CVE-2026-9804

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9804">https://www.tenable.com/cve/CVE-2026-9804</a></p>

2026/5/28
阅读更多

CVE-2026-7374

<p>Critical Severity</p> <h3>Description</h3> <p>A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-7374">https://www.tenable.com/cve/CVE-2026-7374</a></p>

2026/5/26
阅读更多

CVE-2026-71993

<p>Critical Severity</p> <h3>Description</h3> <p>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71993">https://www.tenable.com/cve/CVE-2026-71993</a></p>

2026/8/9
阅读更多

CVE-2026-71992

<p>Critical Severity</p> <h3>Description</h3> <p>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and obtain root privileges on the underlying system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71992">https://www.tenable.com/cve/CVE-2026-71992</a></p>

2026/8/9
阅读更多

CVE-2026-71991

<p>Critical Severity</p> <h3>Description</h3> <p>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71991">https://www.tenable.com/cve/CVE-2026-71991</a></p>

2026/8/9
阅读更多

CVE-2026-71990

<p>Critical Severity</p> <h3>Description</h3> <p>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71990">https://www.tenable.com/cve/CVE-2026-71990</a></p>

2026/8/9
阅读更多

CVE-2026-71989

<p>Critical Severity</p> <h3>Description</h3> <p>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71989">https://www.tenable.com/cve/CVE-2026-71989</a></p>

2026/8/9
阅读更多

CVE-2026-71988

<p>Critical Severity</p> <h3>Description</h3> <p>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71988">https://www.tenable.com/cve/CVE-2026-71988</a></p>

2026/8/9
阅读更多

CVE-2026-71987

<p>Critical Severity</p> <h3>Description</h3> <p>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71987">https://www.tenable.com/cve/CVE-2026-71987</a></p>

2026/8/9
阅读更多

CVE-2026-71986

<p>Critical Severity</p> <h3>Description</h3> <p>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71986">https://www.tenable.com/cve/CVE-2026-71986</a></p>

2026/8/9
阅读更多

CVE-2026-71985

<p>Critical Severity</p> <h3>Description</h3> <p>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71985">https://www.tenable.com/cve/CVE-2026-71985</a></p>

2026/8/9
阅读更多

CVE-2026-71984

<p>Critical Severity</p> <h3>Description</h3> <p>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71984">https://www.tenable.com/cve/CVE-2026-71984</a></p>

2026/8/9
阅读更多

CVE-2026-69659

<p>Medium Severity</p> <h3>Description</h3> <p>Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in decode_values/2 in lib/ash/page/keyset.ex, which base64-decodes the value and passes it to :erlang.binary_to_term/2 without bounding its size. The Erlang external term format supports zlib-compressed payloads, which the decoder inflates transparently, so a cursor of a few kilobytes can allocate tens of megabytes of heap in a single call. Ash itself only ever encodes cursors uncompressed, so the decoder accepts a term shape its encoder never produces. Concurrent requests aggregate these allocations and can terminate the node. This issue affects ash: from 1.17.0 before 3.31.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-69659">https://www.tenable.com/cve/CVE-2026-69659</a></p>

2026/8/9
阅读更多

CVE-2026-68480

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potentially leading to data leakage through speculative execution. Fixup register state as if the Safe-RET sequence executed successfully by "emulating" it, in a manner of speaking, and avoid executing a RET instruction after returning from the interrupt.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68480">https://www.tenable.com/cve/CVE-2026-68480</a></p>

2026/8/6
阅读更多

CVE-2026-64564

<p>Critical Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). For an ASCONF located through its Address Parameter by __sctp_rcv_asconf_lookup(), that cached transport corresponds to the Address Parameter, which need not be the packet's source address. sctp_process_asconf_param() rejects a DEL-IP for the packet source address (ADDIP D8, SCTP_ERROR_DEL_SRC_IP), but nothing protects asconf->transport. A single ASCONF can therefore carry, in order: [Address Parameter L] [DEL-IP L] [DEL-IP 0.0.0.0] where L differs from the source. The DEL-IP for L passes the D8 check and calls sctp_assoc_rm_peer() on the transport that asconf->transport still points at, freeing it (RCU-deferred). The following wildcard DEL-IP then reuses the now-dangling asconf->transport in sctp_assoc_set_primary() and sctp_assoc_del_nonprimary_peers(): set_primary() dereferences the freed transport (->ipaddr, ->state) and plants the dangling pointer into asoc->peer.primary_path / active_path, and del_nonprimary_peers(), keeping only the pointer that is no longer on the list, removes every real transport, leaving the association with a transport_count of 0 and primary_path/active_path pointing at freed memory. Reject a DEL-IP that targets the transport the ASCONF is being processed against, mirroring the existing source-address guard, so the wildcard branch can never reuse a freed transport.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64564">https://www.tenable.com/cve/CVE-2026-64564</a></p>

2026/8/4
阅读更多

CVE-2026-64561

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64561">https://www.tenable.com/cve/CVE-2026-64561</a></p>

2026/8/4
阅读更多

CVE-2026-62870

<p>High Severity</p> <h3>Description</h3> <p>Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62870">https://www.tenable.com/cve/CVE-2026-62870</a></p>

2026/8/4
阅读更多

CVE-2026-4878

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-4878">https://www.tenable.com/cve/CVE-2026-4878</a></p>

2026/4/9
阅读更多

CVE-2026-46579

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-46579">https://www.tenable.com/cve/CVE-2026-46579</a></p>

2026/5/29
阅读更多

CVE-2026-19364

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorconsultancycharge.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19364">https://www.tenable.com/cve/CVE-2026-19364</a></p>

2026/8/9
阅读更多

CVE-2026-19363

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is the function unwrap of the file src/handler.rs of the component Fixed Message Handler. The manipulation of the argument jwtClaims results in deserialization. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19363">https://www.tenable.com/cve/CVE-2026-19363</a></p>

2026/8/9
阅读更多

CVE-2026-19362

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of the file src/parse_token_from_header.rs of the component Authorization Header Parsing. The manipulation of the argument authorization_token leads to denial of service. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19362">https://www.tenable.com/cve/CVE-2026-19362</a></p>

2026/8/9
阅读更多

CVE-2026-19361

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be launched remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been published and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19361">https://www.tenable.com/cve/CVE-2026-19361</a></p>

2026/8/9
阅读更多

CVE-2026-19360

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19360">https://www.tenable.com/cve/CVE-2026-19360</a></p>

2026/8/9
阅读更多

CVE-2026-19359

<p>Medium Severity</p> <h3>Description</h3> <p>A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.15.0 can resolve this issue. Upgrading the affected component is advised. The project explains: "The reported IAM permission configuration is a known historical issue that was already addressed in 2024, beginning with GoldVIP version 1.13.0. The permissions were updated in subsequent releases, including version 1.15.0. In addition, we also sent a request to either update or deprecate the older release in the AWS SAR application repository."</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19359">https://www.tenable.com/cve/CVE-2026-19359</a></p>

2026/8/9
阅读更多

CVE-2026-19358

<p>Medium Severity</p> <h3>Description</h3> <p>A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was contacted early about this disclosure.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19358">https://www.tenable.com/cve/CVE-2026-19358</a></p>

2026/8/9
阅读更多

CVE-2026-19357

<p>Medium Severity</p> <h3>Description</h3> <p>A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19357">https://www.tenable.com/cve/CVE-2026-19357</a></p>

2026/8/9
阅读更多

CVE-2026-19356

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19356">https://www.tenable.com/cve/CVE-2026-19356</a></p>

2026/8/9
阅读更多

CVE-2026-19355

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19355">https://www.tenable.com/cve/CVE-2026-19355</a></p>

2026/8/9
阅读更多

CVE-2026-19354

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN Clause Handler. Performing a manipulation of the argument ids results in sql injection. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19354">https://www.tenable.com/cve/CVE-2026-19354</a></p>

2026/8/9
阅读更多

CVE-2026-19353

<p>Low Severity</p> <h3>Description</h3> <p>A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19353">https://www.tenable.com/cve/CVE-2026-19353</a></p>

2026/8/9
阅读更多

CVE-2026-19352

<p>Low Severity</p> <h3>Description</h3> <p>A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: "I'm not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn't really a LosslessCut bug." The CVSS vector reflects the high level of pre-requisites.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19352">https://www.tenable.com/cve/CVE-2026-19352</a></p>

2026/8/9
阅读更多

CVE-2026-19351

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19351">https://www.tenable.com/cve/CVE-2026-19351</a></p>

2026/8/9
阅读更多

CVE-2026-19350

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19350">https://www.tenable.com/cve/CVE-2026-19350</a></p>

2026/8/9
阅读更多

CVE-2026-19348

<p>Critical Severity</p> <h3>Description</h3> <p>A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19348">https://www.tenable.com/cve/CVE-2026-19348</a></p>

2026/8/9
阅读更多

CVE-2026-19347

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19347">https://www.tenable.com/cve/CVE-2026-19347</a></p>

2026/8/9
阅读更多

CVE-2026-19346

<p>High Severity</p> <h3>Description</h3> <p>A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19346">https://www.tenable.com/cve/CVE-2026-19346</a></p>

2026/8/9
阅读更多

CVE-2026-19345

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19345">https://www.tenable.com/cve/CVE-2026-19345</a></p>

2026/8/9
阅读更多

CVE-2026-19344

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19344">https://www.tenable.com/cve/CVE-2026-19344</a></p>

2026/8/9
阅读更多

CVE-2026-19343

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19343">https://www.tenable.com/cve/CVE-2026-19343</a></p>

2026/8/9
阅读更多

CVE-2026-19342

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public and may be used.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19342">https://www.tenable.com/cve/CVE-2026-19342</a></p>

2026/8/9
阅读更多

CVE-2026-19341

<p>High Severity</p> <h3>Description</h3> <p>A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulation of the argument EncryptionMode leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19341">https://www.tenable.com/cve/CVE-2026-19341</a></p>

2026/8/9
阅读更多

CVE-2026-19340

<p>Medium Severity</p> <h3>Description</h3> <p>A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhooks API. This manipulation of the argument url causes server-side request forgery. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19340">https://www.tenable.com/cve/CVE-2026-19340</a></p>

2026/8/9
阅读更多

CVE-2026-19339

<p>Medium Severity</p> <h3>Description</h3> <p>A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19339">https://www.tenable.com/cve/CVE-2026-19339</a></p>

2026/8/9
阅读更多

CVE-2026-19338

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried out locally.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19338">https://www.tenable.com/cve/CVE-2026-19338</a></p>

2026/8/9
阅读更多

CVE-2026-19337

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local execution. This patch is called f071d491b685011ca04e8ab8d586fc65f86bcee1. It is advisable to implement a patch to correct this issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19337">https://www.tenable.com/cve/CVE-2026-19337</a></p>

2026/8/9
阅读更多

CVE-2026-19336

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal. The attack is only possible with local access. Upgrading to version 2.2.7 is capable of addressing this issue. The patch is named 9c7a7839e690bb4543f0e7481b5740d23808e5fe. It is advisable to upgrade the affected component.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19336">https://www.tenable.com/cve/CVE-2026-19336</a></p>

2026/8/9
阅读更多

CVE-2026-19335

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the argument skillName leads to path traversal. The attack can only be performed from a local environment. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19335">https://www.tenable.com/cve/CVE-2026-19335</a></p>

2026/8/9
阅读更多

CVE-2026-19334

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/source/destination causes command injection. The attack can only be executed locally. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19334">https://www.tenable.com/cve/CVE-2026-19334</a></p>

2026/8/9
阅读更多

CVE-2026-19333

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulation of the argument schema results in command injection. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19333">https://www.tenable.com/cve/CVE-2026-19333</a></p>

2026/8/9
阅读更多

CVE-2026-19332

<p>Medium Severity</p> <h3>Description</h3> <p>A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19332">https://www.tenable.com/cve/CVE-2026-19332</a></p>

2026/8/9
阅读更多

CVE-2026-19331

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/CanvasService.ts. Such manipulation leads to path traversal. An attack has to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19331">https://www.tenable.com/cve/CVE-2026-19331</a></p>

2026/8/9
阅读更多

CVE-2026-19330

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to get_system_json/switch_memory_library of the file src/index.ts. This manipulation causes path traversal. The attack requires local access. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19330">https://www.tenable.com/cve/CVE-2026-19330</a></p>

2026/8/9
阅读更多

CVE-2026-19329

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-simple.ts of the component ask MCP Tool. The manipulation of the argument model results in command injection. The attack requires a local approach. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19329">https://www.tenable.com/cve/CVE-2026-19329</a></p>

2026/8/9
阅读更多

CVE-2026-19328

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/installSkill/updateAgentsMd/uninstallSkill of the file src/installer.ts. The manipulation of the argument workspacePath leads to path traversal. The attack needs to be performed locally. Upgrading to version 0.1.1 is recommended to address this issue. The identifier of the patch is 855b46739e0f6e8388f17f9d0066ac4298a3965d. Upgrading the affected component is recommended.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19328">https://www.tenable.com/cve/CVE-2026-19328</a></p>

2026/8/9
阅读更多

CVE-2026-19327

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession of the file src/services/enricher.ts. Executing a manipulation of the argument sessionId can lead to path traversal. The attack needs to be launched locally. This patch is called 786c9d74800e6d0858b65778f31beb71b3983a50. Applying a patch is advised to resolve this issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19327">https://www.tenable.com/cve/CVE-2026-19327</a></p>

2026/8/9
阅读更多

CVE-2026-19326

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagement.service.ts. Performing a manipulation of the argument imagePath results in path traversal. The attack must be initiated from a local position. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19326">https://www.tenable.com/cve/CVE-2026-19326</a></p>

2026/8/9
阅读更多

CVE-2026-19325

<p>Medium Severity</p> <h3>Description</h3> <p>A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. Such manipulation of the argument file_name leads to path traversal. The attack must be carried out locally. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19325">https://www.tenable.com/cve/CVE-2026-19325</a></p>

2026/8/9
阅读更多

CVE-2026-19324

<p>Medium Severity</p> <h3>Description</h3> <p>A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by this issue is the function fs.promises.readFile of the file src/server/callback-server.ts. This manipulation of the argument filepath causes path traversal. The attack is restricted to local execution. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19324">https://www.tenable.com/cve/CVE-2026-19324</a></p>

2026/8/9
阅读更多

CVE-2026-19323

<p>Medium Severity</p> <h3>Description</h3> <p>A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component analyze-projec. The manipulation of the argument projectName results in path traversal. The attack is only possible with local access. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19323">https://www.tenable.com/cve/CVE-2026-19323</a></p>

2026/8/9
阅读更多

CVE-2026-19195

<p>High Severity</p> <h3>Description</h3> <p>A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19195">https://www.tenable.com/cve/CVE-2026-19195</a></p>

2026/8/7
阅读更多

CVE-2026-19193

<p>High Severity</p> <h3>Description</h3> <p>A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19193">https://www.tenable.com/cve/CVE-2026-19193</a></p>

2026/8/7
阅读更多

CVE-2026-18651

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-18651">https://www.tenable.com/cve/CVE-2026-18651</a></p>

2026/8/3
阅读更多

CVE-2026-18603

<p>High Severity</p> <h3>Description</h3> <p>The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allowing unauthenticated users to disclose the contents of other customers' orders, as well as to clear and repopulate a logged in user's cart via a crafted link.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-18603">https://www.tenable.com/cve/CVE-2026-18603</a></p>

2026/8/9
阅读更多

CVE-2026-18473

<p>Critical Severity</p> <h3>Description</h3> <p>The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-18473">https://www.tenable.com/cve/CVE-2026-18473</a></p>

2026/8/9
阅读更多

CVE-2026-18465

<p>Critical Severity</p> <h3>Description</h3> <p>The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary existing local PHP files on the server.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-18465">https://www.tenable.com/cve/CVE-2026-18465</a></p>

2026/8/9
阅读更多

CVE-2026-18464

<p>High Severity</p> <h3>Description</h3> <p>The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-18464">https://www.tenable.com/cve/CVE-2026-18464</a></p>

2026/8/9
阅读更多

CVE-2026-18357

<p>Medium Severity</p> <h3>Description</h3> <p>The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and order dates.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-18357">https://www.tenable.com/cve/CVE-2026-18357</a></p>

2026/8/9
阅读更多

CVE-2026-18037

<p>Medium Severity</p> <h3>Description</h3> <p>The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-18037">https://www.tenable.com/cve/CVE-2026-18037</a></p>

2026/8/9
阅读更多

CVE-2026-18032

<p>High Severity</p> <h3>Description</h3> <p>The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, allowing unauthenticated attackers to read arbitrary columns of the database table the affected front-end form is bound to, including user password hashes where that table is the users table.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-18032">https://www.tenable.com/cve/CVE-2026-18032</a></p>

2026/8/9
阅读更多

CVE-2026-1784

<p>High Severity</p> <h3>Description</h3> <p>The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-1784">https://www.tenable.com/cve/CVE-2026-1784</a></p>

2026/6/2
阅读更多

CVE-2026-17510

<p>High Severity</p> <h3>Description</h3> <p>Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its declared byte length with `Renew(*attribute, length, char)`. A zero length attribute makes that a zero size reallocation, which Perl implements as a free returning NULL, so the buffer pointer becomes NULL, the following `strncpy` copies nothing, and the caller dereferences NULL in the `strlen()` it passes to `newSVpvn()`. A zero length BMPSTRING is even length, so the ASN.1 decoder accepts it and the value reaches this code. The UTF8STRING, OCTET STRING and BIT STRING arms size on `length + 1` or `length * 4 + 1` and are unaffected. Any caller that passes an untrusted PKCS#12 file to info_as_hash() can crash the process. info() prints attribute values directly without sizing a buffer and is unaffected.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-17510">https://www.tenable.com/cve/CVE-2026-17510</a></p>

2026/8/9
阅读更多

CVE-2026-17107

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-17107">https://www.tenable.com/cve/CVE-2026-17107</a></p>

2026/7/24
阅读更多

CVE-2026-17044

<p>Critical Severity</p> <h3>Description</h3> <p>The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-17044">https://www.tenable.com/cve/CVE-2026-17044</a></p>

2026/8/9
阅读更多

CVE-2026-17017

<p>High Severity</p> <h3>Description</h3> <p>The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-17017">https://www.tenable.com/cve/CVE-2026-17017</a></p>

2026/8/9
阅读更多

CVE-2026-17014

<p>High Severity</p> <h3>Description</h3> <p>The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-17014">https://www.tenable.com/cve/CVE-2026-17014</a></p>

2026/8/9
阅读更多

CVE-2026-17011

<p>High Severity</p> <h3>Description</h3> <p>The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-17011">https://www.tenable.com/cve/CVE-2026-17011</a></p>

2026/8/9
阅读更多

CVE-2026-16992

<p>Medium Severity</p> <h3>Description</h3> <p>The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16992">https://www.tenable.com/cve/CVE-2026-16992</a></p>

2026/8/9
阅读更多

CVE-2026-16988

<p>Medium Severity</p> <h3>Description</h3> <p>The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16988">https://www.tenable.com/cve/CVE-2026-16988</a></p>

2026/8/9
阅读更多

CVE-2026-16965

<p>Medium Severity</p> <h3>Description</h3> <p>The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16965">https://www.tenable.com/cve/CVE-2026-16965</a></p>

2026/8/9
阅读更多

CVE-2026-16957

<p>Medium Severity</p> <h3>Description</h3> <p>The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own, including password-protected posts and posts of non-public post types.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16957">https://www.tenable.com/cve/CVE-2026-16957</a></p>

2026/8/9
阅读更多

CVE-2026-16242

<p>Critical Severity</p> <h3>Description</h3> <p>A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16242">https://www.tenable.com/cve/CVE-2026-16242</a></p>

2026/7/20
阅读更多

CVE-2026-16093

<p>Medium Severity</p> <h3>Description</h3> <p>Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16093">https://www.tenable.com/cve/CVE-2026-16093</a></p>

2026/7/17
阅读更多

CVE-2026-1609

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-1609">https://www.tenable.com/cve/CVE-2026-1609</a></p>

