09:30:38', 'description': "EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:26D9F7EF-E0F1-42E6-B457-1D72BF655414']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12581']}, {'type': 'cve', 'idList': ['CVE-2026-12581']}, {'type': 'euvd', 'idList': ['EUVD-2026-38223']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12581']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51289']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12581']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12602
CVE-2026-12602 Incorrect permissions in ArubaSign by Aruba
Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\Program Files have excessive permissions for the ‘Everyone’ group. This could allow an unprivileged user to replace the main executable and/or its components with a malicious file, thereby enabling the execution of arbitrary code. In the worst-case scenario, if the malicious code is executed with elevated privileges (such as those of Administrator or SYSTEM), the attacker could escalate privileges and gain full control of the system, compromising both security and data integrity.
HIGH
8.80
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H
2026-06-22 12:34:49+03:00
2026-06-22 12:34:49+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12602']
['CVE-2026-12602']
8783aebc07463a3025b64eb9cc0255c303d57db742de49135f55316dbf44e619
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12602', 'cvss': {'score': 8.8, 'source': 'incibe', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12602', 'type': 'cvelist', 'title': 'CVE-2026-12602 Incorrect permissions in ArubaSign by Aruba', 'cvelist': ['CVE-2026-12602'], 'assigned': '2026-06-18T11:18:05', 'lastseen': '2026-06-22T17:20:54', 'modified': '2026-06-22T12:34:49', 'published': '2026-06-22T12:34:49', 'description': 'Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\\Program Files have excessive permissions for the ‘Everyone’ group. This could allow an unprivileged user to replace the main executable and/or its components with a malicious file, thereby enabling the execution of arbitrary code. In the worst-case scenario, if the malicious code is executed with elevated privileges (such as those of Administrator or SYSTEM), the attacker could escalate privileges and gain full control of the system, compromising both security and data integrity.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:7948B7E9-C6DE-40B4-B63F-FB8B285A6F97']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12602']}, {'type': 'cve', 'idList': ['CVE-2026-12602']}, {'type': 'euvd', 'idList': ['EUVD-2026-38230']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12602']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51300']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12602']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12628
CVE-2026-12628 Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentication code paths, and does not properly validate authentication responses, which may allow an unauthenticated attacker to establish a trusted session and access protected services. This vulnerability affects client components across multiple versions and may allow an attacker to impersonate legitimate clients, potentially leading to unauthorized access to system resources.
CRITICAL
9.10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
2026-06-22 13:43:33+03:00
2026-06-23 18:52:31+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12628']
['CVE-2026-12628']
2895137f6fdccb2066768e7375b470eeee2987444ed692c379a21c724335b205
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12628', 'cvss': {'score': 9.1, 'source': 'ibm', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'version': '3.1', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12628', 'type': 'cvelist', 'title': 'CVE-2026-12628 Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system', 'cvelist': ['CVE-2026-12628'], 'assigned': '2026-06-18T15:18:16', 'lastseen': '2026-06-23T19:40:19', 'modified': '2026-06-23T18:52:31', 'published': '2026-06-22T13:43:33', 'description': 'IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentication code paths, and does not properly validate authentication responses, which may allow an unauthenticated attacker to establish a trusted session and access protected services. This vulnerability affects client components across multiple versions and may allow an attacker to impersonate legitimate clients, potentially leading to unauthorized access to system resources.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:3672989E-24CF-446D-BC88-6943CD3AC7AD']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12628']}, {'type': 'cve', 'idList': ['CVE-2026-12628']}, {'type': 'euvd', 'idList': ['EUVD-2026-38277']}, {'type': 'ibm', 'idList': ['1AF0FD585992D2BAD69C0E0E47B05C79E3D356B2A735778FDA0073F2B6A29B5B']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12628']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51331']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12628']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12725
CVE-2026-12725 Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service.
MEDIUM
5.90
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
2026-06-22 13:55:05+03:00
2026-06-22 14:12:03+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12725']
['CVE-2026-12725']
2e587d27eca4fdbac0588f1dc9281c6e8901b73c0cb9bf714d514931a4f226b4
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12725', 'cvss': {'score': 5.9, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12725', 'type': 'cvelist', 'title': 'CVE-2026-12725 Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies', 'cvelist': ['CVE-2026-12725'], 'assigned': '2026-06-19T14:44:05', 'lastseen': '2026-06-22T18:48:30', 'modified': '2026-06-22T14:12:03', 'published': '2026-06-22T13:55:05', 'description': 'A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and\nquery logging are both enabled, logging of DS or DNSKEY replies containing\nunsupported algorithm or digest types can cause dnsmasq to write past the end\nof an internal logging buffer. A remote attacker able to supply such a DNS\nresponse may crash the dnsmasq process, resulting in denial of service.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:86457FB5-C1E8-4414-9FC4-D0F827ABABE9']}, {'type': 'cve', 'idList': ['CVE-2026-12725']}, {'type': 'euvd', 'idList': ['EUVD-2026-38278']}, {'type': 'nessus', 'idList': ['UNPATCHED_CVE_2026_12725.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12725']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-12725']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51332']}, {'type': 'susecve', 'idList': ['SUSECVE:CVE-2026-12725']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12725']}]}}, 'bulletinFamily': 'cve'}
CVE-2021-47987
CVE-2021-47987 Parse Server - Arbitrary Code Execution via Malicious Version Tags
Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based dependency referencing one of the affected tags (for example, parse-server#4.9.3). The code behind the tags was not reviewed or approved, and although no malicious code was identified, the introduction of security vulnerabilities could not be ruled out.
HIGH
7.70
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
2026-06-25 21:41:02+03:00
2026-06-25 21:41:02+03:00
['https://www.cve.org/CVERecord?id=CVE-2021-47987']
['CVE-2021-47987']
ce9042b542d091b363b8f3787a0b9017bde6a53b5545fdff0f4edea51e7c4b6e
2026-06-26 15:06:33.367280+03:00
2026-06-26 15:06:33.367280+03:00
{'id': 'CVELIST:CVE-2021-47987', 'cvss': {'score': 7.7, 'source': 'vulncheck', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2021-47987', 'type': 'cvelist', 'title': 'CVE-2021-47987 Parse Server - Arbitrary Code Execution via Malicious Version Tags', 'cvelist': ['CVE-2021-47987'], 'assigned': '2026-06-21T02:08:33', 'lastseen': '2026-06-25T21:59:22', 'modified': '2026-06-25T21:41:02', 'published': '2026-06-25T21:41:02', 'description': 'Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based dependency referencing one of the affected tags (for example, parse-server#4.9.3). The code behind the tags was not reviewed or approved, and although no malicious code was identified, the introduction of security vulnerabilities could not be ruled out.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:68B60196-76BF-4B2A-A08C-7AA32F2CF5FA']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2021-47987']}, {'type': 'cve', 'idList': ['CVE-2021-47987']}, {'type': 'euvd', 'idList': ['EUVD-2021-34853']}, {'type': 'nvd', 'idList': ['NVD:CVE-2021-47987']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52608']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12862
CVE-2026-12862 XLSX formula injection in exports
Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.
MEDIUM
5.10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N
2026-06-22 08:26:10+03:00
2026-06-22 08:26:10+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12862']
['CVE-2026-12862']
0608521c4ad29a5282f58d6e0cd16ccd45751d75223110a502ec55d9e42bc5f0
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12862', 'cvss': {'score': 5.1, 'source': 'rami.io', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12862', 'type': 'cvelist', 'title': 'CVE-2026-12862 XLSX formula injection in exports', 'cvelist': ['CVE-2026-12862'], 'assigned': '2026-06-22T08:16:55', 'lastseen': '2026-06-22T13:45:14', 'modified': '2026-06-22T08:26:10', 'published': '2026-06-22T08:26:10', 'description': 'Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:6D57D0CE-A977-4AC4-81A2-ABF9326106A1']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12862']}, {'type': 'cve', 'idList': ['CVE-2026-12862']}, {'type': 'euvd', 'idList': ['EUVD-2026-38220']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12862']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51290']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12862']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12863
CVE-2026-12863 Open redirect
An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.
MEDIUM
5.10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N
2026-06-22 08:41:33+03:00
2026-06-23 11:54:38+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12863']
['CVE-2026-12863']
e9491d9e1ea59a03fbb0cb1352e4c5646e04ea32854023789a448bc7d3f990f9
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12863', 'cvss': {'score': 5.1, 'source': 'rami.io', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12863', 'type': 'cvelist', 'title': 'CVE-2026-12863 Open redirect', 'cvelist': ['CVE-2026-12863'], 'assigned': '2026-06-22T08:17:20', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-23T11:54:38', 'published': '2026-06-22T08:41:33', 'description': "An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:C117D061-EC7C-41E4-9F12-83A3BD2F32E4']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12863']}, {'type': 'cve', 'idList': ['CVE-2026-12863']}, {'type': 'euvd', 'idList': ['EUVD-2026-38221']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12863']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51291']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12863']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12866
CVE-2026-12866
All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.
CRITICAL
9.80
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2026-06-23 05:00:00+03:00
2026-06-23 05:00:00+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12866']
['CVE-2026-12866']
9851d5a0289b19473dedbbe173d234b7175af4f2d6388f507976d56af5d1d05b
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12866', 'cvss': {'score': 9.8, 'source': 'snyk', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'version': '3.1', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12866', 'type': 'cvelist', 'title': 'CVE-2026-12866', 'cvelist': ['CVE-2026-12866'], 'assigned': '2026-06-22T08:22:34', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-23T05:00:00', 'published': '2026-06-23T05:00:00', 'description': "All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B9AD2EB5-7004-4EF8-B473-06E59884E4C8']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12866']}, {'type': 'cve', 'idList': ['CVE-2026-12866']}, {'type': 'euvd', 'idList': ['EUVD-2026-38415']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12866']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51474']}, {'type': 'snyk', 'idList': ['SNYK:JS-EXPREVAL-15054690']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12866']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12888
CVE-2026-12888 HTML injection in the Canarytoken Google Chat notification
An HTML injection vulnerability exists in the Google Chat webhook notification  sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content including links. This issue affects Canarytokens: from Docker tag sha-4aef1db90 before sha-8ab4dccd, from Git commit 4aef1db90 before 8ab4dccd.
MEDIUM
5.10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/SC:N/VI:N/SI:L/VA:N/SA:N/E:P/AU:N/U:Green/RE:L
2026-06-22 13:05:53+03:00
2026-06-22 13:05:53+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12888']
['CVE-2026-12888']
387a6a537f3ba7dfe28d9f27e5172c85e53f97bc43146bc52df69578a3fa8f34
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12888', 'cvss': {'score': 5.1, 'source': 'thinkstappliedresearch', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/SC:N/VI:N/SI:L/VA:N/SA:N/E:P/AU:N/U:Green/RE:L', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12888', 'type': 'cvelist', 'title': 'CVE-2026-12888 HTML injection in the Canarytoken Google Chat notification', 'cvelist': ['CVE-2026-12888'], 'assigned': '2026-06-22T10:56:11', 'lastseen': '2026-06-22T15:44:28', 'modified': '2026-06-22T13:05:53', 'published': '2026-06-22T13:05:53', 'description': 'An HTML injection vulnerability exists in the Google Chat webhook notification\xa0 sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content including links.\n\n\nThis issue affects Canarytokens: from Docker tag sha-4aef1db90 before sha-8ab4dccd, from Git commit 4aef1db90 before 8ab4dccd.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:D54A113B-EDEF-40AD-8021-D343C8F8ADBE']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12888']}, {'type': 'cve', 'idList': ['CVE-2026-12888']}, {'type': 'euvd', 'idList': ['EUVD-2026-38240']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12888']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51301']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12888']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12891
CVE-2026-12891 Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser
A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream that, when processed by a GStreamer-based application, could leak limited memory contents through video metadata, potentially exposing sensitive information from the application's address space.
MEDIUM
4.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
2026-06-23 19:53:21+03:00
2026-06-23 19:53:21+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12891']
['CVE-2026-12891']
215c9cb672a8dcf7c08d60a33ed5c4fbc4f7fdc2044a1a22622957286bff7fa5
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12891', 'cvss': {'score': 4.3, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12891', 'type': 'cvelist', 'title': 'CVE-2026-12891 Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser', 'cvelist': ['CVE-2026-12891'], 'assigned': '2026-06-22T11:31:30', 'lastseen': '2026-06-23T20:20:10', 'modified': '2026-06-23T19:53:21', 'published': '2026-06-23T19:53:21', 'description': "A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream that, when processed by a GStreamer-based application, could leak limited memory contents through video metadata, potentially exposing sensitive information from the application's address space.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F57D6483-B818-4FAA-B2D2-3980B8457F9D']}, {'type': 'cve', 'idList': ['CVE-2026-12891']}, {'type': 'euvd', 'idList': ['EUVD-2026-38606']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12891']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51589']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2026-12891']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12892
CVE-2026-12892 Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser
A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.
MEDIUM
4.40
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
2026-06-23 19:53:23+03:00
2026-06-23 19:53:23+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12892']
['CVE-2026-12892']
65975a0dd3d870cfd59a94958dbac8ad16cb911a27ca274fe63e027a365057e8
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12892', 'cvss': {'score': 4.4, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12892', 'type': 'cvelist', 'title': 'CVE-2026-12892 Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser', 'cvelist': ['CVE-2026-12892'], 'assigned': '2026-06-22T11:32:29', 'lastseen': '2026-06-23T20:20:10', 'modified': '2026-06-23T19:53:23', 'published': '2026-06-23T19:53:23', 'description': "A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:69D839D5-CC5C-4DAF-AFE4-BCB9D2D99161']}, {'type': 'cve', 'idList': ['CVE-2026-12892']}, {'type': 'euvd', 'idList': ['EUVD-2026-38607']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12892']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51590']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2026-12892']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12957
CVE-2026-12957 Arbitrary Code Execution in Language Servers for AWS
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted. To remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher.
HIGH
8.50
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
2026-06-23 16:02:53+03:00
2026-06-23 17:37:44+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12957']
['CVE-2026-12957']
da868c84186713cc8d2e158280f527489bb2b6defd747c30c2c293785910daf5
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12957', 'cvss': {'score': 8.5, 'source': 'amzn', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12957', 'type': 'cvelist', 'title': 'CVE-2026-12957 Arbitrary Code Execution in Language Servers for AWS', 'cvelist': ['CVE-2026-12957'], 'assigned': '2026-06-23T01:55:35', 'lastseen': '2026-06-23T18:08:57', 'modified': '2026-06-23T17:37:44', 'published': '2026-06-23T16:02:53', 'description': 'Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.\n\n\n\nTo remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:0FA62E27-2ECB-48A9-AE2A-DE377EBE1437']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12957']}, {'type': 'cve', 'idList': ['CVE-2026-12957']}, {'type': 'euvd', 'idList': ['EUVD-2026-38488']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12957']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51547']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12957']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12958
CVE-2026-12958 Arbitrary file write in Language Servers for AWS
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate this issue, users should upgrade to version 1.69.0 or higher.
HIGH
8.50
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
2026-06-23 16:03:01+03:00
2026-06-23 17:38:05+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12958']
['CVE-2026-12958']
fe5584d45ce889c92f4e78fe0c5227429027fbb47250183658c4adc96e09f177
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12958', 'cvss': {'score': 8.5, 'source': 'amzn', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12958', 'type': 'cvelist', 'title': 'CVE-2026-12958 Arbitrary file write in Language Servers for AWS', 'cvelist': ['CVE-2026-12958'], 'assigned': '2026-06-23T01:55:37', 'lastseen': '2026-06-23T18:08:57', 'modified': '2026-06-23T17:38:05', 'published': '2026-06-23T16:03:01', 'description': 'Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary.\n\n\n\nTo remediate this issue, users should upgrade to version 1.69.0 or higher.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:1EAAA15A-21DD-4C13-A7DD-0642AFF998BE']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12958']}, {'type': 'cve', 'idList': ['CVE-2026-12958']}, {'type': 'euvd', 'idList': ['EUVD-2026-38489']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12958']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51548']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12958']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12969
CVE-2026-12969 Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation
An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions.
MEDIUM
5.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
2026-06-23 13:28:56+03:00
2026-06-23 13:28:56+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12969']
['CVE-2026-12969']
32e58aae6ae9c79bda7d6107668fd399914427342df890efcad885c2e5687b58
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-12969', 'cvss': {'score': 5.3, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12969', 'type': 'cvelist', 'title': 'CVE-2026-12969 Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation', 'cvelist': ['CVE-2026-12969'], 'assigned': '2026-06-23T09:25:06', 'lastseen': '2026-06-23T15:52:49', 'modified': '2026-06-23T13:28:56', 'published': '2026-06-23T13:28:56', 'description': "An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:7B02CA65-C1E4-4A75-B0A3-86E4FCA76D45']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12969']}, {'type': 'cve', 'idList': ['CVE-2026-12969']}, {'type': 'euvd', 'idList': ['EUVD-2026-38449']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12969']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51520']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12969']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-13007
CVE-2026-13007 Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.
HIGH
8.70
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:N/SI:L/VA:N/SA:N
2026-06-23 15:59:50+03:00
2026-06-23 15:59:50+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-13007']
['CVE-2026-13007']
138072f4a8a75ed33292d935fc06cfa24e2eb7f8da8fd09b4cb13c8ef5e1bfa9
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-13007', 'cvss': {'score': 8.7, 'source': 'tenable', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:N/SI:L/VA:N/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-13007', 'type': 'cvelist', 'title': 'CVE-2026-13007 Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure', 'cvelist': ['CVE-2026-13007'], 'assigned': '2026-06-23T14:57:21', 'lastseen': '2026-06-23T18:08:57', 'modified': '2026-06-23T15:59:50', 'published': '2026-06-23T15:59:50', 'description': 'Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:45773FCF-F8DF-49F7-BA11-CC99F75ED6C3']}, {'type': 'cve', 'idList': ['CVE-2026-13007']}, {'type': 'euvd', 'idList': ['EUVD-2026-38487']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-13007']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51549']}, {'type': 'tenable', 'idList': ['TENABLE:62B57783F3E5F5A03959DD4C1BB5FC9A']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-13007']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-10097
CVE-2026-10097 ML-KEM-1024 x64 AVX2 implicit rejection failure breaks IND-CCA2 security
ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from the implicit-rejection behavior required by the standard. The AVX2 constant-time ciphertext comparison used during decapsulation never compared the final 32-byte block of the 1568-byte ML-KEM-1024 ciphertext, so a ciphertext manipulated only in those final bytes would compare as equal and decapsulation returned the real shared secret instead of performing the required implicit rejection.
MEDIUM
6.30
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/SC:N/VI:L/SI:N/VA:N/SA:N
2026-06-25 19:59:30+03:00
2026-06-25 19:59:30+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-10097']
['CVE-2026-10097']
532b814996297006e8b13cd5fbaac16765121b99a8f1254042b4f9f756faeb0d
2026-06-26 15:06:33.367280+03:00
2026-06-26 15:06:33.367280+03:00
{'id': 'CVELIST:CVE-2026-10097', 'cvss': {'score': 6.3, 'source': 'wolfssl', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/SC:N/VI:L/SI:N/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10097', 'type': 'cvelist', 'title': 'CVE-2026-10097 ML-KEM-1024 x64 AVX2 implicit rejection failure breaks IND-CCA2 security', 'cvelist': ['CVE-2026-10097'], 'assigned': '2026-05-29T15:01:16', 'lastseen': '2026-06-25T20:22:25', 'modified': '2026-06-25T19:59:30', 'published': '2026-06-25T19:59:30', 'description': 'ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from the implicit-rejection behavior required by the standard. The AVX2 constant-time ciphertext comparison used during decapsulation never compared the final 32-byte block of the 1568-byte ML-KEM-1024 ciphertext, so a ciphertext manipulated only in those final bytes would compare as equal and decapsulation returned the real shared secret instead of performing the required implicit rejection.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:815FDAD5-DED6-4D76-BFE8-56B87A6337C8']}, {'type': 'cve', 'idList': ['CVE-2026-10097']}, {'type': 'euvd', 'idList': ['EUVD-2026-39553']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10097']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52560']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-28381
CVE-2026-28381 Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.
CRITICAL
9.60
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
2026-06-22 13:20:29+03:00
2026-06-22 13:20:29+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-28381']
['CVE-2026-28381']
7bacb97641385f1ef587d971857b854658c03aa31a7a115fa20d24412cda9b55
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-28381', 'cvss': {'score': 9.6, 'source': 'grafana', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N', 'version': '3.1', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-28381', 'type': 'cvelist', 'title': 'CVE-2026-28381 Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT', 'cvelist': ['CVE-2026-28381'], 'assigned': '2026-02-27T07:16:12', 'lastseen': '2026-06-22T15:44:25', 'modified': '2026-06-22T13:20:29', 'published': '2026-06-22T13:20:29', 'description': 'The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:40CDBF9D-F93F-45D5-B231-40359370B5E9']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-28381']}, {'type': 'cve', 'idList': ['CVE-2026-28381']}, {'type': 'euvd', 'idList': ['EUVD-2026-38244']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-28381']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51302']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-28381']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-33760
CVE-2026-33760 Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages, sessions, build artifacts, and LLM transaction logs — without verifying that the authenticated requester owns the targeted resource. Any authenticated user can read, modify, rename, or permanently delete another user's data by supplying the target's resource ID or flow_id. This is a classic IDOR/BOLA vulnerability. Notably, the same source file (monitor.py) contains one correctly-implemented endpoint that uses an ownership check, demonstrating the correct pattern was known but inconsistently applied. This vulnerability is fixed in 1.9.0.