2026/7/16
阅读更多

CVE-2026-16089

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16089">https://www.tenable.com/cve/CVE-2026-16089</a></p>

2026/7/17
阅读更多

CVE-2026-16072

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16072">https://www.tenable.com/cve/CVE-2026-16072</a></p>

2026/7/17
阅读更多

CVE-2026-16032

<p>Critical Severity</p> <h3>Description</h3> <p>The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the affected dashboard page.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16032">https://www.tenable.com/cve/CVE-2026-16032</a></p>

2026/8/9
阅读更多

CVE-2026-15945

<p>Low Severity</p> <h3>Description</h3> <p>A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-15945">https://www.tenable.com/cve/CVE-2026-15945</a></p>

2026/7/16
阅读更多

CVE-2026-15943

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-15943">https://www.tenable.com/cve/CVE-2026-15943</a></p>

2026/7/17
阅读更多

CVE-2026-15534

<p>High Severity</p> <h3>Description</h3> <p>Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it. A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-15534">https://www.tenable.com/cve/CVE-2026-15534</a></p>

2026/8/9
阅读更多

CVE-2026-15038

<p>Critical Severity</p> <h3>Description</h3> <p>The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-15038">https://www.tenable.com/cve/CVE-2026-15038</a></p>

2026/8/9
阅读更多

CVE-2026-11368

<p>Medium Severity</p> <h3>Description</h3> <p>The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last reference is dropped, its net-buf destroy callback defers the completion handling to the system workqueue (att_tx_destroy -> att_tx_destroy_work_handler -> att_on_sent_cb -> bt_att_sent), where bt_att_sent dereferences the channel and its ATT context (sys_slist_get(&att->reqs)). When a peer disconnects while an ATT PDU (a server notification/indication or any response) is still in flight in the controller TX path, L2CAP tears the channel down in l2cap_chan_del(): it runs the disconnected callback and then the released callback (bt_att_released), which frees the channel slab slot. Because the in-flight buffer is held by the connection TX path rather than the channel's own queue, its deferred destroy work can run after the channel has been freed. The att_on_sent_cb guard intended to drop the stale callback itself dereferences meta->att_chan, which is now a dangling pointer into a freed (and possibly reused) slab slot. A remote peer with an ATT connection can drive this by disconnecting during routine ATT traffic; no pairing or user interaction is required to reach the ATT bearer. The result is a use-after-free read/write of freed channel memory, reliably crashing the Bluetooth host (denial of service) and, because the channel slab slot may be reused, potentially corrupting live memory. The fix makes bt_att_released() NULL the att_chan field of every tx_meta_data_storage[] entry still referencing the channel before freeing it, so the deferred guard observes a NULL pointer and drops the callback. Teardown and the destroy work both run on the cooperative system workqueue, so the array update is serialized and needs no lock.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-11368">https://www.tenable.com/cve/CVE-2026-11368</a></p>

2026/8/4
阅读更多

CVE-2026-10849

<p>High Severity</p> <h3>Description</h3> <p>The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. When the full response has arrived, the code writes response_data[downloaded_size] = '\0' — and whenever the accumulated body length equals the allocation, that terminator lands one byte past the end of the heap object (a heap-based out-of-bounds write, CWE-122 / CWE-787). The body length and fragmentation are taken directly from the parsed HTTP response (rsp->body_frag_start / rsp->body_frag_len) and are fully controlled by the remote hawkBit server, which chooses its own response length. The precise trigger depends on how the buffer grows, and both forms are remotely reachable. Since v4.0.0 the reallocation is sized to exactly downloaded_size + body_len, so any response body larger than the 1100-byte initial buffer makes the out-of-bounds write deterministic; such response sizes are normal for hawkBit deployment metadata. Before v4.0.0 the buffer grew by doubling and the growth check ((downloaded_size + body_len) > response_buffer_size) is false at equality, so a response body whose length is exactly the current allocation — 1100 bytes with the default initial buffer — skips the reallocation entirely and writes the terminator at response_data[1100] of an 1100-byte object. The HTTP length-mismatch check does not catch this, because the declared and received lengths genuinely agree. Either form is reachable by a malicious, compromised, or man-in-the-middle update server (TLS is optional and, when enabled, does not protect against a hostile server), with no authentication of response content and no client-side length cap protecting the write. The out-of-bounds write is a fixed single NUL byte immediately following the allocation, corrupting adjacent allocator metadata or the next allocation. The practical impact is heap corruption leading to denial of service (fault on a subsequent allocation or free), with the bounded, allocator-dependent possibility of further corruption. The fix sizes the buffer to the body length plus one and copies with memcpy, ensuring the terminator always lands within the allocation.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-10849">https://www.tenable.com/cve/CVE-2026-10849</a></p>

2026/8/3
阅读更多

CVE-2026-10595

<p>High Severity</p> <h3>Description</h3> <p>A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-encoded dot-dot sequences (`%2e%2e`) bypass Starlette's built-in path normalization and are resolved by Python's `pathlib`, allowing an unauthenticated attacker to read arbitrary files on the server. This issue has been resolved in version 3.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-10595">https://www.tenable.com/cve/CVE-2026-10595</a></p>

2026/8/9
阅读更多

CVE-2025-7425

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-7425">https://www.tenable.com/cve/CVE-2025-7425</a></p>

2025/7/10
阅读更多

CVE-2025-7195

<p>Medium Severity</p> <h3>Description</h3> <p>Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images. In affected images, the /etc/passwd file is created during build time with group-writable permissions and a group ownership of root (gid=0). An attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-7195">https://www.tenable.com/cve/CVE-2025-7195</a></p>

2025/8/7
阅读更多

CVE-2025-6020

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-6020">https://www.tenable.com/cve/CVE-2025-6020</a></p>

2025/6/17
阅读更多

CVE-2025-5914

<p>High Severity</p> <h3>Description</h3> <p>A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-5914">https://www.tenable.com/cve/CVE-2025-5914</a></p>

2025/6/9
阅读更多

CVE-2025-5318

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-5318">https://www.tenable.com/cve/CVE-2025-5318</a></p>

2025/6/24
阅读更多

CVE-2025-5278

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-5278">https://www.tenable.com/cve/CVE-2025-5278</a></p>

2025/5/27
阅读更多

CVE-2025-4373

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-4373">https://www.tenable.com/cve/CVE-2025-4373</a></p>

2025/5/6
阅读更多

CVE-2025-2842

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole. This can be exploited if a user has 'create' permissions on TempoStack and 'get' permissions on Secret in a namespace (for example, a user has ClusterAdmin permissions for a specific namespace), as the user can read the token of the Tempo service account and therefore has access to see all cluster metrics.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-2842">https://www.tenable.com/cve/CVE-2025-2842</a></p>

2025/4/2
阅读更多

CVE-2025-2786

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-2786">https://www.tenable.com/cve/CVE-2025-2786</a></p>

2025/4/2
阅读更多

CVE-2024-6832

<p>High Severity</p> <h3>Description</h3> <p>The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the lockout mechanism for users within active stores. When the account locking mechanism is bypassed due to the inaccessibility of secondary user stores, users in accessible user stores are left vulnerable to brute force attacks. A malicious actor can exploit this by attempting numerous invalid password combinations against a user account without the expected account lockout consequence.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-6832">https://www.tenable.com/cve/CVE-2024-6832</a></p>

2026/8/6
阅读更多

CVE-2024-45497

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from private repositories. The mount is not read-only, which allows the attacker to overwrite it. By modifying the config.json file, the attacker can cause a denial of service by preventing the node from pulling new images and potentially exfiltrating sensitive secrets. This flaw impacts the availability of services dependent on image pulls and exposes sensitive information to unauthorized parties.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-45497">https://www.tenable.com/cve/CVE-2024-45497</a></p>

2024/12/31
阅读更多

CVE-2024-11831

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-11831">https://www.tenable.com/cve/CVE-2024-11831</a></p>

2025/2/10
阅读更多

CVE-2024-10302

<p>Medium Severity</p> <h3>Description</h3> <p>The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidated input into user claims can lead to various security risks. Malicious or malformed data injected during signup could be processed by other parts of the application, potentially enabling attacks such as content manipulation, redirection, user interface inconsistencies, unauthorized actions, and data exposure. The actual impact depends on how the compromised data is consumed and the privileges associated with the affected users.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-10302">https://www.tenable.com/cve/CVE-2024-10302</a></p>

2026/8/6
阅读更多

CVE-2026-8798

<p>High Severity</p> <h3>Description</h3> <p>In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound. RDSEED and RDRAND report failure through their carry flag, and the JNI seeding routine spun re-issuing the instruction for as long as that flag stayed clear, so a persistent failure of the on-chip entropy source - whether from a hardware fault, from the underlying DRBG being exhausted by contention across many cores, or from a hypervisor that does not provide the instruction - left the calling thread looping indefinitely inside the JNI call, where it could be neither interrupted nor timed out. Any operation drawing from the native entropy source could therefore hang, denying service to the application. The retry loops are now bounded (200 attempts for RDSEED and 20 for RDRAND, twice the baselines given in Intel's Digital Random Number Generator software implementation guide), pausing between attempts and, on exhaustion, clearing any partially written buffer and throwing rather than continuing to spin. The clear is performed by an un-elidable memzero, which uses a volatile pointer and an assembly memory barrier so that a compiler cannot optimise the erase away as a dead store. Bouncy Castle for Java (bcprov) is not affected, as it has no native entropy source; the 1.0.X and 2.0.X FIPS series are not affected.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-8798">https://www.tenable.com/cve/CVE-2026-8798</a></p>

2026/8/8
阅读更多

CVE-2026-8325

<p>High Severity</p> <h3>Description</h3> <p>A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-8325">https://www.tenable.com/cve/CVE-2026-8325</a></p>

2026/8/6
阅读更多

CVE-2026-8037

<p>Critical Severity</p> <h3>Description</h3> <p>OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-8037">https://www.tenable.com/cve/CVE-2026-8037</a></p>

2026/6/4
阅读更多

CVE-2026-7867

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-7867">https://www.tenable.com/cve/CVE-2026-7867</a></p>

2026/8/6
阅读更多

CVE-2026-71983

<p>Critical Severity</p> <h3>Description</h3> <p>MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71983">https://www.tenable.com/cve/CVE-2026-71983</a></p>

2026/8/8
阅读更多

CVE-2026-71958

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71958">https://www.tenable.com/cve/CVE-2026-71958</a></p>

2026/8/8
阅读更多

CVE-2026-71957

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71957">https://www.tenable.com/cve/CVE-2026-71957</a></p>

2026/8/8
阅读更多

CVE-2026-71956

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71956">https://www.tenable.com/cve/CVE-2026-71956</a></p>

2026/8/8
阅读更多

CVE-2026-71955

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71955">https://www.tenable.com/cve/CVE-2026-71955</a></p>

2026/8/8
阅读更多

CVE-2026-71954

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71954">https://www.tenable.com/cve/CVE-2026-71954</a></p>

2026/8/8
阅读更多

CVE-2026-71953

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71953">https://www.tenable.com/cve/CVE-2026-71953</a></p>

2026/8/8
阅读更多

CVE-2026-71952

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71952">https://www.tenable.com/cve/CVE-2026-71952</a></p>

2026/8/8
阅读更多

CVE-2026-71951

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71951">https://www.tenable.com/cve/CVE-2026-71951</a></p>

2026/8/8
阅读更多

CVE-2026-71950

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71950">https://www.tenable.com/cve/CVE-2026-71950</a></p>

2026/8/8
阅读更多

CVE-2026-71949

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71949">https://www.tenable.com/cve/CVE-2026-71949</a></p>

2026/8/8
阅读更多

CVE-2026-71948

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71948">https://www.tenable.com/cve/CVE-2026-71948</a></p>

2026/8/8
阅读更多

CVE-2026-71947

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71947">https://www.tenable.com/cve/CVE-2026-71947</a></p>

2026/8/8
阅读更多

CVE-2026-71946

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71946">https://www.tenable.com/cve/CVE-2026-71946</a></p>

2026/8/8
阅读更多

CVE-2026-71945

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71945">https://www.tenable.com/cve/CVE-2026-71945</a></p>

2026/8/8
阅读更多

CVE-2026-71944

<p>Critical Severity</p> <h3>Description</h3> <p>D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71944">https://www.tenable.com/cve/CVE-2026-71944</a></p>

2026/8/8
阅读更多

CVE-2026-71851

<p>Critical Severity</p> <h3>Description</h3> <p>crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptographically secure source. This generator was introduced in version 3.1.2-4 and remained present in nearly every 3.x release. Nominal requests for 128 or 256 bits of entropy through this function produce effective search spaces of approximately 2 to the 39th and 2 to the 47th possibilities, small enough to enumerate on commodity hardware. Downstream wallet applications that used CryptoJS.lib.WordArray.random() as the entropy source for BIP39 recovery phrases are affected, and an attacker who enumerates the reduced output space can recover the resulting private keys and control the associated funds. This issue is fixed in version 4.0.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71851">https://www.tenable.com/cve/CVE-2026-71851</a></p>

2026/8/7
阅读更多

CVE-2026-71848

<p>Medium Severity</p> <h3>Description</h3> <p>Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen separated subtags. To implement progressive language tag truncation, normalizeLanguage() repeatedly calls parts.slice(0, i).join('-') for every possible prefix, so the total amount of string processing grows quadratically with the number of subtags. Language values may come from a query parameter, cookie, Accept-Language header, or URL path, depending on the detector configuration, and the default detector order enables query string, cookie, and header detection, so applications using languageDetector() may expose this processing to unauthenticated requests. An attacker may repeatedly send requests containing long, hyphen separated language tags, causing excessive CPU consumption and preventing unrelated requests from being processed. This issue is fixed in version 4.12.34.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71848">https://www.tenable.com/cve/CVE-2026-71848</a></p>

2026/8/7
阅读更多

CVE-2026-7163

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. The credentials download endpoint (GET /v2/clusters/{cluster_id}/credentials, which returns the kubeadmin password) and the kubeconfig download endpoint are operational in AUTH_TYPE=local mode, the only authentication mode available in on-premises ACM/MCE hub deployments. The local authenticator unconditionally grants full administrative access to any request bearing a valid JWT, with no per-endpoint restrictions. A valid local JWT is embedded as a plaintext query parameter in InfraEnvStatus.ISODownloadURL and is readable by any user who has get rights on an InfraEnv object in their own namespace. The affected components ship as part of Multicluster Engine (MCE). The Red Hat Advanced Cluster Management (ACM) deployments that include MCE are equally affected. This issue does not affect the hosted SaaS offering (console.redhat.com), which uses a different authentication mode. Successful exploitation gives the attacker the kubeadmin password and kubeconfig for any OpenShift cluster provisioned through the affected hub, granting unrestricted root-level administrative access to those spoke clusters.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-7163">https://www.tenable.com/cve/CVE-2026-7163</a></p>

2026/4/30
阅读更多

CVE-2026-71560

<p>Critical Severity</p> <h3>Description</h3> <p>Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71560">https://www.tenable.com/cve/CVE-2026-71560</a></p>

2026/8/7
阅读更多

CVE-2026-71559

<p>High Severity</p> <h3>Description</h3> <p>Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0. Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71559">https://www.tenable.com/cve/CVE-2026-71559</a></p>

2026/8/7
阅读更多

CVE-2026-71558

<p>Critical Severity</p> <h3>Description</h3> <p>Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71558">https://www.tenable.com/cve/CVE-2026-71558</a></p>

2026/8/7
阅读更多

CVE-2026-71554

<p>Medium Severity</p> <h3>Description</h3> <p>h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, providing a request smuggling primitive. This issue is fixed in version 4.4.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71554">https://www.tenable.com/cve/CVE-2026-71554</a></p>

2026/8/6
阅读更多

CVE-2026-71502

<p>Medium Severity</p> <h3>Description</h3> <p>CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template expression delimiters in server-rendered user-controlled data. An unauthenticated attacker can create a public conversion whose name or description contains a malicious Vue expression using the application's configured [[ ... ]] delimiters. User profile names may provide an additional injection vector. Although Jinja HTML escaping is applied, the resulting value is subsequently included in a DOM region compiled by Vue. Vue interprets the attacker-controlled value as a template expression rather than ordinary text. By accessing the JavaScript Function constructor from within the expression, an attacker can execute arbitrary JavaScript in the security context of the CTI-Transmute origin. The application's nonce-based Content Security Policy does not prevent exploitation because the Vue runtime compiler requires the unsafe-eval policy exception. The malicious payload is stored by the application and executed whenever another user opens an affected page, such as the public conversion detail page. The victim may be a normal user or an administrator. Successful exploitation could allow the attacker to: * Access data available to the victim through the application. * Extract API keys, tokens, or other sensitive information exposed to the page. * Perform authenticated actions using the victim's session. * Modify conversions or other application data. * Escalate the impact by targeting an administrator. A demonstrated payload can use [].constructor.constructor(...) to obtain the JavaScript Function constructor and execute arbitrary code. The regression tests also show that a short first-stage payload could retrieve an uncapped conversion description and evaluate a larger second-stage payload. The patch addresses the vulnerability by registering a global Jinja finalize hook that inserts a zero-width Unicode word joiner inside every Vue delimiter found in server-rendered values. This prevents Vue from recognizing the values as template expressions while preserving their visible representation.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71502">https://www.tenable.com/cve/CVE-2026-71502</a></p>

2026/8/8
阅读更多

CVE-2026-71476

<p>High Severity</p> <h3>Description</h3> <p>Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malicious or on-path (MITM) remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations on the machine running Nx, which can be escalated to remote code execution. Nx's default local cache and Nx Cloud are not affected; only workspaces configured to use a self-hosted remote cache are affected. This issue is fixed in versions 22.7.7 and 23.0.2.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71476">https://www.tenable.com/cve/CVE-2026-71476</a></p>

2026/8/6
阅读更多

CVE-2026-71435

<p>Medium Severity</p> <h3>Description</h3> <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification emails sent to the configured recipients. This issue is fixed in versions 5.74.3 and 6.24.2.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71435">https://www.tenable.com/cve/CVE-2026-71435</a></p>

2026/8/6
阅读更多

CVE-2026-71326

<p>Low Severity</p> <h3>Description</h3> <p>Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71326">https://www.tenable.com/cve/CVE-2026-71326</a></p>

2026/8/6
阅读更多

CVE-2026-70646

<p>High Severity</p> <h3>Description</h3> <p>aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON payloads that will ultimately be rejected, leading to unnecessary CPU and memory consumption. Version 3.0.7 fixes the issue. Some workarounds are available. Restrict request body size at the reverse proxy or web framework, rate-limit webhook endpoints, and/or reject oversized requests before JSON parsing.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70646">https://www.tenable.com/cve/CVE-2026-70646</a></p>

2026/8/6
阅读更多

CVE-2026-70636

<p>High Severity</p> <h3>Description</h3> <p>Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to bypass all authentication and authorization checks, triggering unauthorized OAuth token rotation against credentials belonging to any workspace and potentially disrupting dependent OAuth integrations. This is a bypass of CVE-2026-41273.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70636">https://www.tenable.com/cve/CVE-2026-70636</a></p>

2026/8/6
阅读更多

CVE-2026-70631

<p>Medium Severity</p> <h3>Description</h3> <p>FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70631">https://www.tenable.com/cve/CVE-2026-70631</a></p>

2026/8/6
阅读更多

CVE-2026-70558

<p>Critical Severity</p> <h3>Description</h3> <p>Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard is a header equality check against a dinkyToken value whose default (efda1551-7958-4e0f-80a8-dfd107df3e38) is hardcoded in source and shipped to every deployment. Anyone who can reach Dinky's HTTP port (8888 by default) and supplies the hardcoded token can write arbitrary files as the Dinky service account. The default Docker image runs on 8888 with no proxy or authentication and chmod 777 on /opt/dinky, so the application's own classpath, launch scripts, and static assets are writable. Demonstrated impact: overwriting /opt/dinky/config/static/index.html served attacker JavaScript to admin browsers immediately, and writing /opt/dinky/org/dinky/Dinky.class executed attacker code as the Dinky service account at the next JVM start via a classpath-shadow launched by script/bin/auto.sh. Writes are uid 9999 (flink), not root, so /etc, /root, /home, and /usr are refused. Affects Dinky v1.2.5 (the current release) and the development branch, where the code is byte-identical.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70558">https://www.tenable.com/cve/CVE-2026-70558</a></p>

2026/8/6
阅读更多

CVE-2026-68772

<p>High Severity</p> <h3>Description</h3> <p>ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file with a crafted cloudpickle payload containing a malicious __reduce__ method, which executes arbitrary system commands when any user or pipeline materializes the artifact through the unsanitized cloudpickle.load() call in cloudpickle_materializer.py.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68772">https://www.tenable.com/cve/CVE-2026-68772</a></p>

2026/8/7
阅读更多

CVE-2026-68082

<p>Medium Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cls_lock_client.c contains two bare decode operations that allow a malicious or compromised OSD to trigger slab-out-of-bounds reads: 1. ceph_decode_32(p) at the num_lockers field has no preceding bounds check. ceph_start_decoding() accepts struct_len=0 as valid -- the internal ceph_decode_need(p, end, 0, bad) always passes -- so when an OSD sends struct_len=0, ceph_start_decoding() returns success with p == end. The immediately following bare ceph_decode_32(p) then reads 4 bytes past the validated buffer boundary. The garbage value is passed directly to kzalloc_objs() as the locker count. The sibling function decode_watchers() in osd_client.c already uses ceph_decode_32_safe() after its own ceph_start_decoding() call. decode_lockers() was the only site using the bare variant. 2. ceph_decode_8(p) after the decode_locker() loop has no preceding bounds check. If an OSD crafts num_lockers such that the loop advances p exactly to end, the subsequent bare ceph_decode_8(p) reads one byte past the validated buffer boundary. The result is passed directly into *type, which is used as a lock type discriminator by callers, giving an OSD-controlled one-byte OOB read with direct influence over the lock type field. Fix both by replacing bare operations with their safe variants: ceph_decode_32(p) -> ceph_decode_32_safe(p, end, *num_lockers, err_inval) ceph_decode_8(p) -> ceph_decode_8_safe(p, end, *type, err_free_lockers) The goto targets differ intentionally: err_inval: is a new label returning -EINVAL directly. It is used for the pre-allocation failure path where *lockers is not yet allocated and must not be passed to ceph_free_lockers(). err_free_lockers: is the existing label. It is used for the post-allocation failure path where *lockers is allocated and must be freed. ret is set to -EINVAL before ceph_decode_8_safe() so that err_free_lockers returns the correct error code on bounds violation. Without this, err_free_lockers would return a stale ret value (0 from the successful decode_locker() loop), silently swallowing the error. -EINVAL is correct for both failure paths. The data received from the OSD is structurally malformed. -ENOMEM would misrepresent the failure class to callers and to stable@ backporters triaging error paths. Attacker model: a malicious or compromised OSD in a multi-tenant Ceph deployment can trigger this against any kernel client that issues the lock.get_info class method (e.g. during RBD exclusive lock acquisition). [ idryomov: trim changelog, formatting ]</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68082">https://www.tenable.com/cve/CVE-2026-68082</a></p>

2026/8/8
阅读更多

CVE-2026-68081

<p>Medium Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state Put all vmcs12 pages if KVM synthesizes a nested VM-Exit due to invalid guest while emulating VMLAUNCH or VMRESUME. The invalid guest state path doesn't use nested_vmx_vmexit() as that API is intended to be used if and only if L2 is active, and the open coded equivalent neglects to put the vmcs12 pages. Failure to put the vmcs12 pages leaks any pinned pages (and/or mappings) if L1 retries VMLAUNCH/VMRESUME. Note, the !from_vmenter scenario doesn't suffer the same problem, as vmx_get_nested_state_pages() only gets/pins/maps the vmcs12 pages if L2 is active, i.e. if a "full" VM-Exit is guaranteed before KVM will retry getting vmcs12 pages.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68081">https://www.tenable.com/cve/CVE-2026-68081</a></p>

2026/8/8
阅读更多

CVE-2026-67620

<p>Medium Severity</p> <h3>Description</h3> <p>Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services. Attackers can send requests to the fetch-links API endpoint with a crafted URL parameter, bypassing deny-list validation including redirect-based bypasses, to reach instance metadata services and expose instance identity data and role credentials on Oracle Cloud Infrastructure or Alibaba Cloud deployments, with unauthenticated access possible when URL-fetching nodes exist in public chatflows.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67620">https://www.tenable.com/cve/CVE-2026-67620</a></p>

2026/8/8
阅读更多

CVE-2026-66707

<p>High Severity</p> <h3>Description</h3> <p>Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66707">https://www.tenable.com/cve/CVE-2026-66707</a></p>

2026/8/6
阅读更多

CVE-2026-66701

<p>Medium Severity</p> <h3>Description</h3> <p>Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66701">https://www.tenable.com/cve/CVE-2026-66701</a></p>

2026/8/6
阅读更多

CVE-2026-66692

<p>Medium Severity</p> <h3>Description</h3> <p>Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66692">https://www.tenable.com/cve/CVE-2026-66692</a></p>

2026/8/6
阅读更多

CVE-2026-66684

<p>Medium Severity</p> <h3>Description</h3> <p>Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66684">https://www.tenable.com/cve/CVE-2026-66684</a></p>

2026/8/6
阅读更多

CVE-2026-66664

<p>High Severity</p> <h3>Description</h3> <p>Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66664">https://www.tenable.com/cve/CVE-2026-66664</a></p>

2026/8/6
阅读更多

CVE-2026-66494

<p>High Severity</p> <h3>Description</h3> <p>Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically..</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66494">https://www.tenable.com/cve/CVE-2026-66494</a></p>

2026/8/7
阅读更多

CVE-2026-66452

<p>Medium Severity</p> <h3>Description</h3> <p>Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66452">https://www.tenable.com/cve/CVE-2026-66452</a></p>

2026/8/6
阅读更多

CVE-2026-66425

<p>Medium Severity</p> <h3>Description</h3> <p>Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66425">https://www.tenable.com/cve/CVE-2026-66425</a></p>

2026/8/6
阅读更多

CVE-2026-66059

<p>Medium Severity</p> <h3>Description</h3> <p>Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66059">https://www.tenable.com/cve/CVE-2026-66059</a></p>

2026/8/7
阅读更多

CVE-2026-6540

<p>High Severity</p> <h3>Description</h3> <p>Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request under the permitted prefix while the downstream workload or a fronting proxy normalizes the path and serves the restricted endpoint. An attacker with network access and no special RBAC can potentially reach HTTP endpoints the policy was intended to restrict.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-6540">https://www.tenable.com/cve/CVE-2026-6540</a></p>

2026/7/30
阅读更多

CVE-2026-64677

<p>Medium Severity</p> <h3>Description</h3> <p>Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious websites combined with an origin-check bypass, to read local files through directory traversal. This issue is fixed in version 25.09.3.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64677">https://www.tenable.com/cve/CVE-2026-64677</a></p>

2026/8/6
阅读更多

CVE-2026-64655

<p>Low Severity</p> <h3>Description</h3> <p>GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow flag values without escaping regex metacharacters, so a user-supplied repository or workflow name is treated as a regular expression rather than a literal string. Because GitHub permits characters such as `.` in organization, repository, and workflow path names and `.` is a regex wildcard, an attacker can register a lookalike name (for example github/artifact.attestations-workflows) that satisfies a matcher intended for a different trusted signer (github/artifact-attestations-workflows), bypassing the intended Sigstore attestation verification. Exploitation requires the attacker to create a plausible lookalike repository and produce valid attestations from it, which could undermine supply chain verification for CI/CD pipelines or policy gates that pin trust to a specific signing workflow. This issue is fixed in version 2.97.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64655">https://www.tenable.com/cve/CVE-2026-64655</a></p>

2026/8/6
阅读更多

CVE-2026-64601

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission In capture_urb_complete(), usb_anchor_urb() is called on every completion callback, but the URB is already anchored from the initial submission in tascam_trigger_start(). Each redundant call corrupts the anchor's doubly-linked list and inflates the URB refcount. When usb_kill_anchored_urbs() traverses the list during stream stop / suspend / disconnect, the corrupted list leads to use-after-free. Remove the redundant usb_anchor_urb() from the resubmit path.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64601">https://www.tenable.com/cve/CVE-2026-64601</a></p>

2026/8/6
阅读更多

CVE-2026-64599

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double cleanup in meson_crypto_probe() When meson_allocate_chanlist() fails after a partial allocation, it already unwinds the allocated chanlist state through its local error path. meson_crypto_probe() then jump to error_flow and calls meson_free_chanlist() again, causing the same per-flow resources to be torn down twice. In the reproduced failure path, the second teardown re-entered crypto_engine_exit() on an already destroyed worker and KASAN reported a slab-use-after-free in kthread_destroy_worker(). Prevent double-free by handling partial allocation failures locally within meson_allocate_chanlist() and skipping the outer cleanup path. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. The bug was reproduced in a QEMU x86_64 guest booted with KASAN on v7.1, using the reproducer under tools/testing/meson_crypto_probe. The reproducer forces the second dma_alloc_attrs() call in the gxl-crypto probe path to return NULL, making meson_allocate_chanlist() fail after partial initialization. On the unpatched kernel this reliably triggered a slab-use-after-free. With this fix applied, the same reproducer no longer emits any KASAN report and the probe fails cleanly with -ENOMEM. ================================================================== BUG: KASAN: slab-use-after-free in kthread_destroy_worker+0xb2/0xd0 Read of size 8 at addr ff1100010c057a68 by task insmod/265 CPU: 1 UID: 0 PID: 265 Comm: insmod Tainted: G O 7.1.0-rc2-00376-g810af9adc907-dirty #10 PREEMPT(lazy) Tainted: [O]=OOT_MODULE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0x68/0xa0 print_report+0xcb/0x5e0 ? __virt_addr_valid+0x21d/0x3f0 ? kthread_destroy_worker+0xb2/0xd0 ? kthread_destroy_worker+0xb2/0xd0 kasan_report+0xca/0x100 ? kthread_destroy_worker+0xb2/0xd0 kthread_destroy_worker+0xb2/0xd0 meson_crypto_probe+0x4d0/0xc10 [amlogic_gxl_crypto] platform_probe+0x99/0x140 really_probe+0x1c6/0x6a0 ? __pfx___device_attach_driver+0x10/0x10 __driver_probe_device+0x248/0x310 ? acpi_driver_match_device+0xb0/0x100 driver_probe_device+0x48/0x210 ? __pfx___device_attach_driver+0x10/0x10 __device_attach_driver+0x160/0x320 bus_for_each_drv+0x104/0x190 ? __pfx_bus_for_each_drv+0x10/0x10 ? _raw_spin_unlock_irqrestore+0x2c/0x50 __device_attach+0x19d/0x3b0 ? __pfx___device_attach+0x10/0x10 ? do_raw_spin_unlock+0x53/0x220 device_initial_probe+0x78/0xa0 bus_probe_device+0x5b/0x130 device_add+0xcfd/0x1430 ? __pfx_device_add+0x10/0x10 ? insert_resource+0x34/0x50 ? lock_release+0xc9/0x290 platform_device_add+0x24e/0x590 ? __pfx_meson_crypto_probe_repro_init+0x10/0x10 [meson_crypto_probe_repro] meson_crypto_probe_repro_init+0x330/0xff0 [meson_crypto_probe_repro] do_one_initcall+0xc0/0x450 ? __pfx_do_one_initcall+0x10/0x10 ? _raw_spin_unlock_irqrestore+0x2c/0x50 ? __create_object+0x59/0x80 ? kasan_unpoison+0x27/0x60 do_init_module+0x27b/0x7d0 ? __pfx_do_init_module+0x10/0x10 ? kasan_quarantine_put+0x84/0x1d0 ? kfree+0x32c/0x510 ? load_module+0x561e/0x5ff0 load_module+0x54fe/0x5ff0 ? __pfx_load_module+0x10/0x10 ? security_file_permission+0x20/0x40 ? kernel_read_file+0x23d/0x6e0 ? mmap_region+0x235/0x4a0 ? __pfx_kernel_read_file+0x10/0x10 ? __file_has_perm+0x2c0/0x3e0 init_module_from_file+0x158/0x180 ? __pfx_init_module_from_file+0x10/0x10 ? __lock_acquire+0x45a/0x1ba0 ? idempotent_init_module+0x315/0x610 ? lock_release+0xc9/0x290 ? lock ---truncated---</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64599">https://www.tenable.com/cve/CVE-2026-64599</a></p>

2026/8/6
阅读更多

CVE-2026-64598

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc() The "*num_sgs" variable is a u32 so "ERR_PTR(*num_sgs)" doesn't work. We would have to do something similar to the previous line where it's cast to int and then long. However, it's simpler to store the return in an int ret variable. This bug would eventually result in a crash when dereference the invalid error pointer.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64598">https://www.tenable.com/cve/CVE-2026-64598</a></p>

2026/8/6
阅读更多

CVE-2026-64597

<p>Critical Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64597">https://www.tenable.com/cve/CVE-2026-64597</a></p>

2026/8/6
阅读更多

CVE-2026-64588

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix data races on ring->ready On weakly-ordered architectures, the store to fiq->ops can be reordered past the store to ring->ready, allowing a CPU that sees ring->ready == true via fuse_uring_ready() to dispatch requests through a stale fiq->ops pointer. Upgrade the store to smp_store_release() and the load in fuse_uring_ready() to smp_load_acquire() so that the preceding WRITE_ONCE(fiq->ops, ...) is visible to any CPU that observes ring->ready == true. Additionally, fuse_uring_do_register() publishes ring->ready with WRITE_ONCE() but the fast-path check reads it with a plain load. This is a marked-vs-unmarked access that KCSAN will flag. Wrap it in READ_ONCE() to mark it without adding unnecessary ordering. Also wrap the fc->ring load in fuse_uring_ready() in READ_ONCE() to prevent the compiler from reloading it between the NULL check and the dereference.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64588">https://www.tenable.com/cve/CVE-2026-64588</a></p>

2026/8/6
阅读更多

CVE-2026-64587

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts before requesting IRQ Normal RX/TX interrupts are enabled later, in arc_emac_open(), so probe should not see interrupt delivery in the usual case. However, hardware may still present stale or latched interrupt status left by firmware or the bootloader. If probe later unwinds after devm_request_irq() has installed the handler, such a stale interrupt can still reach arc_emac_intr() during teardown and race with release of the associated net_device. Avoid that window by putting the device into a known quiescent state before requesting the IRQ: disable all EMAC interrupt sources and clear any pending EMAC interrupt status bits. This keeps the change hardware-focused and minimal, while preventing spurious IRQ delivery from leftover state.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64587">https://www.tenable.com/cve/CVE-2026-64587</a></p>

2026/8/6
阅读更多

CVE-2026-64586

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device removal brcmf_fw_crashed() and the debugfs "reset" entry both schedule drvr->bus_reset, whose callback recovers drvr through container_of() and dereferences it. The removal path frees drvr (brcmf_free -> wiphy_free) without draining the work, so a bus_reset callback pending or running during removal can outlive drvr. Cancellation cannot live in brcmf_detach() or brcmf_free(): the work callback reaches teardown through the bus .reset op (PCIe brcmf_pcie_reset -> brcmf_detach; SDIO brcmf_sdio_bus_reset -> brcmf_sdiod_remove -> brcmf_free), so cancelling there would wait for the running work and deadlock. Add a per-bus mutex (bus_reset_lock) and route all arming through brcmf_bus_schedule_reset(), which under the lock skips when the bus is marked removing. Each bus remove entry calls brcmf_bus_cancel_reset_work(), which under the same lock sets removing and cancels the work. Holding the mutex across cancel_work_sync() makes the set-removing + drain step atomic. Every producer reaches the arming path from process context -- the PCIe firmware-halt notification runs in the threaded IRQ handler (brcmf_pcie_isr_thread) and the SDIO hostmail path runs from the data workqueue -- so the mutex is taken only in sleepable contexts. Where applicable the remove entry first stops the firmware-crash producer: on PCIe mask the mailbox and synchronize_irq; on SDIO unregister the bus interrupt and cancel the data worker, which also reports firmware halts through brcmf_fw_crashed(). The mutex is initialized at bus allocation. The SDIO suspend power-off path frees drvr through the same brcmf_sdiod_remove() and takes the same lock; resume re-allows the work only on a successful re-probe. Also guard brcmf_fw_crashed() against a NULL bus_if/drvr: it can fire before brcmf_attach() wires up drvr, and it dereferences drvr (bphy_err/brcmf_dev_coredump) before reaching the arming gate. The bus_reset work is shared across buses, so the drain is applied to every remove path: PCIe (the .reset op introduced by the Fixes commit), SDIO (arms the same work through brcmf_fw_crashed()), and USB (via the debugfs "reset" entry). cancel_work_sync() drains a running or pending bus_reset work item before removal frees drvr, and patch 1/2 makes the scratch-buffer release safe when reset teardown has already released those DMA buffers. This patch fixes the lifetime of the bus_reset work item itself. It does not attempt to address the separate, pre-existing lifetime of the asynchronous firmware completion started by the PCIe reset path. That callback needs its own lifetime/ownership protocol and is being tracked separately. This issue was found by an in-house static analysis tool.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64586">https://www.tenable.com/cve/CVE-2026-64586</a></p>

2026/8/6
阅读更多

CVE-2026-64585

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URBs before freeing netdevs esd_usb_disconnect() frees each CAN netdev with free_candev() inside its per-netdev loop and only calls unlink_all_urbs(dev) afterwards. The per-netdev private data (struct esd_usb_net_priv) is embedded in the net_device allocation returned by alloc_candev(), so once free_candev() has run, dev->nets[i] points to freed memory. unlink_all_urbs() then dereferences the freed dev->nets[i] to kill the per-netdev TX anchor (usb_kill_anchored_urbs(&priv->tx_submitted)), clear active_tx_jobs, and reset priv->tx_contexts[]. Reorder the teardown so the anchored URBs are killed before the netdevs are freed, matching other CAN/USB drivers in the same directory such as ems_usb, usb_8dev and mcba_usb, which unregister, then unlink, then free: unregister the netdevs first (which stops their TX queues), call unlink_all_urbs(dev) once, then free the netdevs. This issue was found by an in-house static analysis tool.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64585">https://www.tenable.com/cve/CVE-2026-64585</a></p>

2026/8/6
阅读更多

CVE-2026-64584

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before freeing the midi object The f_midi driver embeds a work item (midi->work) whose handler, f_midi_in_work(), dereferences the enclosing struct f_midi through container_of(). This work is armed from two sites: f_midi_complete(), on a normal IN-endpoint completion, and f_midi_in_trigger(), on an ALSA rawmidi output-stream start. Neither f_midi_disable() nor f_midi_unbind() cancels midi->work. f_midi_disable() only disables the endpoints and drains the in_req_fifo; it does not synchronize the work item, and the sound card is released asynchronously to the final free of the midi object. The midi object is reference-counted (midi->free_ref) and is freed in f_midi_free() only once both the usb_function reference and the rawmidi private_data reference have been dropped. In f_midi_unbind(), f_midi_disable() runs before the sound card is released, so while the USB endpoints are already disabled the rawmidi device is still usable by an open substream. A concurrent userspace write on such a substream can reach f_midi_in_trigger() and queue midi->work again after f_midi_disable() has returned. A work item armed this way may still be pending when the last reference drops and f_midi_free() proceeds to kfree(midi), letting f_midi_in_work() dereference the struct after it has been freed, a use-after-free. For this reason cancelling midi->work in f_midi_disable() would not be sufficient: the ALSA trigger path can rearm the work after disable() returns. Cancelling at the refcount-zero free site is the boundary after which neither arming source can survive, because by then both references that keep the midi object alive have been dropped: the USB endpoints are already disabled and the rawmidi device has been released. Fix this by calling cancel_work_sync(&midi->work) in the refcount-zero block of f_midi_free(), before the embedded work_struct is freed along with the rest of the structure. opts->lock is a sleeping mutex, so calling cancel_work_sync() under it is permitted, and the handler takes midi->transmit_lock rather than opts->lock, so no self-deadlock can occur while it waits for a running instance of the work to finish. This issue was found by an in-house static analysis tool.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64584">https://www.tenable.com/cve/CVE-2026-64584</a></p>