HIGH
8.80
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2026-06-23 16:30:16+03:00
2026-06-23 16:30:16+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-33760']
['CVE-2026-33760']
8cee75751706f1a80dc78e1b72f002e6622fb9e343adc4d81243d7e4efbed147
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-33760', 'cvss': {'score': 8.8, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-33760', 'type': 'cvelist', 'title': 'CVE-2026-33760 Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints', 'cvelist': ['CVE-2026-33760'], 'assigned': '2026-03-23T18:30:14', 'lastseen': '2026-06-23T16:38:56', 'modified': '2026-06-23T16:30:16', 'published': '2026-06-23T16:30:16', 'description': "Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages, sessions, build artifacts, and LLM transaction logs — without verifying that the authenticated requester owns the targeted resource. Any authenticated user can read, modify, rename, or permanently delete another user's data by supplying the target's resource ID or flow_id. This is a classic IDOR/BOLA vulnerability. Notably, the same source file (monitor.py) contains one correctly-implemented endpoint that uses an ownership check, demonstrating the correct pattern was known but inconsistently applied. This vulnerability is fixed in 1.9.0.", 'enchantments': {'dependencies': {'references': [{'type': 'circl', 'idList': ['CIRCL:CVE-2026-33760']}, {'type': 'cve', 'idList': ['CVE-2026-33760']}, {'type': 'euvd', 'idList': ['EUVD-2026-38519']}, {'type': 'github', 'idList': ['GHSA-9C59-2MVC-VFR8']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-33760']}, {'type': 'osv', 'idList': ['OSV:GHSA-9C59-2MVC-VFR8']}, {'type': 'ptsecurity', 'idList': ['PT-2026-50139']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-34912
CVE-2026-34912
A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account.
MEDIUM
4.30
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
2026-06-23 16:14:38+03:00
2026-06-23 16:14:38+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-34912']
['CVE-2026-34912']
4cf886cc31c9f1089edb7db297aef445c5dc2a335b39a58a978f284ae82071f6
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-34912', 'cvss': {'score': 4.3, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N', 'version': '3.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34912', 'type': 'cvelist', 'title': 'CVE-2026-34912', 'cvelist': ['CVE-2026-34912'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T18:08:57', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34912']}, {'type': 'euvd', 'idList': ['EUVD-2026-38501']}, {'type': 'hackerone', 'idList': ['H1:3650504']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34912']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51550']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34912']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-34913
CVE-2026-34913
A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that campaigns can only be linked to trackers owned by the same advertiser.
MEDIUM
4.30
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
2026-06-23 16:14:38+03:00
2026-06-23 16:14:38+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-34913']
['CVE-2026-34913']
1cacb4b136300ef694439293ae50a1a5dfabb5beb725860b161b3f72e89f28b1
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-34913', 'cvss': {'score': 4.3, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N', 'version': '3.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34913', 'type': 'cvelist', 'title': 'CVE-2026-34913', 'cvelist': ['CVE-2026-34913'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T17:26:52', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that campaigns can only be linked to trackers owned by the same advertiser.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34913']}, {'type': 'euvd', 'idList': ['EUVD-2026-38510']}, {'type': 'hackerone', 'idList': ['H1:3650582']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34913']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51551']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34913']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-10098
CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation status of a different certificate. The lookup compared serial-number bytes without first requiring the two serial numbers to be of equal length, so a SingleResponse for one certificate (same issuer) whose serial is a prefix of the target's serial would match, returning the wrong certificate's status. The fix requires the serial lengths to be equal before comparing the serial bytes.
MEDIUM
6.30
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:N/VA:N/SA:N
2026-06-25 21:16:45+03:00
2026-06-25 21:16:45+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-10098']
['CVE-2026-10098']
9ae072931d8fad30616ce956124bea5f449835323d3e7262596e8df1378cbb77
2026-06-26 15:06:33.367280+03:00
2026-06-26 15:06:33.367280+03:00
{'id': 'CVELIST:CVE-2026-10098', 'cvss': {'score': 6.3, 'source': 'wolfssl', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:N/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10098', 'type': 'cvelist', 'title': 'CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status', 'cvelist': ['CVE-2026-10098'], 'assigned': '2026-05-29T15:03:08', 'lastseen': '2026-06-26T11:02:40', 'modified': '2026-06-25T21:16:45', 'published': '2026-06-25T21:16:45', 'description': "OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation status of a different certificate. The lookup compared serial-number bytes without first requiring the two serial numbers to be of equal length, so a SingleResponse for one certificate (same issuer) whose serial is a prefix of the target's serial would match, returning the wrong certificate's status. The fix requires the serial lengths to be equal before comparing the serial bytes.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B05531BB-61EB-4917-A3D7-39EA09236C19']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10098']}, {'type': 'cve', 'idList': ['CVE-2026-10098']}, {'type': 'euvd', 'idList': ['EUVD-2026-39578']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10098']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52590']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10098']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-34914
CVE-2026-34914
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.
HIGH
8.30
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
2026-06-23 16:14:38+03:00
2026-06-23 16:14:38+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-34914']
['CVE-2026-34914']
de9a3ee58517c95597f4595009b02f7896291955b5bf8e1656f7dd442d15d6b2
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-34914', 'cvss': {'score': 8.3, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H', 'version': '3.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34914', 'type': 'cvelist', 'title': 'CVE-2026-34914', 'cvelist': ['CVE-2026-34914'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T17:32:54', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34914']}, {'type': 'euvd', 'idList': ['EUVD-2026-38506']}, {'type': 'hackerone', 'idList': ['H1:3653196']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34914']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51552']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34914']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-34915
CVE-2026-34915
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.
MEDIUM
6.10
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
2026-06-23 16:14:38+03:00
2026-06-23 16:14:38+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-34915']
['CVE-2026-34915']
9c134c3c4305adda6582738e8492e4d56b2467d87738ced5b64ba1f53a4ae5db
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-34915', 'cvss': {'score': 6.1, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'version': '3.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34915', 'type': 'cvelist', 'title': 'CVE-2026-34915', 'cvelist': ['CVE-2026-34915'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T18:08:56', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34915']}, {'type': 'euvd', 'idList': ['EUVD-2026-38499']}, {'type': 'hackerone', 'idList': ['H1:3653316']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34915']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51553']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34915']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-34916
CVE-2026-34916
A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during banner delivery. Input sanitisation has been improved to ensure that the parameter is properly validated.
HIGH
8.80
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2026-06-23 16:14:38+03:00
2026-06-23 16:14:38+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-34916']
['CVE-2026-34916']
f8816f1a808fdb29d07b0bc684cc32dce608bdd23a0efc20af1404e254de6b5d
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-34916', 'cvss': {'score': 8.8, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'version': '3.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34916', 'type': 'cvelist', 'title': 'CVE-2026-34916', 'cvelist': ['CVE-2026-34916'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T17:26:52', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during banner delivery. Input sanitisation has been improved to ensure that the parameter is properly validated.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34916']}, {'type': 'euvd', 'idList': ['EUVD-2026-38507']}, {'type': 'hackerone', 'idList': ['H1:3656781']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34916']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51554']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34916']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-34917
CVE-2026-34917
Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. The session context (web/API) is now recorded along with other session data, preventing session IDs from being used interchangeably.
MEDIUM
4.30
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
2026-06-23 16:14:38+03:00
2026-06-23 16:14:38+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-34917']
['CVE-2026-34917']
48b14897e38546757908a5fba67b4bc05b6e34cd632abb4d742fd1430a637369
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-34917', 'cvss': {'score': 4.3, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'version': '3.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34917', 'type': 'cvelist', 'title': 'CVE-2026-34917', 'cvelist': ['CVE-2026-34917'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T17:26:52', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. The session context (web/API) is now recorded along with other session data, preventing session IDs from being used interchangeably.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34917']}, {'type': 'euvd', 'idList': ['EUVD-2026-38502', 'EUVD-2026-38509']}, {'type': 'hackerone', 'idList': ['H1:3672641']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34917']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51555']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34917']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-39904
CVE-2026-39904 Gophish 0.12.1 Denial of Service via Office Document Upload
Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP archives and calls ioutil.ReadAll() on each contained file entry without enforcing size restrictions on uncompressed content, allowing a zip bomb payload to expand to several gigabytes in memory and cause the process to be terminated by the operating system.
HIGH
7.10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N
2026-06-22 20:11:14+03:00
2026-06-22 20:11:14+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-39904']
['CVE-2026-39904']
a28a9e22303a227fa892683fd6d235d352abfac19bf71542fbf75908a5fca179
2026-06-24 06:24:34.230611+03:00
2026-06-24 06:24:34.230611+03:00
{'id': 'CVELIST:CVE-2026-39904', 'cvss': {'score': 7.1, 'source': 'vulncheck', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-39904', 'type': 'cvelist', 'title': 'CVE-2026-39904 Gophish 0.12.1 Denial of Service via Office Document Upload', 'cvelist': ['CVE-2026-39904'], 'assigned': '2026-04-07T20:57:06', 'lastseen': '2026-06-23T14:38:43', 'modified': '2026-06-22T20:11:14', 'published': '2026-06-22T20:11:14', 'description': 'Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP archives and calls ioutil.ReadAll() on each contained file entry without enforcing size restrictions on uncompressed content, allowing a zip bomb payload to expand to several gigabytes in memory and cause the process to be terminated by the operating system.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:3FB4157A-6FBF-41EB-8BBA-631996E7D618']}, {'type': 'cve', 'idList': ['CVE-2026-39904']}, {'type': 'euvd', 'idList': ['EUVD-2026-38351']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-39904']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51379']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-39904']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-11310
CVE-2026-11310 X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring
X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra (OPENSSL_EXTRA) and whose application validates certificates by calling X509_verify_cert() with caller-supplied untrusted intermediate certificates; for those users it is critical, otherwise the library is unaffected. In particular, native wolfSSL TLS/DTLS usage is not impacted. wolfSSL's X509_verify_cert() temporarily loads each caller-supplied untrusted intermediate into the certificate manager but failed to drop them before the trusted-store check, so an untrusted intermediate could anchor the path itself. An attacker can present a chain that never reaches a configured trust anchor and have it accepted, resulting in acceptance of an attacker-controlled certificate. This is certificate verification independent of TLS (e.g. S/MIME/CMS, code/firmware signing, JWT/JWS x5c), is not specific to any key type or algorithm, and a single untrusted intermediate suffices. The default wolfSSL TLS handshake (WOLFSSL_VERIFY_PEER) is not affected; only TLS applications doing manual or deferred peer verification through this API are, which also requires --enable-sessioncerts.