2026/8/6
阅读更多

CVE-2026-64583

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown The Broadcom BDC UDC driver registers its IRQ handler with devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm only after bdc_remove() returns. devm releases resources in reverse LIFO order, but bdc_remove() runs bdc_udc_exit() and bdc_hw_exit() -> bdc_mem_free() manually before returning: bdc_udc_exit() tears down individual endpoint objects via bdc_free_ep(), while bdc_hw_exit() -> bdc_mem_free() frees and NULLs the DMA-coherent status-report ring (bdc->srr.sr_bds) and kfree()s bdc->bdc_ep_array. Both happen while the IRQ handler (bdc_udc_interrupt, requested with IRQF_SHARED) remains deliverable in the window up to the post-remove devm free_irq(). On receipt of a shared interrupt in that window, bdc_udc_interrupt() dereferences bdc->srr.sr_bds[bdc->srr.dqp_index] (NULL or freed DMA) and dispatches sr_handler callbacks that index into bdc_ep_array, causing a NULL-deref or use-after-free. The same window affects the delayed_work bdc->func_wake_notify, which is armed from the IRQ handler via bdc_sr_uspc() -> handle_link_state_change() -> schedule_delayed_work() and may self-rearm from its own callback bdc_func_wake_timer(). No cancel exists anywhere in the driver, so a queued work item that fires after bdc_remove() returns and the bdc structure is devm-freed dereferences freed memory. Replace devm_request_irq() with request_irq() and add an explicit free_irq(bdc->irq, bdc) in bdc_remove(). Clear BDC_GIE before free_irq() to stop the device from asserting interrupts, then free_irq() drains any in-flight handler, then cancel_delayed_work_sync() drains the func_wake_notify delayed work. This ordering ensures the IRQ handler and delayed work cannot interfere with the subsequent endpoint and DMA teardown in bdc_udc_exit() and bdc_hw_exit(). Wire the matching free_irq() into the bdc_udc_init() error path so the IRQ is released on probe failure, and route the bdc_init_ep() failure through err0 instead of returning directly. This issue was found by an in-house static analysis tool.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64583">https://www.tenable.com/cve/CVE-2026-64583</a></p>

2026/8/6
阅读更多

CVE-2026-64582

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: list_del_init(&ip->pending_mmaps); spin_unlock_bh(&rxe->pending_lock); /* ref == 1, no lock held */ ret = remap_vmalloc_range(vma, ip->obj, 0); /* walks PTEs */ [...] rxe_vma_open(vma); /* kref_get, ref → 2 */ remap_vmalloc_range_partial() walks PTEs without any lock. A concurrent DESTROY_CQ ioctl on another CPU calls: kref_put(&q->ip->ref, rxe_mmap_release) /* ref 1→0 */ vfree(ip->obj) /* clears vmalloc PTEs mid-walk */ kfree(ip) /* frees rxe_mmap_info */ This yields: 1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the per-PTE race -> vm_insert_page(NULL) → GPF in validate_page_before_insert 2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears it. User VMA holds a PTE to a free'd page which might eventually get reallocated later by vmalloc which allows the attacker to get a clean page-level UAF. It is worth noting that even though a page-level UAF is possible given the strong primitive, it is statistically very difficult to achieve given the very short time window (after the last insert_page and before the kref_get). The call trace are as below: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 RIP: 0010:validate_page_before_insert+0x32/0x300 Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5 RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202 RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000 RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008 RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00 R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20 FS: 00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0 Call Trace: <TASK> insert_page+0x8f/0x190 ? __pfx_insert_page+0x10/0x10 ? kasan_save_alloc_info+0x38/0x60 vm_insert_page+0x2e7/0x400 remap_vmalloc_range_partial+0x212/0x3e0 remap_vmalloc_range+0x6e/0xb0 ? __kasan_check_write+0x14/0x30 rxe_mmap+0x2e9/0x5d0 ib_uverbs_mmap+0x1ad/0x2c0 __mmap_region+0x12c2/0x2ad0 ? __pfx___mmap_region+0x10/0x10 ? __sanitizer_cov_trace_switch+0x58/0xb0 ? mas_prev_slot+0x360/0x39c0 ? __sanitizer_cov_trace_switch+0x58/0xb0 ? mas_next_slot+0x1e5b/0x2f40 ? __sanitizer_cov_trace_cmp8+0x18/0x30 ? unmapped_area_topdown+0x4dd/0x610 ? kfree+0x1b1/0x440 ? free_cpumask_var+0x16/0x30 ? __kasan_slab_free+0x7d/0xa0 ? __sanitizer_cov_trace_cmp8+0x18/0x30 mmap_region+0x2e6/0x3c0 do_mmap+0xa3e/0x12a0 ? __pfx_do_mmap+0x10/0x10 ? __kasan_check_write+0x14/0x30 ? down_write_killable+0xba/0x160 ? __pfx_down_write_killable+0x10/0x10 ? __sanitizer_cov_trace_cmp4+0x16/0x30 vm_mmap_pgoff+0x2d4/0x4a0 ? __pfx_vm_mmap_pgoff+0x10/0x10 ? fget+0x1bf/0x270 ksys_mmap_pgoff+0x40c/0x690 ? __sanitizer_cov_trace_const_cmp4+0x16/0x30 ? __pfx_ksys_mmap_pgoff+0x10/0x10 ? __kasan_check_write+0x14/0x30 ? _raw_spin_trylock+0xbb/0x130 ? __pfx__raw_spin_trylock+0x10/0x10 __x64_sys_mmap+0x135/0x1e0 x64_sys_c ---truncated---</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64582">https://www.tenable.com/cve/CVE-2026-64582</a></p>

2026/8/5
阅读更多

CVE-2026-64581

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(), i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with rcu_dereference_protected(), stores NULL and dst_release()s the old dst. That is only safe if no other thread modifies sk_dst_cache concurrently. For a connected UDP socket that does not hold: the transmit fast path (udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly with an atomic xchg(). A per-socket policy change racing a send can make both sides observe the same old dst and each dst_release() it, dropping the socket's single reference twice and freeing the xfrm_dst bundle while it is still referenced: BUG: KASAN: slab-use-after-free in dst_release Write of size 4 at addr ffff88801897b6c0 by task exploit/155 Call Trace: ... dst_release (... ./include/linux/rcuref.h:109) xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053) do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347) ip_setsockopt (net/ipv4/ip_sockglue.c:1417) do_sock_setsockopt (net/socket.c:2368) __sys_setsockopt (net/socket.c:2393) __x64_sys_setsockopt (net/socket.c:2396) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Reachable by an unprivileged user via a user+network namespace. Use the atomic sk_dst_reset() so the cache is cleared and released with a single xchg(): whichever side wins releases the dst once, the other sees NULL and does nothing. Behaviour is otherwise unchanged.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64581">https://www.tenable.com/cve/CVE-2026-64581</a></p>

2026/8/5
阅读更多

CVE-2026-64580

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() On the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst() releases the device reference with netdev_put() but leaves xdst->u.dst.dev set. dst_destroy() later calls netdev_put(dst->dev) again, so the same net_device reference is released twice, underflowing its refcount (ref_tracker WARNING + "unregister_netdevice: waiting for <dev> to become free"). Clear xdst->u.dst.dev after the netdev_put(), the same way the XFRM device-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in net/xfrm/xfrm_device.c NULL ->dev when releasing the reference on error. ref_tracker: reference already released. ref_tracker: allocated in: xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86) ... udpv6_sendmsg (net/ipv6/udp.c:1696) ... ref_tracker: freed in: xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90) ... WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780 dst_destroy (net/core/dst.c:115) rcu_core handle_softirqs ...</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64580">https://www.tenable.com/cve/CVE-2026-64580</a></p>

2026/8/5
阅读更多

CVE-2026-64578

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before reading StructureSize2 When ksmbd validates a compound (chained) SMB2 request, ksmbd_smb2_check_message() reads pdu->StructureSize2 without first checking that the compound element is large enough to contain it. StructureSize2 is a 2-byte field at offset 64 (__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element. The compound-walking logic only guarantees that a full 64-byte SMB2 header is present for the trailing element: when NextCommand is 0, len is reduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A remote client can craft a compound request whose last element has exactly 64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte past the receive buffer, producing a slab-out-of-bounds read. BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402) Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14 The buggy address is located 172 bytes inside of allocated 173-byte region Workqueue: ksmbd-io handle_ksmbd_work Call Trace: ... kasan_report (mm/kasan/report.c:595) ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402) handle_ksmbd_work (fs/smb/server/server.c:119) process_one_work (kernel/workqueue.c:3314) worker_thread (kernel/workqueue.c:3397) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:158) ret_from_fork_asm (arch/x86/entry/entry_64.S:245) Reject any compound element that is too small to hold StructureSize2 before dereferencing it.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64578">https://www.tenable.com/cve/CVE-2026-64578</a></p>

2026/8/5
阅读更多

CVE-2026-64577

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr + gtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For a 16-19 byte echo request the pull fails and returns NULL without advancing skb->data; execution continues, and the following skb_push() plus the IP header pushed by iptunnel_xmit() move skb->data below skb->head, tripping skb_under_panic(). Fix it by dropping the packet when skb_pull_data() fails. skbuff: skb_under_panic: ... kernel BUG at net/core/skbuff.c:214! Call Trace: skb_push (net/core/skbuff.c:2648) iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82) gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920) udp_queue_rcv_one_skb (net/ipv4/udp.c:2388) ... Kernel panic - not syncing: Fatal exception in interrupt</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64577">https://www.tenable.com/cve/CVE-2026-64577</a></p>

2026/8/5
阅读更多

CVE-2026-64576

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate() nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to call_nexthop_res_bucket_notifiers(). When nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns -ENOMEM), the error is propagated back before any notifier sets extack._msg, and the error path formats the stale pointer with pr_err_ratelimited("%s\n", extack._msg). With CONFIG_INIT_STACK_NONE this dereferences uninitialized stack memory: Oops: general protection fault, probably for non-canonical address ... KASAN: maybe wild-memory-access in range [...] RIP: 0010:string (lib/vsprintf.c:730) vsnprintf (lib/vsprintf.c:2945) _printk (kernel/printk/printk.c:2504) nh_res_bucket_migrate (net/ipv4/nexthop.c:1816) nh_res_table_upkeep (net/ipv4/nexthop.c:1866) rtm_new_nexthop (net/ipv4/nexthop.c:3323) rtnetlink_rcv_msg (net/core/rtnetlink.c:7076) netlink_sendmsg (net/netlink/af_netlink.c:1900) Kernel panic - not syncing: Fatal exception Zero-initialize extack so _msg is NULL on error paths that never set it.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64576">https://www.tenable.com/cve/CVE-2026-64576</a></p>

2026/8/5
阅读更多

CVE-2026-64575

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc bpf_iter_tcp_batch() releases the current batch via bpf_iter_tcp_put_batch(), which drops the socket refs and rewrites each slot with the socket cookie, then grows the batch. cur_sk/end_sk are kept for bpf_iter_tcp_resume(), but on realloc failure the function returns ERR_PTR() before resume runs, leaving cur_sk < end_sk over slots that now hold cookies rather than sock pointers. bpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and dereferences a cookie as a struct sock. Empty the batch on the failure path so stop() does not release it again. The sockets were already freed by the first bpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans the bucket from the start instead of skipping it. The sibling GFP_NOWAIT failure path still holds real socket references and is left for stop() to release. BUG: KASAN: null-ptr-deref in __sock_gen_cookie Read of size 8 at addr 0000000000000059 by task exploit ... __sock_gen_cookie (net/core/sock_diag.c:28) bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918) bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270) bpf_seq_read (kernel/bpf/bpf_iter.c:205) vfs_read (fs/read_write.c:572) ksys_read (fs/read_write.c:716) do_syscall_64 entry_SYSCALL_64_after_hwframe Kernel panic - not syncing: Fatal exception</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64575">https://www.tenable.com/cve/CVE-2026-64575</a></p>

2026/8/5
阅读更多

CVE-2026-64574

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update error path When ieee80211_vif_update_links() adds new links it allocates a link container for each and calls ieee80211_link_init() (which registers the per-link debugfs files with file->private_data pointing into the container) and ieee80211_link_setup(). If the subsequent drv_change_vif_links() fails, the error path restores the old pointers and jumps to 'free', which frees the new containers but never removes their debugfs entries or stops the links. The debugfs files survive with file->private_data dangling at the freed container, so a later open()+read() (e.g. link-1/txpower) dereferences freed memory in ieee80211_if_read_link(), a use-after-free. The removal path already dismantles links correctly via ieee80211_tear_down_links(), which removes each link's keys and debugfs entries and calls ieee80211_link_stop(); the add path on the error branch does not. Commit be1ba9ed221f ("wifi: mac80211: avoid weird state in error path") hardened this same error path for the link-removal case (new_links == 0) but left the newly-added links' teardown unaddressed. drv_change_vif_links() can fail at runtime on MLO drivers (internal allocation / queue / firmware command failures). Remove the new links' debugfs entries and stop them before freeing. BUG: KASAN: slab-use-after-free in ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127) Read of size 8 at addr ffff888011290000 by task exploit/145 Call Trace: ... ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127) short_proxy_read (fs/debugfs/file.c:373) vfs_read (fs/read_write.c:572) ksys_read (fs/read_write.c:716) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) ... Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a RIP: 0010:ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127) Kernel panic - not syncing: Fatal exception</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64574">https://www.tenable.com/cve/CVE-2026-64574</a></p>

2026/8/5
阅读更多

CVE-2026-64570

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on alloc failure ieee80211_set_fils_discovery() calls kfree_rcu() on the old template before allocating the replacement. If the kzalloc() then fails, it returns -ENOMEM while link->u.ap.fils_discovery still points at the object already queued for freeing. A later update or AP teardown (ieee80211_stop_ap()) re-queues that same rcu_head; the second free is caught by KASAN when the RCU sheaf is processed in softirq: BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850) Free of addr ffff88800c065280 by task swapper/0/0 ... __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940) rcu_free_sheaf (mm/slub.c:5850) rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869) handle_softirqs (kernel/softirq.c:622) The buggy address belongs to the cache kmalloc-96 of size 96 Queue the old object for kfree_rcu() only after the new one is published, matching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64570">https://www.tenable.com/cve/CVE-2026-64570</a></p>

2026/8/5
阅读更多

CVE-2026-64568

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure ieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old template before allocating the replacement. If the kzalloc() then fails, it returns -ENOMEM while link->u.ap.unsol_bcast_probe_resp still points at the object already queued for freeing. A later update or AP teardown re-queues that same rcu_head; the second free is caught by KASAN when the RCU sheaf is processed in softirq: BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850) Free of addr ffff88800d06f300 by task exploit/145 ... __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940) rcu_free_sheaf (mm/slub.c:5850) rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869) handle_softirqs (kernel/softirq.c:622) The buggy address belongs to the cache kmalloc-128 of size 128 Queue the old object for kfree_rcu() only after the new one is published, matching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon().</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64568">https://www.tenable.com/cve/CVE-2026-64568</a></p>

2026/8/5
阅读更多

CVE-2026-64567

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pages When loading a v1 free space cache, __load_free_space_cache() takes num_entries and num_bitmaps straight from the on-disk btrfs_free_space_header. That header is stored in the tree_root under a key with type 0, which the tree-checker has no case for, so neither count is validated before the load trusts it. The load loops num_entries times and maps the next page whenever the current one runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which does io_ctl->pages[io_ctl->index++]. But pages[] is allocated in io_ctl_init() from the cache inode's i_size, not from num_entries: num_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE); io_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS); So if num_entries claims more records than the pages can hold, io_ctl->index runs off the end of pages[]. The write side never hits this because io_ctl_add_entry() and io_ctl_add_bitmap() both stop once io_ctl->index >= io_ctl->num_pages; the read side just never had the same check. To trigger it, take a clean cache (num_entries = <N> here), set num_entries in the header to 0x10000, and fix up the leaf checksum so it still passes the tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and pages[] is a 16-pointer (kmalloc-128) array. The load now tries to read 65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the array: BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565) Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58 io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565) __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820) load_free_space_cache (fs/btrfs/free-space-cache.c:1017) caching_thread (fs/btrfs/block-group.c:880) btrfs_work_helper (fs/btrfs/async-thread.c:312) process_one_work worker_thread kthread ret_from_fork free-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc() at line 565, which is why that is the frame KASAN names. The out-of-bounds slot is then treated as a struct page and handed to crc32c(), so the bad read turns into a GP fault. Add the missing check to io_ctl_check_crc(), which is where both the entry loop and the bitmap loop end up. When num_entries is too large the load now fails like any corrupt cache: __load_free_space_cache() drops it and rebuilds the free space from the extent tree, so a valid cache is never rejected.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64567">https://www.tenable.com/cve/CVE-2026-64567</a></p>

2026/8/5
阅读更多

CVE-2026-64566

<p>Critical Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() When iptfs_skb_add_frags() copies frag references from the source frag walk into a new SKB, it increments the page reference count via __skb_frag_ref() but does not propagate SKBFL_SHARED_FRAG to the destination SKB's skb_shinfo->flags. If the source SKB carries shared frags (e.g. from a page-pool backed receive path), the new inner SKB will appear to ESP as having privately owned frags. A subsequent esp_input() call for a nested transport-mode SA then takes the no-COW fast path and decrypts in place, writing over pages that are still referenced by the outer IPTFS SKB. This causes kernel-visible memory corruption and can trigger a panic. All other frag-transfer helpers in the kernel (skb_try_coalesce, skb_gro_receive, __pskb_copy_fclone, skb_shift, skb_segment) correctly propagate SKBFL_SHARED_FRAG; align iptfs_skb_add_frags() with this convention by setting the flag inside the loop immediately after __skb_frag_ref() and nr_frags++, so every exit path that attaches a frag unconditionally propagates SKBFL_SHARED_FRAG.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64566">https://www.tenable.com/cve/CVE-2026-64566</a></p>

2026/8/5
阅读更多

CVE-2026-64563

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a walk. When iter->walker.tbl is valid, it re-validates iter->p against the table and sets iter->p = NULL if the object is gone. When iter->walker.tbl is NULL (table was freed during resize), it resets slot and skip but forgets to clear iter->p. rhashtable_walk_next() then dereferences the stale iter->p, reading freed memory. This is a use-after-free. Any caller that does multi-fragment rhashtable walks across walk_stop/walk_start boundaries is affected. Concrete cases include netlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC (tipc_nl_sk_walk in net/tipc/socket.c). Crash stack (netlink_diag): BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0 Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080) Call Trace: rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016) __netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122) netlink_diag_dump+0xc2/0x240 netlink_dump+0x5bc/0x1270 netlink_recvmsg+0x7a3/0x980 sock_recvmsg+0x1bc/0x200 __sys_recvfrom+0x1d4/0x2c0</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64563">https://www.tenable.com/cve/CVE-2026-64563</a></p>

2026/8/4
阅读更多

CVE-2026-64562

<p>High Severity</p> <h3>Description</h3> <p>In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow VMCS while vmcs01 still points to it. But because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU might migrate before the pointer is cleared and __loaded_vmcs_clear() may then execute VMCLEAR. The VMCS needs to stay attached until its explicit VMCLEAR completes, but then it can be hidden and the page safely freed.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64562">https://www.tenable.com/cve/CVE-2026-64562</a></p>

2026/8/4
阅读更多

CVE-2026-62857

<p>High Severity</p> <h3>Description</h3> <p>Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address validation, allowing requests to loopback, link-local, cloud metadata, and private-network services and returning their response bodies. This issue is fixed in versions 1.9.13, 1.10.12, 2.0.22, 2.1.18, 2.2.7, and 2.3.2.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62857">https://www.tenable.com/cve/CVE-2026-62857</a></p>