HIGH
8.70
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:H/SI:N/VA:N/SA:N
2026-06-25 19:38:19+03:00
2026-06-25 19:38:19+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-11310']
['CVE-2026-11310']
d95d10df5f91008a9cce37dffd6fd78043ad25ecc2a15f3f34dccb17408f2518
2026-06-26 15:06:33.367280+03:00
2026-06-26 15:06:33.367280+03:00
{'id': 'CVELIST:CVE-2026-11310', 'cvss': {'score': 8.7, 'source': 'wolfssl', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:H/SI:N/VA:N/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-11310', 'type': 'cvelist', 'title': 'CVE-2026-11310 X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring', 'cvelist': ['CVE-2026-11310'], 'assigned': '2026-06-04T17:58:49', 'lastseen': '2026-06-25T19:56:47', 'modified': '2026-06-25T19:38:19', 'published': '2026-06-25T19:38:19', 'description': "X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra (OPENSSL_EXTRA) and whose application validates certificates by calling X509_verify_cert() with caller-supplied untrusted intermediate certificates; for those users it is critical, otherwise the library is unaffected. In particular, native wolfSSL TLS/DTLS usage is not impacted. wolfSSL's X509_verify_cert() temporarily loads each caller-supplied untrusted intermediate into the certificate manager but failed to drop them before the trusted-store check, so an untrusted intermediate could anchor the path itself. An attacker can present a chain that never reaches a configured trust anchor and have it accepted, resulting in acceptance of an attacker-controlled certificate. This is certificate verification independent of TLS (e.g. S/MIME/CMS, code/firmware signing, JWT/JWS x5c), is not specific to any key type or algorithm, and a single untrusted intermediate suffices. The default wolfSSL TLS handshake (WOLFSSL_VERIFY_PEER) is not affected; only TLS applications doing manual or deferred peer verification through this API are, which also requires --enable-sessioncerts.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:3FB961E1-EDA1-4A2C-9C5A-114FDD091A90']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-11310']}, {'type': 'cve', 'idList': ['CVE-2026-11310']}, {'type': 'euvd', 'idList': ['EUVD-2026-39548']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-11310']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52563']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-12340
CVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation
Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Identifier computation reads the trailing 65 bytes of the public key without checking that the key is at least that long. A public key shorter than 65 bytes results in an out-of-bounds heap read, leading to a potential crash (denial of service); there is no out-of-bounds write. Note this only affects builds with SM2 support (--enable-sm2 or --enable-all).
MEDIUM
6.30
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N
2026-06-25 19:36:21+03:00
2026-06-25 19:36:21+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-12340']
['CVE-2026-12340']
fa24bf8a94b921b18c54b9cb49dd3ea5df8c5131ff4273abcaa9a703eca91c4a
2026-06-26 15:06:33.367280+03:00
2026-06-26 15:06:33.367280+03:00
{'id': 'CVELIST:CVE-2026-12340', 'cvss': {'score': 6.3, 'source': 'wolfssl', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12340', 'type': 'cvelist', 'title': 'CVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation', 'cvelist': ['CVE-2026-12340'], 'assigned': '2026-06-15T16:30:26', 'lastseen': '2026-06-25T19:56:47', 'modified': '2026-06-25T19:36:21', 'published': '2026-06-25T19:36:21', 'description': 'Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Identifier computation reads the trailing 65 bytes of the public key without checking that the key is at least that long. A public key shorter than 65 bytes results in an out-of-bounds heap read, leading to a potential crash (denial of service); there is no out-of-bounds write. Note this only affects builds with SM2 support (--enable-sm2 or --enable-all).', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:142B8861-742B-46E4-86A9-F447AC86A168']}, {'type': 'cve', 'idList': ['CVE-2026-12340']}, {'type': 'euvd', 'idList': ['EUVD-2026-39547']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12340']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52564']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-2053
CVE-2026-2053 Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from external networks.
HIGH
8.30
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
2026-06-26 07:26:15+03:00
2026-06-26 07:26:15+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-2053']
['CVE-2026-2053']
4537d2dc6ed91ea96c6052ae27a47d4d892a27b73ad020eac98bff49d7b5c778
2026-06-26 15:06:33.367280+03:00
2026-06-26 15:06:33.367280+03:00
{'id': 'CVELIST:CVE-2026-2053', 'cvss': {'score': 8.3, 'source': 'wso2', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-2053', 'type': 'cvelist', 'title': 'CVE-2026-2053 Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager', 'cvelist': ['CVE-2026-2053'], 'assigned': '2026-02-06T06:12:48', 'lastseen': '2026-06-26T07:39:38', 'modified': '2026-06-26T07:26:15', 'published': '2026-06-26T07:26:15', 'description': "The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests.\n\nSuccessful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from external networks.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:75CEFD01-AC57-4CD7-A102-51541407168F']}, {'type': 'cve', 'idList': ['CVE-2026-2053']}, {'type': 'euvd', 'idList': ['EUVD-2026-39638']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-2053']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52667']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-2299
CVE-2026-2299 Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint
The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.
MEDIUM
4.20
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
2026-06-25 18:55:11+03:00
2026-06-25 18:55:11+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-2299']
['CVE-2026-2299']
44ecdfa260db2dc82a332cdd7b06485590531b4854e0e58e29074ee3b7a4b919
2026-06-26 15:06:33.367280+03:00
2026-06-26 15:06:33.367280+03:00
{'id': 'CVELIST:CVE-2026-2299', 'cvss': {'score': 4.2, 'source': 'mattermost', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-2299', 'type': 'cvelist', 'title': 'CVE-2026-2299 Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint', 'cvelist': ['CVE-2026-2299'], 'assigned': '2026-02-10T16:46:56', 'lastseen': '2026-06-25T19:56:47', 'modified': '2026-06-25T18:55:11', 'published': '2026-06-25T18:55:11', 'description': 'The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:363C9B40-C228-41DB-9A99-7E2DA1507D8A']}, {'type': 'cve', 'idList': ['CVE-2026-2299']}, {'type': 'euvd', 'idList': ['EUVD-2026-39540']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-2299']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52566']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-40080
CVE-2026-40080 Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than a host check at str_contains($referer, CACTI_PATH_URL). When the user's login_opts == '1' (redirect to referer after login), the function used $_SERVER['HTTP_REFERER'] directly. An attacker could craft a referer such as https://evil.com/cacti/. Where CACTI_PATH_URL is /cacti/, the substring matches and the user is redirected to evil.com after login. The pre-existing validate_redirect_url() helper at lib/html_utility.php performed proper validation but was not invoked from auth_login_redirect(). This issue has been fixed in version 1.2.31.
MEDIUM
6.10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
2026-06-25 22:29:51+03:00
2026-06-25 22:29:51+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-40080']
['CVE-2026-40080']
9fec44baa2454f3a2b1196d37cda0aeecc92390c42b5784d3b346d8ad8ad2c7e
2026-06-26 15:06:33.367280+03:00
2026-06-26 15:06:33.367280+03:00
{'id': 'CVELIST:CVE-2026-40080', 'cvss': {'score': 6.1, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-40080', 'type': 'cvelist', 'title': 'CVE-2026-40080 Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect', 'cvelist': ['CVE-2026-40080'], 'assigned': '2026-04-09T00:39:12', 'lastseen': '2026-06-25T22:32:40', 'modified': '2026-06-25T22:29:51', 'published': '2026-06-25T22:29:51', 'description': "Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than a host check at str_contains($referer, CACTI_PATH_URL). When the user's login_opts == '1' (redirect to referer after login), the function used $_SERVER['HTTP_REFERER'] directly. An attacker could craft a referer such as https://evil.com/cacti/. Where CACTI_PATH_URL is /cacti/, the substring matches and the user is redirected to evil.com after login. The pre-existing validate_redirect_url() helper at lib/html_utility.php performed proper validation but was not invoked from auth_login_redirect(). This issue has been fixed in version 1.2.31.", 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-40080']}, {'type': 'attackerkb', 'idList': ['AKB:6C4D4E9E-3B39-46BE-92AC-4FFECF6662D6']}, {'type': 'cve', 'idList': ['CVE-2026-40080']}, {'type': 'debiancve', 'idList': ['DEBIANCVE:CVE-2026-40080']}, {'type': 'euvd', 'idList': ['EUVD-2026-39585']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-40080']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52624']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-41479
CVE-2026-41479 Authlib OAuth 2.0 authorization endpoint open redirects to attacker-controlled redirect_uri on unsupported response_type
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. A single request to the authorization endpoint is enough to obtain a 302 Location response to an arbitrary attacker-controlled URL. This vulnerability is fixed in 1.6.10 and 1.7.1.
MEDIUM
5.40
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
2026-06-22 20:35:13+03:00
2026-06-22 20:35:13+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-41479']
['CVE-2026-41479']
ccd4b8777c34088332a547d7880d38379c9b5ff6f389cbe10f55c94fa1fb8f84
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-41479', 'cvss': {'score': 5.4, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-41479', 'type': 'cvelist', 'title': 'CVE-2026-41479 Authlib OAuth 2.0 authorization endpoint open redirects to attacker-controlled redirect_uri on unsupported response_type', 'cvelist': ['CVE-2026-41479'], 'assigned': '2026-04-20T16:14:19', 'lastseen': '2026-06-23T15:52:49', 'modified': '2026-06-22T20:35:13', 'published': '2026-06-22T20:35:13', 'description': "Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. A single request to the authorization endpoint is enough to obtain a 302 Location response to an arbitrary attacker-controlled URL. This vulnerability is fixed in 1.6.10 and 1.7.1.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:0189293F-3039-4DCF-A55B-DF05671B08F0']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-41479']}, {'type': 'cve', 'idList': ['CVE-2026-41479']}, {'type': 'debiancve', 'idList': ['DEBIANCVE:CVE-2026-41479']}, {'type': 'euvd', 'idList': ['EUVD-2026-38360']}, {'type': 'github', 'idList': ['GHSA-W8P2-R796-3VMQ']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-41479']}, {'type': 'osv', 'idList': ['OSV:DEBIAN-CVE-2026-41479', 'OSV:GHSA-W8P2-R796-3VMQ', 'OSV:MINI-P297-6W5V-99R9', 'OSV:MINI-V75P-C3RC-GQF7', 'OSV:UBUNTU-CVE-2026-41479']}, {'type': 'ptsecurity', 'idList': ['PT-2026-47598']}, {'type': 'snyk', 'idList': ['SNYK:PYTHON-AUTHLIB-17266082']}, {'type': 'vulnersosv', 'idList': ['VULNERSOSV:BM445WB5DIMB3ALISMPXQBHPTQ', 'VULNERSOSV:UW6ZIHF7JU2A3BFBWRQBEIRYSM']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-41479']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-41523
CVE-2026-41523 vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (python -O or PYTHONOPTIMIZE=1). This vulnerability is fixed in 0.22.0.