2026/8/6
阅读更多

CVE-2026-62836

<p>Critical Severity</p> <h3>Description</h3> <p>Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62836">https://www.tenable.com/cve/CVE-2026-62836</a></p>

2026/8/7
阅读更多

CVE-2026-5857

<p>Critical Severity</p> <h3>Description</h3> <p>Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==0, and the persisted topic_len_received==1 skips the length-reading block containing the guard, falling through directly to a memcpy() that uses the unvalidated 16-bit topic_len as the copy length. The 65-byte topic[] destination overruns into adjacent struct fields including the payload_chunk pointer, which subsequent MQTT code dereferences, giving a compromised or attacker-controlled broker an arbitrary-pointer-write primitive. Contiki-NG's MQTT implementation has no TLS support so the connection is plaintext. Impact ranges from information disclosure and denial of service to remote code execution on embedded targets without memory protection.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-5857">https://www.tenable.com/cve/CVE-2026-5857</a></p>

2026/8/6
阅读更多

CVE-2026-56818

<p>Medium Severity</p> <h3>Description</h3> <p>Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when the sibling maxElements limit is exceeded. A peer can start a valid RESP array, send a bulk string child, then send a nested array header longer than the configured maxElements. Netty throws a decoder exception in decodeRedisArrayHeader, but the existing partial aggregate remains retained in the handler. If the application leaves the channel alive after the exception, later messages are still consumed into the pre-error aggregate, allowing an unauthenticated peer to keep attacker-controlled aggregate state alive across a security-limit exception and pin retained pooled buffers. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-56818">https://www.tenable.com/cve/CVE-2026-56818</a></p>

2026/8/7
阅读更多

CVE-2026-56794

<p>Medium Severity</p> <h3>Description</h3> <p>Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-56794">https://www.tenable.com/cve/CVE-2026-56794</a></p>

2026/8/7
阅读更多

CVE-2026-56793

<p>Critical Severity</p> <h3>Description</h3> <p>Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-56793">https://www.tenable.com/cve/CVE-2026-56793</a></p>

2026/8/7
阅读更多

CVE-2026-56162

<p>Critical Severity</p> <h3>Description</h3> <p>Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-56162">https://www.tenable.com/cve/CVE-2026-56162</a></p>

2026/8/7
阅读更多

CVE-2026-48088

<p>Critical Severity</p> <h3>Description</h3> <p>OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on the platform without authentication. The handler logs an "Unauthorized crypto key storage attempt" warning when neither a session nor a registration cookie is present, then proceeds to insert the row regardless. The platform's E2E claim that "even administrators cannot view sensitive information" is broken: any unauthenticated network attacker can register themselves as an additional encryption recipient for any tenant's future patient appointments. A second variant of the bug suppresses the unauthorized-warning log entry. The Zod schema makes the `email` field optional. When the request body omits `email` and the request carries no registration cookie, the comparison `registrationEmail === email` becomes `undefined === undefined`, which evaluates to `true`. The handler treats the request as a legitimate registration flow, skips the warning entirely, and stores the row. Successful storage is still recorded as an `[info]` log line, but the security-relevant warning that operators are most likely to monitor or alert on is gone. The `staff_crypto` table has no unique constraint on `user_id`, so an arbitrary number of attacker rows can coexist for the same staff identifier and all return as `is_active=true`. The supplied `staffId` does not need to match any existing user or pending invite. Schema validation on `passkeyId`, `publicKey`, and `privateKeyShare` is also weak: the literal string `<placeholder-base64>` was accepted, indicating no length, format, or cryptographic-validity check beyond field presence. This weakness is independent of the auth bypass but compounds it: a poisoned directory can also be filled with malformed entries that break legitimate booking flows. The injected key is consumed by the public booking flow. After completing the unauthenticated `bootstrap-challenge` and `bootstrap-verify` ceremony as a "patient", the resulting `bookingAccessToken` is accepted by `GET /api/tenants/{id}/appointments/staff-public-keys`, which returns the attacker-controlled keys alongside any legitimate ones. A new appointment encrypts its tunnel key with ML-KEM to all listed recipients, so the attacker becomes a co-recipient of the encryption and can decapsulate the tunnel key with the matching secret. From there, all appointment payloads for that booking are decryptable. Version 1.0.4 patches the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-48088">https://www.tenable.com/cve/CVE-2026-48088</a></p>

2026/8/6
阅读更多

CVE-2026-48083

<p>Medium Severity</p> <h3>Description</h3> <p>OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema validation to the message body, writes attacker-controlled content directly into the application's stdout log, interprets newline characters as real line breaks, and enforces no size or rate limits. Three independent abuse modes follow: log injection (forge log lines that look like legitimate system events), log volume DoS (saturate the logging pipeline at sustained 100+ requests per second of small messages), and oversized-payload submission (100 KB payloads accepted; larger sizes not tested). The most operationally damaging mode is log injection. An attacker can inject lines that an operator scanning logs would mistake for real system errors, mask their own activity behind fake noise, or pollute SIEM alerting rules with crafted false positives. A line such as `[error]: injected admin error` injected from an unauthenticated source is indistinguishable from the application's own error output once written to disk. Version 1.0.2 fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-48083">https://www.tenable.com/cve/CVE-2026-48083</a></p>

2026/8/6
阅读更多

CVE-2026-48078

<p>Medium Severity</p> <h3>Description</h3> <p>OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` flag. Channels marked `isPublic = false` are intended to be invisible to public callers; the dashboard creates them deliberately to hide internal-only services from the patient booking UI. The schedule endpoint ignores the flag entirely and discloses channel names, descriptions, IDs, agent associations, pause status, confirmation requirements, and computed slot availability for the requested date range. The asymmetry between `addAppointmentToTunnel` (which enforces `eq(channel.isPublic, true)`) and the schedule endpoint (which does not) confirms the design intent: private channels exist as a real access boundary in the booking flow, just not in the schedule disclosure. Version 1.0.5 patches the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-48078">https://www.tenable.com/cve/CVE-2026-48078</a></p>

2026/8/6
阅读更多

CVE-2026-48071

<p>Medium Severity</p> <h3>Description</h3> <p>OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows live in the central `challenge_throttle` table, which is shared across all tenants. Every tenant's `/api/tenants/{id}/appointments/verify-challenge` endpoint increments the same row when a PIN response fails, and every tenant's `/api/tenants/{id}/appointments/challenge` endpoint reads the same row when deciding whether to issue a new challenge. When the same `emailHash` exists in multiple tenants on the same OpenReception instance (the same patient holding tunnels in two different clinics that share the platform), an attacker who knows the patient's email can lock out that patient on tenant B by issuing failed challenge responses against tenant A. The attacker needs no relationship to tenant B; the lockout propagates through the shared throttle row. The lockout escalates with repeated failures. The first lockout triggers at 4 failed attempts and lasts approximately 60 seconds. Subsequent failures escalate the lockout duration to 5 minutes, 30 minutes, and 60 minutes per the throttle service's escalation logic. Repeated bursts produce sustained denial of service against the targeted email. Version 1.0.4 patches the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-48071">https://www.tenable.com/cve/CVE-2026-48071</a></p>

2026/8/6
阅读更多

CVE-2026-47427

<p>High Severity</p> <h3>Description</h3> <p>GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because the crash occurs before any authentication or token validation, any unauthenticated client able to send JSON-RPC messages can crash the server, resulting in a complete denial of service. This issue is fixed in version 1.1.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-47427">https://www.tenable.com/cve/CVE-2026-47427</a></p>

2026/7/28
阅读更多

CVE-2026-47364

<p>Medium Severity</p> <h3>Description</h3> <p>In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-47364">https://www.tenable.com/cve/CVE-2026-47364</a></p>

2026/8/7
阅读更多

CVE-2026-47363

<p>Medium Severity</p> <h3>Description</h3> <p>In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend. This requires a malicious application co-installed on a device with the Datadog app installed, and an OAuth token the attacker is willing to load into the victim's app. Impact: A co-installed application can switch the victim's Datadog app to a session the attacker controls. This is an account-confusion issue; it does not by itself expose the victim's existing session or data.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-47363">https://www.tenable.com/cve/CVE-2026-47363</a></p>

2026/8/7
阅读更多

CVE-2026-47362

<p>Medium Severity</p> <h3>Description</h3> <p>In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recipient, service, tags, and on-call/incident deep links) and SearchRecentDatabase (the user's full in-app search history). Impact: Any actor able to bypass the app sandbox can read these databases in plaintext.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-47362">https://www.tenable.com/cve/CVE-2026-47362</a></p>

2026/8/7
阅读更多

CVE-2026-47361

<p>Medium Severity</p> <h3>Description</h3> <p>In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process session matches that ID, it unconditionally cancels notification ID 9201 (the Bits AI chat notification), with no check on the caller's identity or ownership of the conversation. This requires a malicious application co-installed on the victim's device. Impact: A co-installed application can silently dismiss the victim's Bits AI chat notification. No chat content is exposed; conversation data remains server-authentication gated and is never returned to the caller.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-47361">https://www.tenable.com/cve/CVE-2026-47361</a></p>

2026/8/7
阅读更多

CVE-2026-45573

<p>Medium Severity</p> <h3>Description</h3> <p>Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery is enabled, the notification subscription flow stores a client-supplied push endpoint without validating that it belongs to an approved push service, and SendPushNotification later passes that endpoint to WebPush.payload_send, allowing an authenticated user to create stored, mostly blind server-side requests to arbitrary reachable HTTPS endpoints. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-45573">https://www.tenable.com/cve/CVE-2026-45573</a></p>

2026/8/6
阅读更多

CVE-2026-44965

<p>Medium Severity</p> <h3>Description</h3> <p>In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported with no permission guard. Each accepts a caller-supplied AppWidgetManager.EXTRA_APPWIDGET_ID and, when no deep-link destination is resolved, uses it to load the matching widget's stored session and automatically log in as that user. Because Android widget IDs are small sequential integers, a co-installed application can brute-force this value to find one that matches a widget configured on the victim's device. This requires: A malicious application co-installed on the victim's device. At least one of the six widgets configured on the victim's home screen. An active Datadog session cached locally. Impact: The matching configuration activity opens in the foreground under the victim's session and renders live infrastructure data. Exposure is limited to a visual side channel (e.g., screen recording or accessibility services); the calling application cannot programmatically read the rendered data.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-44965">https://www.tenable.com/cve/CVE-2026-44965</a></p>

2026/8/7
阅读更多

CVE-2026-44964

<p>Medium Severity</p> <h3>Description</h3> <p>In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-controlled Intent extras, including a full-screen lock-screen message, an arbitrary on-call page ID, and an arbitrary Intent to run inside the Datadog process. This requires: A malicious application co-installed on the victim's device. An active Datadog session in the Android app. Impact: After a single tap on the Acknowledge button, the app sends a forged on-call acknowledgement to the backend under the victim's session, launches the attacker-supplied Intent from within the Datadog process (reaching otherwise non-exported components), and turns on the screen while dismissing the keyguard.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-44964">https://www.tenable.com/cve/CVE-2026-44964</a></p>

2026/8/7
阅读更多

CVE-2026-43632

<p>Critical Severity</p> <h3>Description</h3> <p>llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task queue and access ctx_server.vocab directly on HTTP worker threads. Attackers can exploit a time-of-check-time-of-use race condition where the main thread destroys and frees vocab after the synchronization lock is released but before the handler finishes using it, causing a crash or potential code execution when --sleep-idle-seconds is configured.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-43632">https://www.tenable.com/cve/CVE-2026-43632</a></p>

2026/8/6
阅读更多

CVE-2026-43627

<p>High Severity</p> <h3>Description</h3> <p>llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-43627">https://www.tenable.com/cve/CVE-2026-43627</a></p>

2026/8/6
阅读更多

CVE-2026-42170

<p>High Severity</p> <h3>Description</h3> <p>A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel data consumption at the real format's stride causes a write past the heap buffer boundary, leading to heap metadata corruption and potential code execution.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-42170">https://www.tenable.com/cve/CVE-2026-42170</a></p>

2026/8/8
阅读更多

CVE-2026-41187

<p>Medium Severity</p> <h3>Description</h3> <p>Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-41187">https://www.tenable.com/cve/CVE-2026-41187</a></p>

2026/7/30
阅读更多

CVE-2026-41186

<p>Medium Severity</p> <h3>Description</h3> <p>When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap, goroutine stacks (including function arguments), and command-line arguments. Depending on the process's in-memory state, the heap may contain sensitive material. The debug listener is opt-in but is unsafe when enabled because it offers no authentication and no safe localhost-only binding option.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-41186">https://www.tenable.com/cve/CVE-2026-41186</a></p>

2026/7/30
阅读更多

CVE-2026-2100

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-2100">https://www.tenable.com/cve/CVE-2026-2100</a></p>

2026/3/26
阅读更多

CVE-2026-19288

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. Such manipulation of the argument libraryId leads to path traversal. The attack needs to be performed locally. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19288">https://www.tenable.com/cve/CVE-2026-19288</a></p>

2026/8/8
阅读更多

CVE-2026-19287

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the argument ID causes path traversal. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19287">https://www.tenable.com/cve/CVE-2026-19287</a></p>

2026/8/8
阅读更多

CVE-2026-19285

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function JsonMemoryStorage.createDomain/JsonMemoryStorage.getMemories/JsonMemoryStorage.saveMemories of the file src/tools/memoryTools.ts. The manipulation results in path traversal. The attack must be initiated from a local position. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19285">https://www.tenable.com/cve/CVE-2026-19285</a></p>

2026/8/8
阅读更多

CVE-2026-19284

<p>Medium Severity</p> <h3>Description</h3> <p>A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the component Projects Endpoint. The manipulation leads to command injection. The attack must be carried out locally. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19284">https://www.tenable.com/cve/CVE-2026-19284</a></p>

2026/8/8
阅读更多

CVE-2026-19282

<p>Medium Severity</p> <h3>Description</h3> <p>A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llm_memory_mcp. Executing a manipulation of the argument hash can lead to command injection. The attack is restricted to local execution. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19282">https://www.tenable.com/cve/CVE-2026-19282</a></p>

2026/8/8
阅读更多

CVE-2026-19281

<p>Medium Severity</p> <h3>Description</h3> <p>A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command injection. The attack is only possible with local access. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19281">https://www.tenable.com/cve/CVE-2026-19281</a></p>

2026/8/8
阅读更多

CVE-2026-19279

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId leads to command injection. The attack can only be performed from a local environment. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19279">https://www.tenable.com/cve/CVE-2026-19279</a></p>

2026/8/8
阅读更多

CVE-2026-19270

<p>Medium Severity</p> <h3>Description</h3> <p>A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_stats of the file src/journey/JourneyStorage.ts of the component Journey/Usage. The manipulation of the argument journeyId/filename results in path traversal. The attack requires a local approach. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19270">https://www.tenable.com/cve/CVE-2026-19270</a></p>

2026/8/8
阅读更多

CVE-2026-19268

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file src/services/claude-usage.ts of the component Claude Usage Range Endpoint. The manipulation of the argument since leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19268">https://www.tenable.com/cve/CVE-2026-19268</a></p>

2026/8/8
阅读更多

CVE-2026-19266

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the file src/mcp/utils/gitUtils.ts of the component review-git-diff Endpoint. Executing a manipulation of the argument args can lead to command injection. Upgrading to version 1.9.1 mitigates this issue. This patch is called e0729dcfd3a2b1682a7bff86e7174852c03419ba. It is advisable to upgrade the affected component.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19266">https://www.tenable.com/cve/CVE-2026-19266</a></p>

2026/8/8
阅读更多

CVE-2026-19263

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an unknown function of the file mcp-bridge.js of the component Servers Endpoint. Performing a manipulation of the argument command/args results in command injection. It is possible to initiate the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The pull request to fix this issue awaits acceptance.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19263">https://www.tenable.com/cve/CVE-2026-19263</a></p>

2026/8/8
阅读更多

CVE-2026-19259

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the component MMS Protocol Workflow. Such manipulation of the argument GetNamedVariableListAttributesResponse.itemId leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19259">https://www.tenable.com/cve/CVE-2026-19259</a></p>

2026/8/8
阅读更多

CVE-2026-19212

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WTSTradeDef.hpp of the component TraderATP Cash Trade Conversion. Executing a manipulation of the argument m_offsetType can lead to use of uninitialized variable. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19212">https://www.tenable.com/cve/CVE-2026-19212</a></p>

2026/8/7
阅读更多

CVE-2026-19207

<p>Medium Severity</p> <h3>Description</h3> <p>A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some unknown processing of the file /manage-newvisitors.php. The manipulation of the argument fullname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19207">https://www.tenable.com/cve/CVE-2026-19207</a></p>

2026/8/7
阅读更多

CVE-2026-19192

<p>High Severity</p> <h3>Description</h3> <p>A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit is now public and may be used.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19192">https://www.tenable.com/cve/CVE-2026-19192</a></p>

2026/8/7
阅读更多

CVE-2026-19175

<p>Critical Severity</p> <h3>Description</h3> <p>Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19175">https://www.tenable.com/cve/CVE-2026-19175</a></p>

2026/8/6
阅读更多

CVE-2026-19173

<p>High Severity</p> <h3>Description</h3> <p>Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19173">https://www.tenable.com/cve/CVE-2026-19173</a></p>

2026/8/6
阅读更多

CVE-2026-19171

<p>Critical Severity</p> <h3>Description</h3> <p>Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19171">https://www.tenable.com/cve/CVE-2026-19171</a></p>

2026/8/6
阅读更多

CVE-2026-19166

<p>Critical Severity</p> <h3>Description</h3> <p>Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19166">https://www.tenable.com/cve/CVE-2026-19166</a></p>

2026/8/6
阅读更多

CVE-2026-19164

<p>Critical Severity</p> <h3>Description</h3> <p>Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19164">https://www.tenable.com/cve/CVE-2026-19164</a></p>

2026/8/6
阅读更多

CVE-2026-19159

<p>High Severity</p> <h3>Description</h3> <p>Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19159">https://www.tenable.com/cve/CVE-2026-19159</a></p>

2026/8/6
阅读更多

CVE-2026-19158

<p>High Severity</p> <h3>Description</h3> <p>Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19158">https://www.tenable.com/cve/CVE-2026-19158</a></p>

2026/8/6
阅读更多

CVE-2026-19156

<p>High Severity</p> <h3>Description</h3> <p>Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19156">https://www.tenable.com/cve/CVE-2026-19156</a></p>

2026/8/6
阅读更多

CVE-2026-19152

<p>High Severity</p> <h3>Description</h3> <p>Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19152">https://www.tenable.com/cve/CVE-2026-19152</a></p>

2026/8/6
阅读更多

CVE-2026-19148

<p>High Severity</p> <h3>Description</h3> <p>Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19148">https://www.tenable.com/cve/CVE-2026-19148</a></p>

2026/8/6
阅读更多

CVE-2026-19147

<p>High Severity</p> <h3>Description</h3> <p>Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19147">https://www.tenable.com/cve/CVE-2026-19147</a></p>

2026/8/6
阅读更多

CVE-2026-19144

<p>High Severity</p> <h3>Description</h3> <p>Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19144">https://www.tenable.com/cve/CVE-2026-19144</a></p>

2026/8/6
阅读更多

CVE-2026-19143

<p>High Severity</p> <h3>Description</h3> <p>Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19143">https://www.tenable.com/cve/CVE-2026-19143</a></p>

2026/8/6
阅读更多

CVE-2026-19142

<p>High Severity</p> <h3>Description</h3> <p>Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19142">https://www.tenable.com/cve/CVE-2026-19142</a></p>

2026/8/6
阅读更多

CVE-2026-19141

<p>High Severity</p> <h3>Description</h3> <p>Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19141">https://www.tenable.com/cve/CVE-2026-19141</a></p>