HIGH
7.50
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
2026-06-22 22:18:14+03:00
2026-06-22 22:18:14+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-41523']
['CVE-2026-41523']
8e4564d898227aa3bde77cc23eaa619d0584372dfdf6b0a2aa5e1669c13c72c1
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-41523', 'cvss': {'score': 7.5, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-41523', 'type': 'cvelist', 'title': 'CVE-2026-41523 vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution', 'cvelist': ['CVE-2026-41523'], 'assigned': '2026-04-20T18:18:50', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-22T22:18:14', 'published': '2026-06-22T22:18:14', 'description': "vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (python -O or PYTHONOPTIMIZE=1). This vulnerability is fixed in 0.22.0.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:BC5FFF6D-47D3-4CF8-A9A3-C0BF1718CFC7']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-41523']}, {'type': 'cve', 'idList': ['CVE-2026-41523']}, {'type': 'euvd', 'idList': ['EUVD-2026-38406']}, {'type': 'github', 'idList': ['GHSA-Q8GQ-377P-JQ3R']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-41523']}, {'type': 'osv', 'idList': ['OSV:GHSA-Q8GQ-377P-JQ3R', 'OSV:MINI-7P69-F6M2-CC4R', 'OSV:MINI-JX2C-GF52-2PW6', 'OSV:MINI-RJGP-HVFC-VVGM']}, {'type': 'ptsecurity', 'idList': ['PT-2026-50140']}, {'type': 'snyk', 'idList': ['SNYK:PYTHON-VLLM-17353931']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-41523']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-42127
CVE-2026-42127 Grafana pre-auth DoS through arbitrarily large input to public dashboard query handler
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
HIGH
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2026-06-22 16:31:28+03:00
2026-06-22 16:31:28+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-42127']
['CVE-2026-42127']
fffe4985c3a889a95cad2c4ef28361510271ae490ca79021e7681e3dae88a4a8
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-42127', 'cvss': {'score': 7.5, 'source': 'grafana', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-42127', 'type': 'cvelist', 'title': 'CVE-2026-42127 Grafana pre-auth DoS through arbitrarily large input to public dashboard query handler', 'cvelist': ['CVE-2026-42127'], 'assigned': '2026-04-24T15:38:08', 'lastseen': '2026-06-22T17:32:46', 'modified': '2026-06-22T16:31:28', 'published': '2026-06-22T16:31:28', 'description': 'The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.', 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-42127']}, {'type': 'attackerkb', 'idList': ['AKB:C32F0E1A-B842-4F97-B2D0-50B904370097']}, {'type': 'cve', 'idList': ['CVE-2026-42127']}, {'type': 'euvd', 'idList': ['EUVD-2026-38309']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-42127']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-42127']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51363']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-42127']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-42129
CVE-2026-42129 Path Traversal in Loki Datasource leads to Internal Information Disclosure
The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and internal service information.
HIGH
7.70
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
2026-06-22 13:18:27+03:00
2026-06-22 13:18:27+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-42129']
['CVE-2026-42129']
1df068f5ce7b1f6bb84aa7f41723f83adaefe56cfa7d0573bcf92a023435eaa2
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-42129', 'cvss': {'score': 7.7, 'source': 'grafana', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-42129', 'type': 'cvelist', 'title': 'CVE-2026-42129 Path Traversal in Loki Datasource leads to Internal Information Disclosure', 'cvelist': ['CVE-2026-42129'], 'assigned': '2026-04-24T15:38:08', 'lastseen': '2026-06-22T17:20:50', 'modified': '2026-06-22T13:18:27', 'published': '2026-06-22T13:18:27', 'description': "The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and internal service information.", 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-42129']}, {'type': 'attackerkb', 'idList': ['AKB:CDFF8776-A1DD-4F41-B836-EED0B0A8A34D']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-42129']}, {'type': 'cve', 'idList': ['CVE-2026-42129']}, {'type': 'euvd', 'idList': ['EUVD-2026-38241']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-42129']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51303']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-42129']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-42867
CVE-2026-42867 Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (POST /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem. This vulnerability is fixed in 1.9.0.
MEDIUM
6.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
2026-06-23 16:29:11+03:00
2026-06-23 16:29:11+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-42867']
['CVE-2026-42867']
6d8419916e1775461aac1ca2b0ae0b459cb4976da22d499d8d6f36dca27956c5
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-42867', 'cvss': {'score': 6.5, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-42867', 'type': 'cvelist', 'title': 'CVE-2026-42867 Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint', 'cvelist': ['CVE-2026-42867'], 'assigned': '2026-04-30T18:49:06', 'lastseen': '2026-06-23T17:02:48', 'modified': '2026-06-23T16:29:11', 'published': '2026-06-23T16:29:11', 'description': "Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (POST /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem. This vulnerability is fixed in 1.9.0.", 'enchantments': {'dependencies': {'references': [{'type': 'circl', 'idList': ['CIRCL:CVE-2026-42867']}, {'type': 'cve', 'idList': ['CVE-2026-42867']}, {'type': 'euvd', 'idList': ['EUVD-2026-38518']}, {'type': 'github', 'idList': ['GHSA-79PH-745M-6WXQ']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-42867']}, {'type': 'osv', 'idList': ['OSV:GHSA-79PH-745M-6WXQ']}, {'type': 'ptsecurity', 'idList': ['PT-2026-50141']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-42867']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-40082
CVE-2026-40082 Cacti: Session Fixation via missing session_regenerate_id() after login
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is NOT called after successful login. The login flow at auth_login.php:203-207 directly sets $_SESSION[SESS_USER_ID] without rotating the session ID. The session cookie configuration is otherwise good (httponly=true, samesite=Strict, secure=true for HTTPS at include/global.php:513-537), but these do not prevent session fixation via same-site vectors. This issue has been fixed in version 1.2.31.
MEDIUM
5.40
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
2026-06-25 22:33:45+03:00
2026-06-25 22:33:45+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-40082']
['CVE-2026-40082']
841c225ad7c0671f401a34033f22bbf5ea615da452121b9240210ce18b29fd49
2026-06-26 15:06:33.367280+03:00
2026-06-26 15:06:33.367280+03:00
{'id': 'CVELIST:CVE-2026-40082', 'cvss': {'score': 5.4, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-40082', 'type': 'cvelist', 'title': 'CVE-2026-40082 Cacti: Session Fixation via missing session_regenerate_id() after login', 'cvelist': ['CVE-2026-40082'], 'assigned': '2026-04-09T00:39:12', 'lastseen': '2026-06-25T23:08:40', 'modified': '2026-06-25T22:33:45', 'published': '2026-06-25T22:33:45', 'description': 'Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is NOT called after successful login. The login flow at auth_login.php:203-207 directly sets $_SESSION[SESS_USER_ID] without rotating the session ID. The session cookie configuration is otherwise good (httponly=true, samesite=Strict, secure=true for HTTPS at include/global.php:513-537), but these do not prevent session fixation via same-site vectors. This issue has been fixed in version 1.2.31.', 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-40082']}, {'type': 'attackerkb', 'idList': ['AKB:6CE54899-FC0E-423A-B9C1-AA8149E6EEC3']}, {'type': 'cve', 'idList': ['CVE-2026-40082']}, {'type': 'debiancve', 'idList': ['DEBIANCVE:CVE-2026-40082']}, {'type': 'euvd', 'idList': ['EUVD-2026-39586']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-40082']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52625']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2026-40082']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-45034
CVE-2026-45034 PhpSpreadsheet: File::prohibitWrappers bypass
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme) && strlen($scheme) > 1 to reject stream wrappers such as phar://, php://, data:// or expect://. The check is not equivalent to "does the path contain a wrapper". When the input has the form phar:///path/file.phar/inner with three or more slashes after the scheme, parse_url returns boolean false instead of returning the scheme string. The is_string($scheme) branch is therefore skipped, the helper returns without throwing, and the caller proceeds. PHP's stream layer, however, still treats phar:///... as a valid phar wrapper and opens the underlying phar file. The result is that IOFactory::load($attackerPath) walks past the patch and still touches the phar wrapper. On PHP 7.x, simply reaching the phar wrapper via is_file is enough for PHP to automatically deserialize the phar metadata, which in turn invokes the magic methods __wakeup and __destruct of an attacker controlled object and gives full RCE. On PHP 8.x, automatic metadata deserialization for plain file ops was removed, so the chain at the PhpSpreadsheet layer reduces to a phar wrapper file read primitive, and RCE only resurfaces if the downstream consumer ever calls Phar::getMetadata. This vulnerability is fixed in 1.30.5.
CRITICAL
9.20
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N
2026-06-22 20:32:32+03:00
2026-06-22 20:32:32+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-45034']
['CVE-2026-45034']
47dd5b44c4aea3422aa0e86e2dadeecef22225f0a3c35c9440464977b9e2ef2d
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-45034', 'cvss': {'score': 9.2, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-45034', 'type': 'cvelist', 'title': 'CVE-2026-45034 PhpSpreadsheet: File::prohibitWrappers bypass', 'cvelist': ['CVE-2026-45034'], 'assigned': '2026-05-08T16:58:28', 'lastseen': '2026-06-23T15:56:50', 'modified': '2026-06-22T20:32:32', 'published': '2026-06-22T20:32:32', 'description': 'PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme) && strlen($scheme) > 1 to reject stream wrappers such as phar://, php://, data:// or expect://. The check is not equivalent to "does the path contain a wrapper". When the input has the form phar:///path/file.phar/inner with three or more slashes after the scheme, parse_url returns boolean false instead of returning the scheme string. The is_string($scheme) branch is therefore skipped, the helper returns without throwing, and the caller proceeds. PHP\'s stream layer, however, still treats phar:///... as a valid phar wrapper and opens the underlying phar file. The result is that IOFactory::load($attackerPath) walks past the patch and still touches the phar wrapper. On PHP 7.x, simply reaching the phar wrapper via is_file is enough for PHP to automatically deserialize the phar metadata, which in turn invokes the magic methods __wakeup and __destruct of an attacker controlled object and gives full RCE. On PHP 8.x, automatic metadata deserialization for plain file ops was removed, so the chain at the PhpSpreadsheet layer reduces to a phar wrapper file read primitive, and RCE only resurfaces if the downstream consumer ever calls Phar::getMetadata. This vulnerability is fixed in 1.30.5.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:E1C3206B-50FA-4F32-8F4F-CA1E25690ED0']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-45034']}, {'type': 'cve', 'idList': ['CVE-2026-45034']}, {'type': 'euvd', 'idList': ['EUVD-2026-38359']}, {'type': 'github', 'idList': ['GHSA-87M4-826X-3CRX']}, {'type': 'githubexploit', 'idList': ['6E759A42-6EB5-5158-BC5F-E1FD8AE27F04']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-45034']}, {'type': 'osv', 'idList': ['OSV:GHSA-87M4-826X-3CRX']}, {'type': 'ptsecurity', 'idList': ['PT-2026-47606']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-45034']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-45135
CVE-2026-45135 Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Caddy's FastCGI splitting into treating a non-.php (or other configured split_path extension) file as a script. In any deployment where the attacker can place content into a file served via FastCGI (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This vulnerability is fixed in 2.11.3.
HIGH
8.10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
2026-06-23 17:56:42+03:00
2026-06-23 17:56:42+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-45135']
['CVE-2026-45135']
4943e35f90de6afb5dd99ef32986bd9db1362d5c58bd4bfbf36682d8b54e34bb
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-45135', 'cvss': {'score': 8.1, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-45135', 'type': 'cvelist', 'title': 'CVE-2026-45135 Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files', 'cvelist': ['CVE-2026-45135'], 'assigned': '2026-05-08T20:08:17', 'lastseen': '2026-06-23T18:32:50', 'modified': '2026-06-23T17:56:42', 'published': '2026-06-23T17:56:42', 'description': "Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Caddy's FastCGI splitting into treating a non-.php (or other configured split_path extension) file as a script. In any deployment where the attacker can place content into a file served via FastCGI (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This vulnerability is fixed in 2.11.3.", 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-45135']}, {'type': 'attackerkb', 'idList': ['AKB:C6170DB6-4D03-4A31-9104-566D9609E46E']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-45135']}, {'type': 'cve', 'idList': ['CVE-2026-45135']}, {'type': 'euvd', 'idList': ['EUVD-2026-38560']}, {'type': 'github', 'idList': ['GHSA-M675-2P33-XV9G']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-45135']}, {'type': 'osv', 'idList': ['OSV:GHSA-M675-2P33-XV9G', 'OSV:MINI-8QH5-R8H3-45GP']}, {'type': 'ptsecurity', 'idList': ['PT-2026-41687']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-45135']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-45692
CVE-2026-45692 Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one config object is accepted, but then resolves to a different config object during traversal. This happens because the authorization layer uses string prefix matching and the /config traversal layer parses array indices numerically using strconv.Atoi(). This vulnerability is fixed in 2.11.3.
MEDIUM
5.40
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
2026-06-23 17:55:11+03:00
2026-06-23 17:55:11+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-45692']
['CVE-2026-45692']
ab99c465f011b3522cd792bb7fc481de227c066890089dd0da181b4919404691
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-45692', 'cvss': {'score': 5.4, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-45692', 'type': 'cvelist', 'title': 'CVE-2026-45692 Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization', 'cvelist': ['CVE-2026-45692'], 'assigned': '2026-05-13T04:38:01', 'lastseen': '2026-06-23T18:08:46', 'modified': '2026-06-23T17:55:11', 'published': '2026-06-23T17:55:11', 'description': 'Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one config object is accepted, but then resolves to a different config object during traversal. This happens because the authorization layer uses string prefix matching and the /config traversal layer parses array indices numerically using strconv.Atoi(). This vulnerability is fixed in 2.11.3.', 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-45692']}, {'type': 'attackerkb', 'idList': ['AKB:AF9DF82A-3475-4611-831A-342F285692B5']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-45692']}, {'type': 'cve', 'idList': ['CVE-2026-45692']}, {'type': 'euvd', 'idList': ['EUVD-2026-38559']}, {'type': 'github', 'idList': ['GHSA-X5W9-XH9R-MVFC']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-45692']}, {'type': 'osv', 'idList': ['OSV:GHSA-X5W9-XH9R-MVFC', 'OSV:MINI-FF5F-X2FR-4VXM', 'OSV:MINI-X239-2FFX-M95M']}, {'type': 'ptsecurity', 'idList': ['PT-2026-41964']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-4610
CVE-2026-4610 ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 5.9.8.5.
MEDIUM
6.40
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
2026-06-23 12:32:56+03:00
2026-06-23 12:32:56+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-4610']
['CVE-2026-4610']
502e6e087946b2a0535265db38e17749fd9cc143c63601582c988830181633f8
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-4610', 'cvss': {'score': 6.4, 'source': 'wordfence', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-4610', 'type': 'cvelist', 'title': 'CVE-2026-4610 ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content', 'cvelist': ['CVE-2026-4610'], 'assigned': '2026-03-23T04:44:36', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-23T12:32:56', 'published': '2026-06-23T12:32:56', 'description': "The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 5.9.8.5.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:2F7706EB-2F4A-4229-9118-8E4625677B7B']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-4610']}, {'type': 'cve', 'idList': ['CVE-2026-4610']}, {'type': 'euvd', 'idList': ['EUVD-2026-38447']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-4610']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51498']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-47155
CVE-2026-47155 vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies --revision or --code-revision can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision. This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision. This vulnerability is fixed in 0.22.0.
MEDIUM
6.50
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
2026-06-22 22:20:10+03:00
2026-06-22 22:20:10+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-47155']
['CVE-2026-47155']
f00f45de1ad47470b3dd70c24be33c19688063cdefca7810863f7cc826d995f6
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-47155', 'cvss': {'score': 6.5, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-47155', 'type': 'cvelist', 'title': 'CVE-2026-47155 vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors', 'cvelist': ['CVE-2026-47155'], 'assigned': '2026-05-18T21:25:34', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-22T22:20:10', 'published': '2026-06-22T22:20:10', 'description': "vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies --revision or --code-revision can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision. This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision. This vulnerability is fixed in 0.22.0.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:8D1042DF-5142-40FE-8430-BC144877C7DA']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-47155']}, {'type': 'cve', 'idList': ['CVE-2026-47155']}, {'type': 'euvd', 'idList': ['EUVD-2026-38407']}, {'type': 'github', 'idList': ['GHSA-3WW4-5JV9-J5GM']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-47155']}, {'type': 'osv', 'idList': ['OSV:GHSA-3WW4-5JV9-J5GM', 'OSV:MINI-265M-796R-J4H6', 'OSV:MINI-4GX2-8QXV-64X8', 'OSV:MINI-9M3H-GJV4-V4J8']}, {'type': 'ptsecurity', 'idList': ['PT-2026-48537']}, {'type': 'snyk', 'idList': ['SNYK:PYTHON-VLLM-17304846']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-47155']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-47240
CVE-2026-47240 Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a "raw data" argument that is sent verbatim after validation to prevent command injection. However, if a server does not support non-synchronizing literals, it may still be possible to inject arbitrary IMAP commands inside non-synchronizing literals. A server without support for non-synchronizing literals may interpret the "+}\r\n" as the end of a malformed command line and respond with a tagged BAD. In that case, the contents of the literal will be interpreted as one or more new pipelined commands, allowing a CRLF command injection attack to succeed. This affects criteria for #search and #uid_search; search_keys for #sort, #thread, #uid_sort, and #uid_thread; and attr for #fetch and #uid_fetch. This vulnerability is fixed in 0.6.5 and 0.5.15.
MEDIUM
5.80
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/SC:N/VI:H/SI:N/VA:L/SA:N
2026-06-22 20:17:15+03:00
2026-06-22 20:17:15+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-47240']
['CVE-2026-47240']
61a432211e1be856d987688eda9d986b7f564872efae224c3fd541164a37c837
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-47240', 'cvss': {'score': 5.8, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/SC:N/VI:H/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-47240', 'type': 'cvelist', 'title': 'CVE-2026-47240 Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument', 'cvelist': ['CVE-2026-47240'], 'assigned': '2026-05-18T22:54:18', 'lastseen': '2026-06-23T15:52:48', 'modified': '2026-06-22T20:17:15', 'published': '2026-06-22T20:17:15', 'description': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a "raw data" argument that is sent verbatim after validation to prevent command injection. However, if a server does not support non-synchronizing literals, it may still be possible to inject arbitrary IMAP commands inside non-synchronizing literals. A server without support for non-synchronizing literals may interpret the "+}\\r\\n" as the end of a malformed command line and respond with a tagged BAD. In that case, the contents of the literal will be interpreted as one or more new pipelined commands, allowing a CRLF command injection attack to succeed. This affects criteria for #search and #uid_search; search_keys for #sort, #thread, #uid_sort, and #uid_thread; and attr for #fetch and #uid_fetch. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:5306386D-D6FF-4C21-9F65-9D0CCECFBEB7']}, {'type': 'cgr', 'idList': ['CHAINGUARD:CVE-2026-47240']}, {'type': 'cve', 'idList': ['CVE-2026-47240']}, {'type': 'euvd', 'idList': ['EUVD-2026-38352']}, {'type': 'github', 'idList': ['GHSA-8P34-64R3-MWG8']}, {'type': 'nessus', 'idList': ['RUBY_GEM_NETIMAP_CVE_2026_47240_47241_47242.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-47240']}, {'type': 'osv', 'idList': ['OSV:CGA-V4XC-FXJJ-9W6P', 'OSV:GHSA-8P34-64R3-MWG8', 'OSV:MINI-2VXC-4X6H-CJ2X', 'OSV:MINI-35G3-2376-MR42', 'OSV:MINI-7F2C-6F6R-HXMX', 'OSV:MINI-G3G9-72PV-X22M', 'OSV:MINI-JCMF-HH2H-WR2J', 'OSV:MINI-MP8Q-Q7CP-8366', 'OSV:MINI-MX77-7RCX-8WMG', 'OSV:MINI-P933-3M9M-964V', 'OSV:MINI-R499-82Q3-WRRX', 'OSV:MINI-V6H4-QGQH-5VV3', 'OSV:MINI-WG6R-8Q3G-M86G', 'OSV:MINI-WJ69-P77W-8MX6']}, {'type': 'ptsecurity', 'idList': ['PT-2026-48340']}, {'type': 'rubygems', 'idList': ['RUBY:NET-IMAP-2026-47240']}, {'type': 'snyk', 'idList': ['SNYK:RUBY-NETIMAP-17277006']}, {'type': 'susecve', 'idList': ['SUSECVE:CVE-2026-47240']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-47240']}, {'type': 'wolfi', 'idList': ['WOLFI:CVE-2026-47240']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-47241
CVE-2026-47241 Net::IMAP: Denial of Service via incomplete raw argument validation
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argument which is only validated to prevent CRLF injection and then sent verbatim. If this string is derived from user-controlled input, an attacker can force the next command to be absorbed as a continuation of the first command. This will cause the first command to eventually fail, but also prevents it from returning until another command is sent (from another thread). That other command will not return until the connection is closed. This vulnerability is fixed in 0.6.5 and 0.5.15.