2026/8/6
阅读更多

CVE-2026-19108

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation results in use after free. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 1.6.2 is sufficient to fix this issue. The patch is identified as 486fd57f3aed65bb9d636ff00f9ddce2e450b168. Upgrading the affected component is advised.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19108">https://www.tenable.com/cve/CVE-2026-19108</a></p>

2026/8/6
阅读更多

CVE-2026-19067

<p>Medium Severity</p> <h3>Description</h3> <p>A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatment.php. Performing a manipulation of the argument editid results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19067">https://www.tenable.com/cve/CVE-2026-19067</a></p>

2026/8/6
阅读更多

CVE-2026-19061

<p>Medium Severity</p> <h3>Description</h3> <p>A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19061">https://www.tenable.com/cve/CVE-2026-19061</a></p>

2026/8/6
阅读更多

CVE-2026-19047

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli_execute. Performing a manipulation of the argument command/args results in command injection. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-19047">https://www.tenable.com/cve/CVE-2026-19047</a></p>

2026/8/6
阅读更多

CVE-2026-18988

<p>Medium Severity</p> <h3>Description</h3> <p>The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, and including, 3.1.8. This is due to insufficient input sanitization and output escaping in the accordion_header_renderer() function, which emits the attacker-supplied tag name using esc_attr() in an HTML tag-name context instead of tag_escape(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-18988">https://www.tenable.com/cve/CVE-2026-18988</a></p>

2026/8/8
阅读更多

CVE-2026-17595

<p>Medium Severity</p> <h3>Description</h3> <p>Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. This issue does not permit method invocation, object construction, or arbitrary code execution. This has been fixed by restricting property access in the JEXL sandbox to the intended data types.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-17595">https://www.tenable.com/cve/CVE-2026-17595</a></p>

2026/8/7
阅读更多

CVE-2026-17593

<p>High Severity</p> <h3>Description</h3> <p>An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because unrecognized entries were persisted and re-evaluated on every realm load via a legacy code path, this could result in unintended code executing inside the Nexus Repository process, and in some cases a persistent authentication lockout that was not visible through the administrative UI.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-17593">https://www.tenable.com/cve/CVE-2026-17593</a></p>

2026/8/7
阅读更多

CVE-2026-16955

<p>Medium Severity</p> <h3>Description</h3> <p>The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16955">https://www.tenable.com/cve/CVE-2026-16955</a></p>

2026/8/8
阅读更多

CVE-2026-16953

<p>High Severity</p> <h3>Description</h3> <p>The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's uploaded files.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16953">https://www.tenable.com/cve/CVE-2026-16953</a></p>

2026/8/8
阅读更多

CVE-2026-16948

<p>Medium Severity</p> <h3>Description</h3> <p>The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16948">https://www.tenable.com/cve/CVE-2026-16948</a></p>

2026/8/8
阅读更多

CVE-2026-16608

<p>High Severity</p> <h3>Description</h3> <p>The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16608">https://www.tenable.com/cve/CVE-2026-16608</a></p>

2026/8/8
阅读更多

CVE-2026-16595

<p>Medium Severity</p> <h3>Description</h3> <p>The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16595">https://www.tenable.com/cve/CVE-2026-16595</a></p>

2026/8/8
阅读更多

CVE-2026-16594

<p>Medium Severity</p> <h3>Description</h3> <p>The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16594">https://www.tenable.com/cve/CVE-2026-16594</a></p>

2026/8/8
阅读更多

CVE-2026-16590

<p>Medium Severity</p> <h3>Description</h3> <p>The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16590">https://www.tenable.com/cve/CVE-2026-16590</a></p>

2026/8/8
阅读更多

CVE-2026-16589

<p>High Severity</p> <h3>Description</h3> <p>The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16589">https://www.tenable.com/cve/CVE-2026-16589</a></p>

2026/8/8
阅读更多

CVE-2026-16578

<p>Medium Severity</p> <h3>Description</h3> <p>The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpoints, allowing unauthenticated attackers to retrieve the full list of registered users including their usernames, email addresses, roles, and two-factor authentication enrollment status.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16578">https://www.tenable.com/cve/CVE-2026-16578</a></p>

2026/8/8
阅读更多

CVE-2026-16574

<p>Medium Severity</p> <h3>Description</h3> <p>The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free download access to another vendor's paid downloadable files.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16574">https://www.tenable.com/cve/CVE-2026-16574</a></p>

2026/8/8
阅读更多

CVE-2026-16562

<p>Medium Severity</p> <h3>Description</h3> <p>The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16562">https://www.tenable.com/cve/CVE-2026-16562</a></p>

2026/8/8
阅读更多

CVE-2026-16559

<p>High Severity</p> <h3>Description</h3> <p>The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16559">https://www.tenable.com/cve/CVE-2026-16559</a></p>

2026/8/8
阅读更多

CVE-2026-16558

<p>Critical Severity</p> <h3>Description</h3> <p>The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is saved, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any visitor viewing an affected filter.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16558">https://www.tenable.com/cve/CVE-2026-16558</a></p>

2026/8/8
阅读更多

CVE-2026-16535

<p>Medium Severity</p> <h3>Description</h3> <p>The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16535">https://www.tenable.com/cve/CVE-2026-16535</a></p>

2026/8/8
阅读更多

CVE-2026-16282

<p>Critical Severity</p> <h3>Description</h3> <p>The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting booking and payment records.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16282">https://www.tenable.com/cve/CVE-2026-16282</a></p>

2026/8/8
阅读更多

CVE-2026-16269

<p>Critical Severity</p> <h3>Description</h3> <p>The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when the optional API has been enabled.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16269">https://www.tenable.com/cve/CVE-2026-16269</a></p>

2026/8/8
阅读更多

CVE-2026-16267

<p>Critical Severity</p> <h3>Description</h3> <p>The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-16267">https://www.tenable.com/cve/CVE-2026-16267</a></p>

2026/8/8
阅读更多

CVE-2026-14644

<p>High Severity</p> <h3>Description</h3> <p>Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw in the privilege update endpoint.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-14644">https://www.tenable.com/cve/CVE-2026-14644</a></p>

2026/8/7
阅读更多

CVE-2026-14541

<p>Critical Severity</p> <h3>Description</h3> <p>An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth access token—even those minted for unrelated ecosystem applications—granting unauthorized clients access to protected tools and data backends.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-14541">https://www.tenable.com/cve/CVE-2026-14541</a></p>

2026/7/31
阅读更多

CVE-2026-14540

<p>Critical Severity</p> <h3>Description</h3> <p>A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to safely regulate request redirection boundaries. Specifically, the client is initialized without a restrictive CheckRedirect policy hook and lacks target IP validation. An attacker or a malicious data-driven prompt can supply a crafted path parameter that triggers an open redirect or a direct destination swap on the target backend, coercing the mcp-toolbox into blindly following the redirection and making unauthorized requests to internal or arbitrary external endpoints.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-14540">https://www.tenable.com/cve/CVE-2026-14540</a></p>

2026/7/31
阅读更多

CVE-2026-14539

<p>High Severity</p> <h3>Description</h3> <p>An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted buffer loop (io.ReadAll) without applying defensive constraints such as http.MaxBytesReader or pre-read Content-Length enforcement. By submitting a single, massive HTTP request body, an attacker can linearly consume available host memory until the runtime process is terminated by an Out-Of-Memory (OOM) error.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-14539">https://www.tenable.com/cve/CVE-2026-14539</a></p>

2026/7/31
阅读更多

CVE-2026-14538

<p>High Severity</p> <h3>Description</h3> <p>An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset restrictions, but due to a fail-open logic flaw, it bypasses validation when the API returns an empty array for specialized constructs. This allows the attacker to extract structural DDL schemas for explicitly excluded datasets via INFORMATION_SCHEMA, and access downstream federated row data via EXTERNAL_QUERY connections.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-14538">https://www.tenable.com/cve/CVE-2026-14538</a></p>

2026/7/31
阅读更多

CVE-2026-14537

<p>Critical Severity</p> <h3>Description</h3> <p>Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-14537">https://www.tenable.com/cve/CVE-2026-14537</a></p>

2026/7/31
阅读更多

CVE-2026-14526

<p>Critical Severity</p> <h3>Description</h3> <p>The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new administrator-level user account and achieve full site takeover by saving and executing a malicious workflow containing a wp_create_user action node specifying role=administrator. This vulnerability is exploitable by unauthenticated attackers on any site where the [aiwu-form] shortcode or public chatbot is rendered on a frontend page, as the waic-nonce value is emitted into publicly accessible JavaScript (WAIC_DATA.waicNonce) on those pages, rendering the nonce check a non-functional authorization barrier.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-14526">https://www.tenable.com/cve/CVE-2026-14526</a></p>

2026/8/8
阅读更多

CVE-2026-13505

<p>High Severity</p> <h3>Description</h3> <p>In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and the PBKD and scrypt parameter classes was zeroised on garbage collection by overriding Object.finalize. Finalization runs at an unspecified time and in an unspecified order and is serviced by a single finalizer thread, so where objects carrying a finalizer are allocated faster than that thread retires them the pending-finalization queue grows without bound: disposal falls arbitrarily far behind, which can contribute to an OutOfMemoryError under load, and the key material those objects hold stays resident in the heap for as long as they are queued, defeating the purpose of the zeroisation. The behaviour was not a problem on Java 8 or Java 11; it is later JVMs, on which finalization has been deprecated and progressively de-emphasised, where it becomes one. Disposal of these classes now runs from a java.lang.ref.Cleaner registered in the multi-release jdk1.9 overlay, so on Java 9 and later it no longer depends on the finalizer being scheduled. Bouncy Castle for Java (bcprov) and Bouncy Castle for Java LTS are not affected, as neither implements the finalizer-based zeroisation scheme.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-13505">https://www.tenable.com/cve/CVE-2026-13505</a></p>

2026/8/8
阅读更多

CVE-2026-1289

<p>High Severity</p> <h3>Description</h3> <p>A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-1289">https://www.tenable.com/cve/CVE-2026-1289</a></p>

2026/8/6
阅读更多

CVE-2026-11907

<p>Medium Severity</p> <h3>Description</h3> <p>The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access all Stream activity records via the Heartbeat API.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-11907">https://www.tenable.com/cve/CVE-2026-11907</a></p>

2026/8/7
阅读更多

CVE-2026-11803

<p>High Severity</p> <h3>Description</h3> <p>A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-11803">https://www.tenable.com/cve/CVE-2026-11803</a></p>

2026/8/6
阅读更多

CVE-2026-11612

<p>Severity Not Scored</p> <h3>Description</h3> <p>Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-11612">https://www.tenable.com/cve/CVE-2026-11612</a></p>

2026/8/8
阅读更多

CVE-2026-10050

<p>High Severity</p> <h3>Description</h3> <p>In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`. An attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters. Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-10050">https://www.tenable.com/cve/CVE-2026-10050</a></p>

2026/8/4
阅读更多

CVE-2025-8419

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is limited to 64 characters (limited local part of the email), so the attack is limited to very shorts emails (subject and little data, the example is 60 chars). This flaw's only direct consequence is an unsolicited email being sent from the Keycloak server. However, this action could be a precursor for more sophisticated attacks.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-8419">https://www.tenable.com/cve/CVE-2025-8419</a></p>

2025/8/6
阅读更多

CVE-2025-7365

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to modify their email address to match that of a victim's account, triggering a verification email sent to the victim's email address. The attacker's email address is not present in the verification email content, making it a potential phishing opportunity. If the victim clicks the verification link, the attacker can gain access to the victim's account.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-7365">https://www.tenable.com/cve/CVE-2025-7365</a></p>

2025/7/10
阅读更多

CVE-2025-6947

<p>Medium Severity</p> <h3>Description</h3> <p>A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-6947">https://www.tenable.com/cve/CVE-2025-6947</a></p>

2025/9/15
阅读更多

CVE-2025-6946

<p>Medium Severity</p> <h3>Description</h3> <p>A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management ninterface of another management user.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-6946">https://www.tenable.com/cve/CVE-2025-6946</a></p>

2025/12/4
阅读更多

CVE-2025-49796

<p>Critical Severity</p> <h3>Description</h3> <p>A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-49796">https://www.tenable.com/cve/CVE-2025-49796</a></p>

2025/6/16
阅读更多

CVE-2025-49794

<p>Critical Severity</p> <h3>Description</h3> <p>A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-49794">https://www.tenable.com/cve/CVE-2025-49794</a></p>

2025/6/16
阅读更多

CVE-2025-4805

<p>Medium Severity</p> <h3>Description</h3> <p>A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-4805">https://www.tenable.com/cve/CVE-2025-4805</a></p>

2025/5/16
阅读更多

CVE-2025-4804

<p>Medium Severity</p> <h3>Description</h3> <p>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-4804">https://www.tenable.com/cve/CVE-2025-4804</a></p>

2025/5/16
阅读更多

CVE-2025-4106

<p>High Severity</p> <h3>Description</h3> <p>An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-4106">https://www.tenable.com/cve/CVE-2025-4106</a></p>

2025/10/24
阅读更多

CVE-2025-2782

<p>Medium Severity</p> <h3>Description</h3> <p>The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-2782">https://www.tenable.com/cve/CVE-2025-2782</a></p>

2025/3/28
阅读更多

CVE-2025-2781

<p>Medium Severity</p> <h3>Description</h3> <p>The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-2781">https://www.tenable.com/cve/CVE-2025-2781</a></p>

2025/3/28
阅读更多

CVE-2025-1910

<p>Medium Severity</p> <h3>Description</h3> <p>The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-1910">https://www.tenable.com/cve/CVE-2025-1910</a></p>

2025/12/4
阅读更多

CVE-2025-1239

<p>Medium Severity</p> <h3>Description</h3> <p>A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-1239">https://www.tenable.com/cve/CVE-2025-1239</a></p>

2025/2/14
阅读更多

CVE-2025-11393

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user within the cluster to send unauthorized commands to the management platform, effectively acting with the full permissions of the cluster administrator. This could lead to unauthorized changes to the cluster's configuration or status on the Red Hat platform.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-11393">https://www.tenable.com/cve/CVE-2025-11393</a></p>

2025/12/15
阅读更多

CVE-2025-1071

<p>Medium Severity</p> <h3>Description</h3> <p>A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-1071">https://www.tenable.com/cve/CVE-2025-1071</a></p>

2025/2/14
阅读更多

CVE-2025-0178

<p>Medium Severity</p> <h3>Description</h3> <p>An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into responses sent by the Web UI.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2025-0178">https://www.tenable.com/cve/CVE-2025-0178</a></p>

2025/2/14
阅读更多

CVE-2024-9621

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP logging enabled, application set client, and endpoint logging properties, and the attacker must have access to the application log.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-9621">https://www.tenable.com/cve/CVE-2024-9621</a></p>

2024/10/8
阅读更多

CVE-2024-9355

<p>High Severity</p> <h3>Description</h3> <p>A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-9355">https://www.tenable.com/cve/CVE-2024-9355</a></p>

2024/10/1
阅读更多

CVE-2024-8424

<p>High Severity</p> <h3>Description</h3> <p>Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-8424">https://www.tenable.com/cve/CVE-2024-8424</a></p>

2024/11/8
阅读更多

CVE-2024-6594

<p>High Severity</p> <h3>Description</h3> <p>Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-On service by repeatedly issuing malformed commands.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-6594">https://www.tenable.com/cve/CVE-2024-6594</a></p>

2024/9/25
阅读更多

CVE-2024-6593

<p>Critical Severity</p> <h3>Description</h3> <p>Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or tamper with the agent configuration. This vulnerability cannot be used by an attacker to gain access to user credentials.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-6593">https://www.tenable.com/cve/CVE-2024-6593</a></p>

2024/9/25
阅读更多

CVE-2024-6592

<p>Critical Severity</p> <h3>Description</h3> <p>An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-6592">https://www.tenable.com/cve/CVE-2024-6592</a></p>

2024/9/25
阅读更多

CVE-2024-5971

<p>High Severity</p> <h3>Description</h3> <p>A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource consumption, leaving the server side to a denial of service attack. This happens only with Java 17 TLSv1.3 scenarios.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-5971">https://www.tenable.com/cve/CVE-2024-5971</a></p>

2024/7/8
阅读更多

CVE-2024-10973

<p>Medium Severity</p> <h3>Description</h3> <p>A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent networks related to JGroups to read sensitive information.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2024-10973">https://www.tenable.com/cve/CVE-2024-10973</a></p>

2024/12/17
阅读更多

CVE-2026-9205

<p>Critical Severity</p> <h3>Description</h3> <p>IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9205">https://www.tenable.com/cve/CVE-2026-9205</a></p>

2026/8/5
阅读更多

CVE-2026-9203

<p>High Severity</p> <h3>Description</h3> <p>A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9203">https://www.tenable.com/cve/CVE-2026-9203</a></p>

2026/8/5
阅读更多

CVE-2026-9196

<p>High Severity</p> <h3>Description</h3> <p>IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user approval, which may allow an attacker to trigger side effects such as outbound network access, file system interaction, or data exfiltration with the privileges of the Langflow backend process.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9196">https://www.tenable.com/cve/CVE-2026-9196</a></p>

2026/8/5
阅读更多

CVE-2026-9193

<p>Critical Severity</p> <h3>Description</h3> <p>An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9193">https://www.tenable.com/cve/CVE-2026-9193</a></p>

2026/8/5
阅读更多

CVE-2026-9192

<p>Critical Severity</p> <h3>Description</h3> <p>An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9192">https://www.tenable.com/cve/CVE-2026-9192</a></p>

2026/8/5
阅读更多

CVE-2026-9190

<p>Critical Severity</p> <h3>Description</h3> <p>An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9190">https://www.tenable.com/cve/CVE-2026-9190</a></p>

2026/8/5
阅读更多

CVE-2026-9169

<p>High Severity</p> <h3>Description</h3> <p>DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9169">https://www.tenable.com/cve/CVE-2026-9169</a></p>

2026/8/7
阅读更多

CVE-2026-9130

<p>High Severity</p> <h3>Description</h3> <p>IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on session_id without validating flow_id or user_id ownership, enabling cross-user information disclosure through multiple authenticated API endpoints including /api/v1/run/*, /api/v1/responses, and /api/v2/workflow/*. This vulnerability only affects multi-user deployments with LANGFLOW_AUTO_LOGIN=False.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9130">https://www.tenable.com/cve/CVE-2026-9130</a></p>

2026/8/5
阅读更多

CVE-2026-9044

<p>High Severity</p> <h3>Description</h3> <p>An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special characters. Successful exploitation of this vulnerability may enable an attacker to gain full control of the affected device, potentially compromising configuration integrity, network security, and service availability.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9044">https://www.tenable.com/cve/CVE-2026-9044</a></p>

2026/7/31
阅读更多

CVE-2026-9031

<p>Medium Severity</p> <h3>Description</h3> <p>An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic. Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9031">https://www.tenable.com/cve/CVE-2026-9031</a></p>

2026/8/7
阅读更多

CVE-2026-9030

<p>Medium Severity</p> <h3>Description</h3> <p>A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations. By sending crafted systool instructions through the asynchronous request path, successful exploitation may cause the httpd process or device management service to crash and may result in temporary loss of access to the web management interface or device reboot.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9030">https://www.tenable.com/cve/CVE-2026-9030</a></p>

2026/8/7
阅读更多

CVE-2026-8709

<p>Critical Severity</p> <h3>Description</h3> <p>An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-8709">https://www.tenable.com/cve/CVE-2026-8709</a></p>

2026/8/5
阅读更多

CVE-2026-7557

<p>Critical Severity</p> <h3>Description</h3> <p>An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-7557">https://www.tenable.com/cve/CVE-2026-7557</a></p>

2026/8/5
阅读更多

CVE-2026-7406

<p>High Severity</p> <h3>Description</h3> <p>A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-7406">https://www.tenable.com/cve/CVE-2026-7406</a></p>

2026/8/6
阅读更多

CVE-2026-7405

<p>Medium Severity</p> <h3>Description</h3> <p>A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-7405">https://www.tenable.com/cve/CVE-2026-7405</a></p>

2026/8/6
阅读更多

CVE-2026-7329

<p>Critical Severity</p> <h3>Description</h3> <p>An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-7329">https://www.tenable.com/cve/CVE-2026-7329</a></p>