LOW
2.10
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N
2026-06-22 20:11:04+03:00
2026-06-22 20:11:04+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-47241']
['CVE-2026-47241']
9c863f2812d98e2c0f229f07af4c6641162684dfb36aceda7f4941e1af17da51
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-47241', 'cvss': {'score': 2.1, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'LOW'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-47241', 'type': 'cvelist', 'title': 'CVE-2026-47241 Net::IMAP: Denial of Service via incomplete raw argument validation', 'cvelist': ['CVE-2026-47241'], 'assigned': '2026-05-18T22:54:18', 'lastseen': '2026-06-23T14:38:43', 'modified': '2026-06-22T20:11:04', 'published': '2026-06-22T20:11:04', 'description': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argument which is only validated to prevent CRLF injection and then sent verbatim. If this string is derived from user-controlled input, an attacker can force the next command to be absorbed as a continuation of the first command. This will cause the first command to eventually fail, but also prevents it from returning until another command is sent (from another thread). That other command will not return until the connection is closed. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:2B0D91DA-14FD-4704-B5D8-F968A333D186']}, {'type': 'cgr', 'idList': ['CHAINGUARD:CVE-2026-47241']}, {'type': 'cve', 'idList': ['CVE-2026-47241']}, {'type': 'euvd', 'idList': ['EUVD-2026-38350']}, {'type': 'github', 'idList': ['GHSA-C4FP-CXRR-MJ66']}, {'type': 'nessus', 'idList': ['RUBY_GEM_NETIMAP_CVE_2026_47240_47241_47242.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-47241']}, {'type': 'osv', 'idList': ['OSV:CGA-29Q6-JFHG-VHHF', 'OSV:GHSA-C4FP-CXRR-MJ66', 'OSV:MINI-2528-PGG6-H4WP', 'OSV:MINI-2VF5-V3CJ-MWCC', 'OSV:MINI-2XHF-Q398-Q93X', 'OSV:MINI-5PC8-MVX4-VVV3', 'OSV:MINI-7J24-3V7W-QHMM', 'OSV:MINI-7PX6-FX4C-7F32', 'OSV:MINI-G4VQ-X5W2-66P9', 'OSV:MINI-HWW9-R2JP-9C2R', 'OSV:MINI-JQ65-38WF-QM57', 'OSV:MINI-R6PM-CCQM-647F', 'OSV:MINI-V2G8-5PHM-C9Q7', 'OSV:MINI-W8MM-H7MC-M5C5']}, {'type': 'ptsecurity', 'idList': ['PT-2026-48341']}, {'type': 'rubygems', 'idList': ['RUBY:NET-IMAP-2026-47241']}, {'type': 'snyk', 'idList': ['SNYK:RUBY-NETIMAP-17277057']}, {'type': 'susecve', 'idList': ['SUSECVE:CVE-2026-47241']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-47241']}, {'type': 'wolfi', 'idList': ['WOLFI:CVE-2026-47241']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-47242
CVE-2026-47242 Net::IMAP: Command Injection via ID command argument
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.
MEDIUM
5.80
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/SC:N/VI:H/SI:N/VA:L/SA:N
2026-06-22 20:19:41+03:00
2026-06-22 20:19:41+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-47242']
['CVE-2026-47242']
e1c360e6d607f08b71a1e3c520641e58e74304d9240795d5328255d12b13755d
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-47242', 'cvss': {'score': 5.8, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/SC:N/VI:H/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-47242', 'type': 'cvelist', 'title': 'CVE-2026-47242 Net::IMAP: Command Injection via ID command argument', 'cvelist': ['CVE-2026-47242'], 'assigned': '2026-05-18T22:54:18', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-22T20:19:41', 'published': '2026-06-22T20:19:41', 'description': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F2DE48BF-CF55-4A76-88A6-E2385999FB83']}, {'type': 'cgr', 'idList': ['CHAINGUARD:CVE-2026-47242']}, {'type': 'cve', 'idList': ['CVE-2026-47242']}, {'type': 'euvd', 'idList': ['EUVD-2026-38353']}, {'type': 'github', 'idList': ['GHSA-46Q3-7GV7-QMGG']}, {'type': 'nessus', 'idList': ['RUBY_GEM_NETIMAP_CVE_2026_47240_47241_47242.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-47242']}, {'type': 'osv', 'idList': ['OSV:CGA-3P52-Q9CM-66F5', 'OSV:GHSA-46Q3-7GV7-QMGG', 'OSV:MINI-5RRX-5QWR-WQVM', 'OSV:MINI-5WPW-974X-P8Q7', 'OSV:MINI-6R5V-VJHV-QGRG', 'OSV:MINI-FPQQ-FPJX-CR84', 'OSV:MINI-M4MM-6G6W-Q6HW', 'OSV:MINI-P5C7-GV53-JF2W', 'OSV:MINI-PCGG-WV5G-PFR2', 'OSV:MINI-Q3J4-8CVR-7VHW', 'OSV:MINI-QJHR-4QC2-QFPR', 'OSV:MINI-RH55-X2W5-88RC', 'OSV:MINI-VJC3-GXHX-7458', 'OSV:MINI-XHPX-XG48-Q48C']}, {'type': 'ptsecurity', 'idList': ['PT-2026-48342']}, {'type': 'rubygems', 'idList': ['RUBY:NET-IMAP-2026-47242']}, {'type': 'snyk', 'idList': ['SNYK:RUBY-NETIMAP-17277096']}, {'type': 'susecve', 'idList': ['SUSECVE:CVE-2026-47242']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-47242']}, {'type': 'wolfi', 'idList': ['WOLFI:CVE-2026-47242']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-47279
CVE-2026-47279 NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without verifying that the column was visible in the shared view, so anyone holding a share UUID could read links from any LTAR column on the view's table — including columns the view owner had hidden. publicMmList, publicHmList, and relDataList already ensured that the requested column belonged to the view's model, but did not check the view-column entry's show flag. This vulnerability is fixed in 2026.05.1.
MEDIUM
6.90
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:N/VI:N/SI:N/VA:N/SA:N
2026-06-23 20:18:57+03:00
2026-06-23 20:18:57+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-47279']
['CVE-2026-47279']
ca871a200a328e258d1b51b3f4970116c50c04a5524159b01b6cadfffc9e52af
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-47279', 'cvss': {'score': 6.9, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:N/VI:N/SI:N/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-47279', 'type': 'cvelist', 'title': 'CVE-2026-47279 NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints', 'cvelist': ['CVE-2026-47279'], 'assigned': '2026-05-18T23:03:37', 'lastseen': '2026-06-23T21:02:41', 'modified': '2026-06-23T20:18:57', 'published': '2026-06-23T20:18:57', 'description': "NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without verifying that the column was visible in the shared view, so anyone holding a share UUID could read links from any LTAR column on the view's table — including columns the view owner had hidden. publicMmList, publicHmList, and relDataList already ensured that the requested column belonged to the view's model, but did not check the view-column entry's show flag. This vulnerability is fixed in 2026.05.1.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:87145375-9C7F-446B-B807-D2A855D92D91']}, {'type': 'cve', 'idList': ['CVE-2026-47279']}, {'type': 'euvd', 'idList': ['EUVD-2026-38620']}, {'type': 'github', 'idList': ['GHSA-9WGH-M22W-9XJ8']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-47279']}, {'type': 'osv', 'idList': ['OSV:GHSA-9WGH-M22W-9XJ8']}, {'type': 'ptsecurity', 'idList': ['PT-2026-46992']}, {'type': 'snyk', 'idList': ['SNYK:JS-NOCODB-17279618']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-48491
CVE-2026-48491 Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with stricter TLS options (for example RequireAndVerifyClientCert), SNICheck resolves the TLS options for the HTTP Host header using exact map lookups only and never applies wildcard matching. If another permissive SNI is served on the same entrypoint, an attacker can complete the TLS handshake under the permissive options and then send an HTTP Host header targeting the wildcard-protected backend, reaching it without presenting a client certificate. This affects the regular HTTPS / HTTP-2 path and does not require HTTP/3. This vulnerability is fixed in 3.7.3.
HIGH
7.80
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:H/VI:N/SI:H/VA:N/SA:N
2026-06-23 19:12:10+03:00
2026-06-23 19:12:10+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-48491']
['CVE-2026-48491']
b0ae1ac3eafc078325f9c11a5077dc73de7ed38da8f2ea918eb29ae741482075
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-48491', 'cvss': {'score': 7.8, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:H/VI:N/SI:H/VA:N/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48491', 'type': 'cvelist', 'title': 'CVE-2026-48491 Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass', 'cvelist': ['CVE-2026-48491'], 'assigned': '2026-05-21T15:33:08', 'lastseen': '2026-06-23T19:40:19', 'modified': '2026-06-23T19:12:10', 'published': '2026-06-23T19:12:10', 'description': "Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with stricter TLS options (for example RequireAndVerifyClientCert), SNICheck resolves the TLS options for the HTTP Host header using exact map lookups only and never applies wildcard matching. If another permissive SNI is served on the same entrypoint, an attacker can complete the TLS handshake under the permissive options and then send an HTTP Host header targeting the wildcard-protected backend, reaching it without presenting a client certificate. This affects the regular HTTPS / HTTP-2 path and does not require HTTP/3. This vulnerability is fixed in 3.7.3.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:4339F627-A564-484E-B3D0-9AAA0913072C']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48491']}, {'type': 'cve', 'idList': ['CVE-2026-48491']}, {'type': 'euvd', 'idList': ['EUVD-2026-38575']}, {'type': 'freebsd', 'idList': ['57E69B2C-67B2-11F1-B3B6-5404A68AD561']}, {'type': 'github', 'idList': ['GHSA-5R4W-85F3-PW66']}, {'type': 'nessus', 'idList': ['FREEBSD_PKG_57E69B2C67B211F1B3B65404A68AD561.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48491']}, {'type': 'opensuse', 'idList': ['OPENSUSE-SU-2026:11047-1']}, {'type': 'osv', 'idList': ['OSV:GHSA-5R4W-85F3-PW66', 'OSV:OPENSUSE-SU-2026:11047-1']}, {'type': 'ptsecurity', 'idList': ['PT-2026-50143']}, {'type': 'susecve', 'idList': ['SUSECVE:CVE-2026-48491']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-48500
CVE-2026-48500 Filament: Unauthenticated temporary file upload on auth pages
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the Livewire component the schema is embedded in. However, some schemas, such as the panel login form, do not require file uploads, and exposing unauthenticated temporary file uploads on these components is not an acceptable risk. On these components, an unauthenticated attacker could upload arbitrary files to the application's temporary storage, which could be abused to exhaust disk space or inflate storage costs. This vulnerability is fixed in 3.3.52, 4.11.5, and 5.6.5.
MEDIUM
6.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
2026-06-22 21:41:17+03:00
2026-06-22 21:41:17+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-48500']
['CVE-2026-48500']
0e149a3b0a9d4606915bfa72da51a091f3696c110890776366b50c06bcfbb9ea
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-48500', 'cvss': {'score': 6.5, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48500', 'type': 'cvelist', 'title': 'CVE-2026-48500 Filament: Unauthenticated temporary file upload on auth pages', 'cvelist': ['CVE-2026-48500'], 'assigned': '2026-05-21T15:33:08', 'lastseen': '2026-06-23T14:38:43', 'modified': '2026-06-22T21:41:17', 'published': '2026-06-22T21:41:17', 'description': "Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the Livewire component the schema is embedded in. However, some schemas, such as the panel login form, do not require file uploads, and exposing unauthenticated temporary file uploads on these components is not an acceptable risk. On these components, an unauthenticated attacker could upload arbitrary files to the application's temporary storage, which could be abused to exhaust disk space or inflate storage costs. This vulnerability is fixed in 3.3.52, 4.11.5, and 5.6.5.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:D2B11DF5-C877-4E51-9C37-B77449B94585']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48500']}, {'type': 'cve', 'idList': ['CVE-2026-48500']}, {'type': 'euvd', 'idList': ['EUVD-2026-38394']}, {'type': 'github', 'idList': ['GHSA-44WP-G8F4-F4V5']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48500']}, {'type': 'osv', 'idList': ['OSV:GHSA-44WP-G8F4-F4V5']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51389']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48500']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-48502
CVE-2026-48502 MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp extension parsing, the computed tokenSize includes the extension body length from the wire and is used in a stackalloc operation before the extension length is validated as one of the valid timestamp sizes. A very small payload can claim a large timestamp extension body and cause a stack allocation large enough to trigger an uncatchable StackOverflowException, terminating the host process. This vulnerability is fixed in 2.5.301 and 3.1.7.