2026/8/5
阅读更多

CVE-2026-7327

<p>High Severity</p> <h3>Description</h3> <p>An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-7327">https://www.tenable.com/cve/CVE-2026-7327</a></p>

2026/8/5
阅读更多

CVE-2026-7326

<p>High Severity</p> <h3>Description</h3> <p>A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-7326">https://www.tenable.com/cve/CVE-2026-7326</a></p>

2026/8/5
阅读更多

CVE-2026-71870

<p>Medium Severity</p> <h3>Description</h3> <p>pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a font /ToUnicode CMap during text extraction. This issue is fixed in 6.15.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71870">https://www.tenable.com/cve/CVE-2026-71870</a></p>

2026/8/7
阅读更多

CVE-2026-71852

<p>Medium Severity</p> <h3>Description</h3> <p>pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /W width ranges or excessive width entries during text extraction. This issue is fixed in 6.15.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71852">https://www.tenable.com/cve/CVE-2026-71852</a></p>

2026/8/7
阅读更多

CVE-2026-71850

<p>Medium Severity</p> <h3>Description</h3> <p>Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders with comparator equal props, and request scoped values read inside the component take no part in that comparison, so a response can contain HTML rendered for another user's request. Components wrapped with memo() are compared by props alone; values read implicitly during rendering, such as JSX Context through createContext() and useContext(), useRequestContext() from hono/jsx-renderer, and getContext() from hono/context-storage, do not participate, and the retained result lives as long as the wrapped component, so it outlives the request that produced it. A user may receive a response containing HTML rendered for another user when both render the same memoized component with comparator equal props on the same warm instance, which may disclose another user's account or profile data, disclose request scoped secrets embedded in HTML such as CSRF tokens, or expose role specific content to users who should not receive it. This issue is fixed in version 4.12.34.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71850">https://www.tenable.com/cve/CVE-2026-71850</a></p>

2026/8/7
阅读更多

CVE-2026-71849

<p>Low Severity</p> <h3>Description</h3> <p>Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin's Connection header. Per RFC 9110 Section 7.6.1, an intermediary must remove the header fields listed in a message's Connection header field before forwarding the message, in addition to the well known hop by hop headers, but the proxy() function only removed the well known hop by hop headers, including Connection itself, from origin responses. A client may therefore receive response headers that the origin intended only for its immediate peer, disclosing connection scoped or internal metadata contained in such headers, when an application proxies responses from an origin that declares additional, non standard headers as hop by hop via the Connection response header. This issue is fixed in version 4.12.34.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71849">https://www.tenable.com/cve/CVE-2026-71849</a></p>

2026/8/7
阅读更多

CVE-2026-71847

<p>High Severity</p> <h3>Description</h3> <p>Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released storage. When partial_value reconstructs an incomplete object containing duplicate keys, the duplicate-key warning path calls cursor_position, which dereferences those stale pointers. This results in a heap-use-after-free and can terminate the Ruby process. An attacker who can supply JSON stream data to an application using JSON::ResumableParser may cause process termination when the application calls partial_value on incomplete attacker-controlled input containing duplicate object keys. This issue has been fixed in version 2.21.2.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71847">https://www.tenable.com/cve/CVE-2026-71847</a></p>

2026/8/7
阅读更多

CVE-2026-71557

<p>Medium Severity</p> <h3>Description</h3> <p>go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71557">https://www.tenable.com/cve/CVE-2026-71557</a></p>

2026/8/7
阅读更多

CVE-2026-71556

<p>High Severity</p> <h3>Description</h3> <p>go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71556">https://www.tenable.com/cve/CVE-2026-71556</a></p>

2026/8/7
阅读更多

CVE-2026-71555

<p>Medium Severity</p> <h3>Description</h3> <p>PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that opens a new browsing context (e.g., target="_blank") retain a window.opener reference back to the originating PILOS tab. A malicious destination page reached this way can use window.opener to navigate or manipulate the original PILOS tab, a technique known as reverse tabnabbing, potentially redirecting an authenticated user to a phishing page that mimics PILOS. This issue is fixed in version 4.14.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71555">https://www.tenable.com/cve/CVE-2026-71555</a></p>

2026/8/6
阅读更多

CVE-2026-71498

<p>Medium Severity</p> <h3>Description</h3> <p>node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the allocated buffer while attempting to decode the final, incomplete code point. This could result in an out-of-bounds read and potential disclosure of adjacent memory contents. This issue is fixed in version 1.26.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71498">https://www.tenable.com/cve/CVE-2026-71498</a></p>

2026/8/6
阅读更多

CVE-2026-71497

<p>Medium Severity</p> <h3>Description</h3> <p>jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a different element. When a custom Safelist permits certain raw-text elements, this misparsing can cause content that should remain inert text to be emitted as active markup after serialization, potentially resulting in cross-site scripting. jsoup's built-in Safelists are not affected. This issue is fixed in version 1.23.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71497">https://www.tenable.com/cve/CVE-2026-71497</a></p>

2026/8/6
阅读更多

CVE-2026-71488

<p>High Severity</p> <h3>Description</h3> <p>league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate the remaining line at every URL-like prefix, allowing an attacker who can submit Markdown for conversion to consume disproportionate CPU time with a comparatively small request. This issue is fixed in 2.9.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71488">https://www.tenable.com/cve/CVE-2026-71488</a></p>

2026/8/6
阅读更多

CVE-2026-71478

<p>Medium Severity</p> <h3>Description</h3> <p>league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71478">https://www.tenable.com/cve/CVE-2026-71478</a></p>

2026/8/6
阅读更多

CVE-2026-71447

<p>Medium Severity</p> <h3>Description</h3> <p>AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages and forum posts. The affected templates inserted message and post identifiers directly into inline JavaScript onclick handlers: onclick="translateMessageToPreferredLanguage('{{ message['id'] }}', '{{ mess_id_escape }}', this)" and: onclick="translatePostToPreferredLanguage('{{ post['id'] }}', '{{ post_id_escape }}', this)" These values were HTML-template escaped but were not safely encoded for use as JavaScript string literals inside an HTML attribute. A specially crafted identifier containing quotation marks, escape characters, or other JavaScript syntax could therefore terminate the expected string argument and inject arbitrary JavaScript into the event handler. Because the affected values are associated with indexed chat messages or forum posts, a malicious value may remain stored by AIL and be rendered whenever an analyst accesses the corresponding chat or forum explorer view. Successful exploitation requires the victim to click the affected Translate to preferred language button. The injected code would then execute in the victim’s browser under the security origin of the AIL instance.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71447">https://www.tenable.com/cve/CVE-2026-71447</a></p>

2026/8/6
阅读更多

CVE-2026-71446

<p>Medium Severity</p> <h3>Description</h3> <p>AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded directly into the JavaScript onclick handler used to display a stored screenshot, without context-appropriate encoding. An attacker who can cause a specially crafted URL to be recorded in the crawler history can inject JavaScript syntax into the stored URL value. The payload remains stored by AIL and is subsequently included in the domain view. When an authenticated analyst clicks the screenshot icon associated with the malicious URL, the injected JavaScript executes in the analyst’s browser within the security context of the AIL Framework application. Successful exploitation could allow an attacker to access information available to the analyst’s session, modify displayed content, or perform application actions using the analyst’s privileges. Exploitation requires the victim to interact with the affected screenshot entry. The vulnerability was corrected by serializing the crawled URL with Jinja’s tojson filter before inserting it into the JavaScript handler. This safely escapes characters that could otherwise terminate the JavaScript string and introduce executable code.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71446">https://www.tenable.com/cve/CVE-2026-71446</a></p>

2026/8/6
阅读更多

CVE-2026-71445

<p>High Severity</p> <h3>Description</h3> <p>AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the error value directly as an HTML response using str(res[0]). If attacker-controlled input was included in the generated error message, a crafted request could cause arbitrary HTML or JavaScript to be reflected in the response without appropriate output encoding. An attacker could exploit the vulnerability by convincing an authenticated AIL Framework user to open a specially crafted link. Successful exploitation could allow JavaScript to execute in the victim’s browser within the security context of the AIL Framework application. Depending on the victim’s privileges and the application’s protections, the attacker could perform actions using the victim’s session, access information available to the victim, or modify data through authenticated application requests. The vulnerability requires user interaction because the authenticated victim must follow or open the crafted request. The attacker does not necessarily require an AIL Framework account, provided that the crafted request can be delivered to an already authenticated user.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71445">https://www.tenable.com/cve/CVE-2026-71445</a></p>

2026/8/6
阅读更多

CVE-2026-71439

<p>Medium Severity</p> <h3>Description</h3> <p>Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage or JavaScript process for long periods of time, potentially until the process is killed from memory exhaustion. This issue is fixed in version 11.16.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71439">https://www.tenable.com/cve/CVE-2026-71439</a></p>

2026/8/6
阅读更多

CVE-2026-71438

<p>Low Severity</p> <h3>Description</h3> <p>Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConfig) merge caller-supplied configuration into Mermaid's internal config using the assignWithDepth deep-merge helper, which is vulnerable to prototype pollution. This is only exploitable if an application forwards untrusted data directly into one of these configuration entry points, which is outside their documented usage; diagram-supplied configuration (e.g. %%{init: {}}%% or YAML frontmatter) is not affected. This issue is fixed in versions 10.9.8 and 11.16.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71438">https://www.tenable.com/cve/CVE-2026-71438</a></p>

2026/8/6
阅读更多

CVE-2026-71437

<p>Medium Severity</p> <h3>Description</h3> <p>Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are vulnerable to prototype pollution when a diagram defines a group with an id of __proto__. Because the group id is used directly as an object property key without validation, an attacker who can supply diagram text can pollute Object.prototype, potentially affecting the behavior of the embedding application. This issue is fixed in version 11.16.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71437">https://www.tenable.com/cve/CVE-2026-71437</a></p>

2026/8/6
阅读更多

CVE-2026-71436

<p>Medium Severity</p> <h3>Description</h3> <p>Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisRangeData function when configuring an X-Axis with invalid parameters. Because each loop iteration appends an element to an array, this generally causes a RangeError to appear after a few seconds, but it may instead cause the page or JavaScript process to crash from memory exhaustion, depending on the environment. This issue is fixed in versions 10.9.8 and 11.16.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71436">https://www.tenable.com/cve/CVE-2026-71436</a></p>

2026/8/6
阅读更多

CVE-2026-71434

<p>Medium Severity</p> <h3>Description</h3> <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could upload file types an administrator had intended to disallow through a form's assets or files field, and for assets fields, files could be stored on a public, web-accessible disk, though the application's global upload allowlist still blocked executable types such as .php and .html. This issue is fixed in versions 5.74.3 and 6.24.2.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71434">https://www.tenable.com/cve/CVE-2026-71434</a></p>

2026/8/6
阅读更多

CVE-2026-71433

<p>Medium Severity</p> <h3>Description</h3> <p>LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that string as a simple prefix pattern, so a read scoped to one namespace could also match a sibling namespace whose flattened form shares the same leading characters, or a namespace label containing unescaped pattern metacharacters, allowing an authenticated caller to retrieve stored items belonging to another tenant or user through an ordinary scoped search or list namespaces call, with no crafted input required. This issue is fixed in versions 3.1.1 of langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71433">https://www.tenable.com/cve/CVE-2026-71433</a></p>

2026/8/6
阅读更多

CVE-2026-71430

<p>Medium Severity</p> <h3>Description</h3> <p>node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V8 returns when the resulting string or buffer exceeds V8's maximum string length. When a global replace uses an output amplifying replacement template, the result can grow quadratically with the input size, and once the result exceeds V8's maximum string length, the unchecked ToLocalChecked call causes a fatal, uncatchable process abort instead of a catchable exception. This issue is fixed in version 1.25.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71430">https://www.tenable.com/cve/CVE-2026-71430</a></p>

2026/8/6
阅读更多

CVE-2026-71381

<p>Medium Severity</p> <h3>Description</h3> <p>Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could have leveraged this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue did not require user interaction, but required the attacker to have access to the local environment the application is installed on.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71381">https://www.tenable.com/cve/CVE-2026-71381</a></p>

2026/8/7
阅读更多

CVE-2026-71327

<p>High Severity</p> <h3>Description</h3> <p>Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71327">https://www.tenable.com/cve/CVE-2026-71327</a></p>

2026/8/6
阅读更多

CVE-2026-71325

<p>Medium Severity</p> <h3>Description</h3> <p>Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71325">https://www.tenable.com/cve/CVE-2026-71325</a></p>

2026/8/6
阅读更多

CVE-2026-71324

<p>High Severity</p> <h3>Description</h3> <p>Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a shared net/http.Transport. When the upstream answers the CONNECT with a keep-alive non-2xx response and does not drain the body, Traefik returns the desynchronized backend socket to its shared pool and reuses it for other clients. An unauthenticated attacker can use this behavior to make a different client read the attacker's smuggled response, which can include authenticated or private content from another request. The ForwardAuth middleware with forwardBody true and preserveRequestMethod true can re-issue a CONNECT with the buffered body attached, exposing the auth-client pool to the same desynchronization. This issue is fixed in 2.11.53, 3.6.24, and 3.7.9.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71324">https://www.tenable.com/cve/CVE-2026-71324</a></p>

2026/8/6
阅读更多

CVE-2026-71320

<p>High Severity</p> <h3>Description</h3> <p>Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing template execution in the Nitro process. This issue is fixed in 3.21.10 and 4.5.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71320">https://www.tenable.com/cve/CVE-2026-71320</a></p>

2026/8/5
阅读更多

CVE-2026-71319

<p>Critical Severity</p> <h3>Description</h3> <p>Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://<host>:<port>/, subprotocol vite-hmr) can call RPC methods, with no token, handshake, or origin check before the channel is established. The updateOptions(), clearOptions(), and openInEditor() methods do not enforce the ensureDevAuthToken check that the other mutating methods use. openInEditor() reads the persisted behavior.openInEditor value and passes it to the launch-editor package, which spawns it as a child process. That value is settable through the equally unauthenticated updateOptions(). An attacker who can reach the HMR port can therefore chain updateOptions('behavior', { openInEditor: '<command>' }) then openInEditor('<any-existing-file>') to execute an arbitrary program on the developer's machine. This issue is fixed in 3.3.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71319">https://www.tenable.com/cve/CVE-2026-71319</a></p>

2026/8/5
阅读更多

CVE-2026-71312

<p>High Severity</p> <h3>Description</h3> <p>rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controlled filename to terminate the intended path literal and append PowerShell statements that execute as the victim SSH account when server-side hashing is invoked. This issue is fixed in v1.75.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-71312">https://www.tenable.com/cve/CVE-2026-71312</a></p>

2026/8/5
阅读更多

CVE-2026-70640

<p>High Severity</p> <h3>Description</h3> <p>llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while Thread B concurrently frees the llama_context. Attackers can exploit this by performing heap spray with attacker-controlled data containing a fake vtable to hijack the vtable pointer at offset +0x30, causing llama_batch_allocr::clear() to dereference arbitrary memory and achieve remote code execution.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70640">https://www.tenable.com/cve/CVE-2026-70640</a></p>

2026/8/6
阅读更多

CVE-2026-70639

<p>Medium Severity</p> <h3>Description</h3> <p>llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model context pointer before dereferencing it. Attackers can supply a malicious, corrupt, or truncated model file to trigger a null context condition, causing a SIGSEGV crash that terminates the Android application process and results in denial of service.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70639">https://www.tenable.com/cve/CVE-2026-70639</a></p>

2026/8/6
阅读更多

CVE-2026-70638

<p>High Severity</p> <h3>Description</h3> <p>llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocation to wrap and allocate insufficient memory. Attackers can exploit this by providing a crafted n_seq_max value through a malicious model file or JNI call to trigger heap corruption and achieve denial of service or arbitrary code execution on Android applications using the LLaMA-Android binding.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70638">https://www.tenable.com/cve/CVE-2026-70638</a></p>

2026/8/6
阅读更多

CVE-2026-70635

<p>High Severity</p> <h3>Description</h3> <p>TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with direct DML access to a non-frozen physical compressed hypertable relation can trigger an out-of-bounds read before the base of the live offsets array through the VectorAgg single-text hashing strategy, resulting in incorrect aggregation output, backend SIGSEGV, or PostgreSQL crash recovery depending on build configuration.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70635">https://www.tenable.com/cve/CVE-2026-70635</a></p>

2026/8/6
阅读更多

CVE-2026-70634

<p>High Severity</p> <h3>Description</h3> <p>TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML access to a physical compressed relation can store a crafted datum and run a reverse-order scan. With a pass-by-value column type the out-of-bounds Datum is returned to the client as a normal column value, disclosing backend memory including the shared buffer pool, which SQL access control does not cover.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70634">https://www.tenable.com/cve/CVE-2026-70634</a></p>

2026/8/6
阅读更多

CVE-2026-70633

<p>High Severity</p> <h3>Description</h3> <p>TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator that allows authenticated attackers to cause a denial of service by storing a crafted compressed datum with an internally inconsistent BitArray. Attackers with DML access to a compressed hypertable can trigger an unsigned integer wraparound in the reverse iterator bucket index computation, causing a read beyond the end of the bucket array, resulting in a SIGSEGV crash that can be repeatedly triggered on each subsequent reverse-order scan.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70633">https://www.tenable.com/cve/CVE-2026-70633</a></p>

2026/8/6
阅读更多

CVE-2026-70632

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70632">https://www.tenable.com/cve/CVE-2026-70632</a></p>

2026/8/6
阅读更多

CVE-2026-70630

<p>Medium Severity</p> <h3>Description</h3> <p>FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid zlib stream that decompresses fewer bytes than the full frame requires. The screenpresso_decode_frame() function fails to validate the produced byte count before calling av_image_copy_plane() to copy the complete frame dimensions from the persistent ctx->inflated_buf buffer, causing unwritten heap memory from prior allocations or prior frames to be copied into decoded output and potentially exposing sensitive data such as userspace addresses from persistent decoding services.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70630">https://www.tenable.com/cve/CVE-2026-70630</a></p>

2026/8/6
阅读更多

CVE-2026-70629

<p>Medium Severity</p> <h3>Description</h3> <p>FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70629">https://www.tenable.com/cve/CVE-2026-70629</a></p>

2026/8/6
阅读更多

CVE-2026-70628

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70628">https://www.tenable.com/cve/CVE-2026-70628</a></p>

2026/8/6
阅读更多

CVE-2026-70624

<p>Severity Not Scored</p> <h3>Description</h3> <p>Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70624">https://www.tenable.com/cve/CVE-2026-70624</a></p>

2026/8/7
阅读更多

CVE-2026-70623

<p>Severity Not Scored</p> <h3>Description</h3> <p>Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70623">https://www.tenable.com/cve/CVE-2026-70623</a></p>

2026/8/7
阅读更多

CVE-2026-70561

<p>High Severity</p> <h3>Description</h3> <p>TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the attachmentdownload.php handler without any project or role authorization check. Attackers can enumerate sequential integer IDs through the attachment download endpoint to retrieve file contents from private projects they have no membership in, bypassing the per-project access control model and exposing test specifications, requirements documents, execution evidence, and other sensitive uploaded files across the entire installation.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70561">https://www.tenable.com/cve/CVE-2026-70561</a></p>

2026/8/7
阅读更多

CVE-2026-70559

<p>High Severity</p> <h3>Description</h3> <p>Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role check. Any remote unauthenticated caller who can reach the Dinky HTTP port (8888 by default) receives the full live system configuration (54 entries on a stock v1.2.5 install) with one parameterless GET. Only one credential field (sys.maven.settings.repositoryPassword) has a desensitization handler wired; the other credential-bearing fields (sys.env.settings.dinkyToken, sys.ldap.settings.userPassword, sys.resource.settings.oss.accessKey and secretKey, and sys.dolphinscheduler.settings.token) return in cleartext. A bare install leaks the shipped defaults, including the hardcoded dinkyToken efda1551-7958-4e0f-80a8-dfd107df3e38 and minioadmin/minioadmin OSS keys; once an operator configures LDAP, object storage, or DolphinScheduler through the Settings Center, those live third-party credentials leak from the same endpoint. Because dinkyToken is the sole gate on the sibling POST /download/uploadFromRsByLocal arbitrary file write, this disclosure defeats token rotation as a mitigation for that vulnerability. Affects Dinky v1.2.5 (the current release, 2025-11-05) and the development branch (dev HEAD 63b5a5a), where the affected code is byte-identical.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70559">https://www.tenable.com/cve/CVE-2026-70559</a></p>