HIGH
8.20
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N
2026-06-22 21:18:29+03:00
2026-06-22 21:18:29+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-48502']
['CVE-2026-48502']
1d7ae6d2df8ed705e86b24ed225c84f45b3540e897f92a2a7b2a3fad0758d142
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-48502', 'cvss': {'score': 8.2, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48502', 'type': 'cvelist', 'title': 'CVE-2026-48502 MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows', 'cvelist': ['CVE-2026-48502'], 'assigned': '2026-05-21T15:33:08', 'lastseen': '2026-06-23T15:52:48', 'modified': '2026-06-22T21:18:29', 'published': '2026-06-22T21:18:29', 'description': 'MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp extension parsing, the computed tokenSize includes the extension body length from the wire and is used in a stackalloc operation before the extension length is validated as one of the valid timestamp sizes. A very small payload can claim a large timestamp extension body and cause a stack allocation large enough to trigger an uncatchable StackOverflowException, terminating the host process. This vulnerability is fixed in 2.5.301 and 3.1.7.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:D330B63C-4C7E-4809-911E-0DC7F6ECF8B9']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48502']}, {'type': 'cve', 'idList': ['CVE-2026-48502']}, {'type': 'euvd', 'idList': ['EUVD-2026-38389']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48502']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51390']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48502']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-48505
CVE-2026-48505 Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused via concurrent submission. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. If an attacker gains access to both the user's password and their recovery codes, they get two authenticated sessions per recovery code burned instead of one, or more if they batch the parallel submissions wider, materially extending the attacker's window of access compared to what the single-use guarantee implies. This vulnerability is fixed in 4.11.5 and 5.6.5.
HIGH
7.40
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
2026-06-22 21:39:26+03:00
2026-06-22 21:42:19+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-48505']
['CVE-2026-48505']
5a750776c807361c8f96ea3589f10196c776ebf30b5b81d5e3017223e52b0a92
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-48505', 'cvss': {'score': 7.4, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48505', 'type': 'cvelist', 'title': 'CVE-2026-48505 Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission', 'cvelist': ['CVE-2026-48505'], 'assigned': '2026-05-21T16:18:10', 'lastseen': '2026-06-23T14:38:43', 'modified': '2026-06-22T21:42:19', 'published': '2026-06-22T21:39:26', 'description': "Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused via concurrent submission. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. If an attacker gains access to both the user's password and their recovery codes, they get two authenticated sessions per recovery code burned instead of one, or more if they batch the parallel submissions wider, materially extending the attacker's window of access compared to what the single-use guarantee implies. This vulnerability is fixed in 4.11.5 and 5.6.5.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:9833D710-90E4-4DE3-9650-056BE4E65728']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48505']}, {'type': 'cve', 'idList': ['CVE-2026-48505']}, {'type': 'euvd', 'idList': ['EUVD-2026-38392']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48505']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51391']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48505']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-48506
CVE-2026-48506 MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested arrays and maps without incrementing the reader depth or calling the configured depth checks. This bypasses MessagePackSecurity.MaximumObjectGraphDepth, the library's documented protection against deeply nested object graphs. Many generated and dynamic formatters call reader.Skip() when they encounter unknown map keys, unknown array members, ignored fields, or data that should be skipped for forward compatibility. A deeply nested value in one of these skipped positions can therefore cause unbounded recursion and an uncatchable StackOverflowException. This vulnerability is fixed in 2.5.301 and 3.1.7.
HIGH
7.50
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2026-06-22 21:17:35+03:00
2026-06-22 21:17:35+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-48506']
['CVE-2026-48506']
78405c095a322c16593d778ed6f757e1e6c6b8303da2b3bf9fea0f9203dd1cb4
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-48506', 'cvss': {'score': 7.5, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48506', 'type': 'cvelist', 'title': 'CVE-2026-48506 MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth', 'cvelist': ['CVE-2026-48506'], 'assigned': '2026-05-21T16:18:10', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-22T21:17:35', 'published': '2026-06-22T21:17:35', 'description': "MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested arrays and maps without incrementing the reader depth or calling the configured depth checks. This bypasses MessagePackSecurity.MaximumObjectGraphDepth, the library's documented protection against deeply nested object graphs. Many generated and dynamic formatters call reader.Skip() when they encounter unknown map keys, unknown array members, ignored fields, or data that should be skipped for forward compatibility. A deeply nested value in one of these skipped positions can therefore cause unbounded recursion and an uncatchable StackOverflowException. This vulnerability is fixed in 2.5.301 and 3.1.7.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:34445DE6-5B1F-46A0-8455-89E2CAE7C4E2']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48506']}, {'type': 'cve', 'idList': ['CVE-2026-48506']}, {'type': 'euvd', 'idList': ['EUVD-2026-38388']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48506']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51392']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48506']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-48509
CVE-2026-48509 MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The formatter is designed for ASP.NET Core MVC request bodies, which commonly cross an HTTP trust boundary. This insecure default can expose applications to denial-of-service attacks that MessagePackSecurity.UntrustedData is intended to mitigate, such as hash-collision attacks against dictionary-like model properties. This vulnerability is fixed in 2.5.301 and 3.1.7.
MEDIUM
6.30
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:N/VA:L/SA:N
2026-06-22 21:16:50+03:00
2026-06-22 21:16:50+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-48509']
['CVE-2026-48509']
50c5b9782780309c4b91371abae57e3f9ea380c95a31e146e355d030e32b181b
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-48509', 'cvss': {'score': 6.3, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48509', 'type': 'cvelist', 'title': 'CVE-2026-48509 MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies', 'cvelist': ['CVE-2026-48509'], 'assigned': '2026-05-21T16:18:10', 'lastseen': '2026-06-23T13:44:44', 'modified': '2026-06-22T21:16:50', 'published': '2026-06-22T21:16:50', 'description': 'MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The formatter is designed for ASP.NET Core MVC request bodies, which commonly cross an HTTP trust boundary. This insecure default can expose applications to denial-of-service attacks that MessagePackSecurity.UntrustedData is intended to mitigate, such as hash-collision attacks against dictionary-like model properties. This vulnerability is fixed in 2.5.301 and 3.1.7.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:033E4CB7-BB90-424E-99BC-26B1D1B96DF3']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48509']}, {'type': 'cve', 'idList': ['CVE-2026-48509']}, {'type': 'euvd', 'idList': ['EUVD-2026-38387']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48509']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51393']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48509']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-48510
CVE-2026-48510 MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray payloads, it reads declared uncompressed lengths from the wire and allocates output buffers based on those lengths before validating that the compressed data is valid or that the declared expansion is reasonable. A small payload can claim a very large uncompressed length and force a large allocation before LZ4 decoding begins. This vulnerability is fixed in 2.5.301 and 3.1.7.
MEDIUM
6.30
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N
2026-06-22 21:16:04+03:00
2026-06-22 21:16:04+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-48510']
['CVE-2026-48510']
2d027a0f159f5ab8e9173b55f3bddb503f40a6292368c027eb18f19badc5af31
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-48510', 'cvss': {'score': 6.3, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48510', 'type': 'cvelist', 'title': 'CVE-2026-48510 MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths', 'cvelist': ['CVE-2026-48510'], 'assigned': '2026-05-21T16:18:10', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-22T21:16:04', 'published': '2026-06-22T21:16:04', 'description': 'MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray payloads, it reads declared uncompressed lengths from the wire and allocates output buffers based on those lengths before validating that the compressed data is valid or that the declared expansion is reasonable. A small payload can claim a very large uncompressed length and force a large allocation before LZ4 decoding begins. This vulnerability is fixed in 2.5.301 and 3.1.7.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:8E68392E-0D81-4614-801C-B2D86034677E']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48510']}, {'type': 'cve', 'idList': ['CVE-2026-48510']}, {'type': 'euvd', 'idList': ['EUVD-2026-38386']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48510']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51394']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48510']}]}}, 'bulletinFamily': 'cve'}
CVE-2026-48511
CVE-2026-48511 MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary<string, object>.Add for each map entry. ExpandoObject internally maintains member names in array-like structures, so inserting many distinct keys can require repeated linear scans and array copies. For large attacker-controlled maps, this produces quadratic CPU and allocation behavior. The issue is especially surprising because ExpandoObjectResolver.Options is configured with MessagePackSecurity.UntrustedData, but collision-resistant dictionary comparers cannot protect ExpandoObject insertion internals. This vulnerability is fixed in 2.5.301 and 3.1.7.
MEDIUM
6.30
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N
2026-06-22 21:14:54+03:00
2026-06-22 21:14:54+03:00
['https://www.cve.org/CVERecord?id=CVE-2026-48511']
['CVE-2026-48511']
67aa93be9feb7fc88f6d15035bf1ffbc793b2dad30b60df200de7500645de21c
2026-06-24 06:24:34.817328+03:00
2026-06-24 06:24:34.817328+03:00
{'id': 'CVELIST:CVE-2026-48511', 'cvss': {'score': 6.3, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48511', 'type': 'cvelist', 'title': 'CVE-2026-48511 MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps', 'cvelist': ['CVE-2026-48511'], 'assigned': '2026-05-21T16:18:10', 'lastseen': '2026-06-23T15:52:48', 'modified': '2026-06-22T21:14:54', 'published': '2026-06-22T21:14:54', 'description': 'MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary<string, object>.Add for each map entry. ExpandoObject internally maintains member names in array-like structures, so inserting many distinct keys can require repeated linear scans and array copies. For large attacker-controlled maps, this produces quadratic CPU and allocation behavior. The issue is especially surprising because ExpandoObjectResolver.Options is configured with MessagePackSecurity.UntrustedData, but collision-resistant dictionary comparers cannot protect ExpandoObject insertion internals. This vulnerability is fixed in 2.5.301 and 3.1.7.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:7B279375-3AC4-4C47-BA64-133E7B7B41EC']}, {'type': 'cve', 'idList': ['CVE-2026-48511']}, {'type': 'euvd', 'idList': ['EUVD-2026-38385']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48511']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51395']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48511']}]}}, 'bulletinFamily': 'cve'}