2026/8/6
阅读更多

CVE-2026-70557

<p>High Severity</p> <h3>Description</h3> <p>diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those values for all rows, with no field or entity allowlist. The only guard, relatedDataSecurityCheck(), returns true unconditionally, so any authenticated user (including a zero-role account) can read @JsonIgnore-annotated secret fields such as IamAccount.authSecret and IamAccount.secretSalt for every account, or arbitrary secret fields of any other entity. Shiro's two-iteration MD5 with an 8-character salt is trivially crackable offline, so the disclosed admin password hashes convert to full administrative takeover. The endpoint is not example code; the official diboot-admin-ui frontend requires it, so deployments following the vendor's recommended integration expose it. The mechanism was renamed relatedData* to attachMore* on the development branch, but attachMoreSecurityCheck() also returns true unconditionally.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70557">https://www.tenable.com/cve/CVE-2026-70557</a></p>

2026/8/6
阅读更多

CVE-2026-70332

<p>Critical Severity</p> <h3>Description</h3> <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-70332">https://www.tenable.com/cve/CVE-2026-70332</a></p>

2026/8/7
阅读更多

CVE-2026-69207

<p>Medium Severity</p> <h3>Description</h3> <p>Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS request, the middleware parses the attacker-controlled Access-Control-Request-Headers header using a whitespace-tolerant regular expression whose backtracking makes its running time quadratic in the input length. Because the header value is bounded only by the deployment's maximum HTTP header size, a single preflight carrying a long run of whitespace can consume seconds of CPU and block request processing. On runtimes that share one execution thread across requests, this stalls concurrent requests as well, and repeated requests can render the service unresponsive. This affects the default configuration, since the vulnerable path is reached whenever cors() is used with an unset or empty allowHeaders. Applications that set a non-empty allowHeaders are not affected. This issue is fixed in version 4.12.34.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-69207">https://www.tenable.com/cve/CVE-2026-69207</a></p>

2026/8/7
阅读更多

CVE-2026-69127

<p>Medium Severity</p> <h3>Description</h3> <p>Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affects all Kirby sites that have not disabled the REST API with the 'api' => false option. This issue is fixed in versions 4.9.5 and 5.5.2.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-69127">https://www.tenable.com/cve/CVE-2026-69127</a></p>

2026/8/7
阅读更多

CVE-2026-68823

<p>Critical Severity</p> <h3>Description</h3> <p>Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68823">https://www.tenable.com/cve/CVE-2026-68823</a></p>

2026/8/7
阅读更多

CVE-2026-68750

<p>High Severity</p> <h3>Description</h3> <p>Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat run of sibling elements in sanitized HTML. The list clause of HtmlSanitizeEx.Traverser.traverse/2 recurses on the tail of a sibling list and then evaluates List.flatten([head] ++ tail) over the already flattened result, so every one of n siblings copies and re-walks the entire remaining tail. The flattening is only needed for the rare case where scrub returns several replacement nodes for one node, but the cost is paid across the whole tail at every step, making traversal quadratic in sibling count. The traverser sits on every public entry point, so no particular scrubber or configuration is required and the payload needs only allowed tags. A 160 KB body of 20,000 sibling elements occupies a scheduler for roughly 1.7 seconds, and the cost grows faster than the body does. This issue affects html_sanitize_ex: from 0.3.1 before 1.5.3.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68750">https://www.tenable.com/cve/CVE-2026-68750</a></p>

2026/8/6
阅读更多

CVE-2026-68749

<p>High Severity</p> <h3>Description</h3> <p>Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS declaration in sanitized HTML. The declaration regex in HtmlSanitizeEx.Scrubber.CSS.scrub/1 matches the property name with an unbounded greedy [-\w]+ followed by a mandatory :, so a long run of word characters not followed by a colon makes the engine give back one character at a time and retry the colon at every start offset. The work is quadratic in the length of the run, and no length cap is applied to the CSS handed to the scrubber. An 80 KB <style> body costs roughly 2.4 seconds of scheduler time, so a few concurrent requests saturate the BEAM scheduler pool and make the application unresponsive. The impact is CPU exhaustion only. Nothing is read, modified or disclosed. This issue affects html_sanitize_ex: from 0.3.1 before 1.5.3.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68749">https://www.tenable.com/cve/CVE-2026-68749</a></p>

2026/8/6
阅读更多

CVE-2026-68747

<p>Low Severity</p> <h3>Description</h3> <p>Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to inject CSS at-rules, including an import of a remote stylesheet, into a page served to other users. HtmlSanitizeEx.Scrubber.CSS.scrub/1 applies its property and value allowlist through a Regex.replace over substrings matching a property: value declaration pattern, so input that does not match that pattern is never inspected and is copied to the output unchanged. @import url(//attacker.example/style.css); survives, while the same URL inside a background: url(...) declaration is removed. Element boundaries are resolved before the scrubber runs, so injected content does not escape the <style> element and no script executes. This issue affects html_sanitize_ex: from 0.3.1 before 1.5.4.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68747">https://www.tenable.com/cve/CVE-2026-68747</a></p>

2026/8/6
阅读更多

CVE-2026-68481

<p>High Severity</p> <h3>Description</h3> <p>In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68481">https://www.tenable.com/cve/CVE-2026-68481</a></p>

2026/8/6
阅读更多

CVE-2026-68079

<p>Critical Severity</p> <h3>Description</h3> <p>In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68079">https://www.tenable.com/cve/CVE-2026-68079</a></p>

2026/8/6
阅读更多

CVE-2026-68074

<p>High Severity</p> <h3>Description</h3> <p>A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68074">https://www.tenable.com/cve/CVE-2026-68074</a></p>

2026/8/5
阅读更多

CVE-2026-68060

<p>High Severity</p> <h3>Description</h3> <p>A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-68060">https://www.tenable.com/cve/CVE-2026-68060</a></p>

2026/8/5
阅读更多

CVE-2026-67863

<p>High Severity</p> <h3>Description</h3> <p>In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local MonitoredItem. This allows a remote attacker to cause a denial of service.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67863">https://www.tenable.com/cve/CVE-2026-67863</a></p>

2026/8/5
阅读更多

CVE-2026-67689

<p>Critical Severity</p> <h3>Description</h3> <p>SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67689">https://www.tenable.com/cve/CVE-2026-67689</a></p>

2026/8/6
阅读更多

CVE-2026-67688

<p>Critical Severity</p> <h3>Description</h3> <p>ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67688">https://www.tenable.com/cve/CVE-2026-67688</a></p>

2026/8/6
阅读更多

CVE-2026-67687

<p>High Severity</p> <h3>Description</h3> <p>Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleController.java and system/user/update endpoint in UserController.java</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67687">https://www.tenable.com/cve/CVE-2026-67687</a></p>

2026/8/6
阅读更多

CVE-2026-67622

<p>High Severity</p> <h3>Description</h3> <p>Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces by exploiting the missing workspace-scoped authorization check in the credential lookup logic.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67622">https://www.tenable.com/cve/CVE-2026-67622</a></p>

2026/8/6
阅读更多

CVE-2026-67621

<p>High Severity</p> <h3>Description</h3> <p>Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67621">https://www.tenable.com/cve/CVE-2026-67621</a></p>

2026/8/6
阅读更多

CVE-2026-67592

<p>High Severity</p> <h3>Description</h3> <p>It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67592">https://www.tenable.com/cve/CVE-2026-67592</a></p>

2026/8/5
阅读更多

CVE-2026-67591

<p>Medium Severity</p> <h3>Description</h3> <p>An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67591">https://www.tenable.com/cve/CVE-2026-67591</a></p>

2026/8/5
阅读更多

CVE-2026-67590

<p>High Severity</p> <h3>Description</h3> <p>A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67590">https://www.tenable.com/cve/CVE-2026-67590</a></p>

2026/8/5
阅读更多

CVE-2026-67589

<p>High Severity</p> <h3>Description</h3> <p>A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67589">https://www.tenable.com/cve/CVE-2026-67589</a></p>

2026/8/5
阅读更多

CVE-2026-67588

<p>High Severity</p> <h3>Description</h3> <p>A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67588">https://www.tenable.com/cve/CVE-2026-67588</a></p>

2026/8/5
阅读更多

CVE-2026-67585

<p>High Severity</p> <h3>Description</h3> <p>Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted _entities representation keys. Every key of every object in the representations argument of the federation-mandated _entities field is converted with String.to_atom/1 by convert_key/2 in lib/absinthe/federation/schema/entities_field.ex. representations is typed as the open-ended _Any scalar, so its keys bypass schema coercion and the attacker names them freely. Atoms are never garbage collected and the BEAM atom table is hard-capped (about 1,048,576 entries by default), so one request carrying tens of thousands of unique keys creates that many permanent atoms and a handful of such requests exhausts the table and aborts the node. The impact is confined to availability: no data is read or altered, and recovery requires restarting the application. This issue affects absinthe_federation: from 0.1.0 before 0.9.3.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67585">https://www.tenable.com/cve/CVE-2026-67585</a></p>

2026/8/7
阅读更多

CVE-2026-67555

<p>Medium Severity</p> <h3>Description</h3> <p>It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67555">https://www.tenable.com/cve/CVE-2026-67555</a></p>

2026/8/5
阅读更多

CVE-2026-67554

<p>Medium Severity</p> <h3>Description</h3> <p>An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67554">https://www.tenable.com/cve/CVE-2026-67554</a></p>

2026/8/5
阅读更多

CVE-2026-67553

<p>Medium Severity</p> <h3>Description</h3> <p>An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67553">https://www.tenable.com/cve/CVE-2026-67553</a></p>

2026/8/5
阅读更多

CVE-2026-67552

<p>High Severity</p> <h3>Description</h3> <p>A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67552">https://www.tenable.com/cve/CVE-2026-67552</a></p>

2026/8/5
阅读更多

CVE-2026-67551

<p>High Severity</p> <h3>Description</h3> <p>pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67551">https://www.tenable.com/cve/CVE-2026-67551</a></p>

2026/8/5
阅读更多

CVE-2026-67465

<p>High Severity</p> <h3>Description</h3> <p>A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67465">https://www.tenable.com/cve/CVE-2026-67465</a></p>

2026/8/5
阅读更多

CVE-2026-67434

<p>High Severity</p> <h3>Description</h3> <p>PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as " and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67434">https://www.tenable.com/cve/CVE-2026-67434</a></p>

2026/8/6
阅读更多

CVE-2026-67422

<p>High Severity</p> <h3>Description</h3> <p>pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in exponentially many ways, causing catastrophic backtracking. As a result, a single untrusted Markdown line under 50 bytes rendered with markdown.markdown() in each extension's default configuration drives the rendering thread into unbounded CPU usage that grows exponentially with input length, enabling an unauthenticated remote attacker who can submit Markdown to cause denial of service. The exposure is concrete for web applications that render user-supplied Markdown (comments, wikis, issue bodies, live preview), including any app using pymdownx.extra which bundles the vulnerable betterem default, as well as hosted docs/CI systems that build untrusted Markdown. The issue has been fixed in version 11.0.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67422">https://www.tenable.com/cve/CVE-2026-67422</a></p>

2026/8/6
阅读更多

CVE-2026-67261

<p>Critical Severity</p> <h3>Description</h3> <p>Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-67261">https://www.tenable.com/cve/CVE-2026-67261</a></p>

2026/8/6
阅读更多

CVE-2026-66914

<p>Critical Severity</p> <h3>Description</h3> <p>Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66914">https://www.tenable.com/cve/CVE-2026-66914</a></p>

2026/8/7
阅读更多

CVE-2026-66909

<p>Critical Severity</p> <h3>Description</h3> <p>Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66909">https://www.tenable.com/cve/CVE-2026-66909</a></p>

2026/8/6
阅读更多

CVE-2026-66843

<p>Low Severity</p> <h3>Description</h3> <p>Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an <object> element in sanitized HTML. object is the one URI-bearing element in lib/html_sanitize_ex/scrubber/html5.ex never registered through allow_tag_with_uri_attributes/3, and its only guard is a prefix match on lowercase "javascript:", so mixed-case variants, data: URIs, protocol-relative URLs and same-origin paths all survive. This is not unconditional cross-site scripting. A javascript: URL does not execute through <object data> in current browsers, data: documents load in an opaque origin, and host-origin script execution additionally requires the application to serve attacker-controlled content from a same-origin path. This issue affects html_sanitize_ex: from 0.3.1 before 1.5.3.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66843">https://www.tenable.com/cve/CVE-2026-66843</a></p>

2026/8/6
阅读更多

CVE-2026-66838

<p>Medium Severity</p> <h3>Description</h3> <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. An attacker who can influence that value can close the comment delimiter with */ and extend the streamed statement with their own clauses, which execute under the connection's role. Ecto exposes the same option through Ecto.Repo.stream/2. Postgrex appends the comment by concatenating it into the statement text sent in the Parse message, without escaping or rejecting */. The option is validated by comment_not_present!/1 at every other execution point; stream/4 never calls it. Because Parse accepts a single command, the injection is confined to the streamed statement and further statements cannot be chained. This issue affects postgrex: from 0.19.3 before 0.22.4.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66838">https://www.tenable.com/cve/CVE-2026-66838</a></p>

2026/8/7
阅读更多

CVE-2026-66829

<p>Low Severity</p> <h3>Description</h3> <p>URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a <meta http-equiv="refresh"> element in sanitized HTML. HtmlSanitizeEx.html5/1 keeps attacker-supplied <meta> elements in its output. A meta element acts on the whole document rather than on the fragment it was embedded in, so it can also declare document-wide directives such as Content-Security-Policy. This is not cross-site scripting. Browsers do not navigate a meta refresh to a javascript: URL, so the uppercase JAVASCRIPT: filter bypass yields no script execution and none was demonstrated. This issue affects html_sanitize_ex: from 0.3.1 before 1.5.3.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66829">https://www.tenable.com/cve/CVE-2026-66829</a></p>

2026/8/6
阅读更多

CVE-2026-66759

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66759">https://www.tenable.com/cve/CVE-2026-66759</a></p>

2026/7/27
阅读更多

CVE-2026-66758

<p>High Severity</p> <h3>Description</h3> <p>A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66758">https://www.tenable.com/cve/CVE-2026-66758</a></p>

2026/7/27
阅读更多

CVE-2026-66493

<p>Medium Severity</p> <h3>Description</h3> <p>Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66493">https://www.tenable.com/cve/CVE-2026-66493</a></p>

2026/8/7
阅读更多

CVE-2026-66492

<p>Medium Severity</p> <h3>Description</h3> <p>Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the file upload action lead to path a traversal vulnerability.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66492">https://www.tenable.com/cve/CVE-2026-66492</a></p>

2026/8/7
阅读更多

CVE-2026-66491

<p>High Severity</p> <h3>Description</h3> <p>Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66491">https://www.tenable.com/cve/CVE-2026-66491</a></p>

2026/8/7
阅读更多

CVE-2026-66373

<p>High Severity</p> <h3>Description</h3> <p>Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66373">https://www.tenable.com/cve/CVE-2026-66373</a></p>

2026/7/25
阅读更多

CVE-2026-66370

<p>Medium Severity</p> <h3>Description</h3> <p>URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to retarget a form already on the rendering page and receive whatever the victim submits, including credentials, via the form and formaction attributes on an <input> element in sanitized HTML. HTML's form attribute associates an input with any form on the page by its id even when the input sits outside that form, and formaction on a submit control overrides the owning form's action. Neither attribute receives a scheme check, so an absolute cross-origin URL survives sanitizing. No script executes. The scrubber allows neither form nor button, so the attacker cannot introduce a form of their own and the rendering page must already contain a form carrying an id. This issue affects html_sanitize_ex: from 0.3.1 before 1.5.3.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66370">https://www.tenable.com/cve/CVE-2026-66370</a></p>

2026/8/6
阅读更多

CVE-2026-66310

<p>High Severity</p> <h3>Description</h3> <p>External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66310">https://www.tenable.com/cve/CVE-2026-66310</a></p>

2026/8/4
阅读更多

CVE-2026-66277

<p>Medium Severity</p> <h3>Description</h3> <p>It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66277">https://www.tenable.com/cve/CVE-2026-66277</a></p>

2026/8/5
阅读更多

CVE-2026-66276

<p>Medium Severity</p> <h3>Description</h3> <p>An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66276">https://www.tenable.com/cve/CVE-2026-66276</a></p>

2026/8/5
阅读更多

CVE-2026-66275

<p>Medium Severity</p> <h3>Description</h3> <p>An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66275">https://www.tenable.com/cve/CVE-2026-66275</a></p>

2026/8/5
阅读更多

CVE-2026-66274

<p>High Severity</p> <h3>Description</h3> <p>A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66274">https://www.tenable.com/cve/CVE-2026-66274</a></p>

2026/8/5
阅读更多

CVE-2026-66273

<p>High Severity</p> <h3>Description</h3> <p>A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66273">https://www.tenable.com/cve/CVE-2026-66273</a></p>

2026/8/5
阅读更多

CVE-2026-66257

<p>High Severity</p> <h3>Description</h3> <p>A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66257">https://www.tenable.com/cve/CVE-2026-66257</a></p>

2026/8/5
阅读更多

CVE-2026-66151

<p>Medium Severity</p> <h3>Description</h3> <p>SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66151">https://www.tenable.com/cve/CVE-2026-66151</a></p>

2026/8/7
阅读更多

CVE-2026-66062

<p>Medium Severity</p> <h3>Description</h3> <p>SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for headers such as Accept) uses a regular expression vulnerable to quadratic backtracking, so a maliciously crafted header value can cause excessive CPU consumption and degrade or deny service. Version 2.70.2 fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66062">https://www.tenable.com/cve/CVE-2026-66062</a></p>

2026/8/7
阅读更多

CVE-2026-66061

<p>High Severity</p> <h3>Description</h3> <p>Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as iOS universal links as if they were physically scanned, without validating the calling app or prompting the user. As a result, any untrusted app on the device can forward an arbitrary tag to Home Assistant, causing it to execute the associated automation as though a legitimate user had scanned an authorized tag. This allows silent, unattended automation execution by untrusted local callers. This issue has been fixed in version 2026.5.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66061">https://www.tenable.com/cve/CVE-2026-66061</a></p>

2026/8/7
阅读更多

CVE-2026-66060

<p>High Severity</p> <h3>Description</h3> <p>Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism as if they were physically scanned, without validating the calling app or prompting the user. As a result, any untrusted app on the device can forward an arbitrary tag to Home Assistant, causing it to execute the associated automation as though a legitimate user had scanned an authorized tag. This allows silent, unattended automation execution by untrusted local callers. This issue is fixed in version 2026.8.1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66060">https://www.tenable.com/cve/CVE-2026-66060</a></p>

2026/8/7
阅读更多

CVE-2026-66058

<p>Medium Severity</p> <h3>Description</h3> <p>Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66058">https://www.tenable.com/cve/CVE-2026-66058</a></p>

2026/8/7
阅读更多

CVE-2026-66041

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66041">https://www.tenable.com/cve/CVE-2026-66041</a></p>

2026/7/24
阅读更多

CVE-2026-66040

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66040">https://www.tenable.com/cve/CVE-2026-66040</a></p>

2026/7/24
阅读更多

CVE-2026-66039

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66039">https://www.tenable.com/cve/CVE-2026-66039</a></p>

2026/7/24
阅读更多

CVE-2026-66038

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66038">https://www.tenable.com/cve/CVE-2026-66038</a></p>

2026/7/24
阅读更多

CVE-2026-66037

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66037">https://www.tenable.com/cve/CVE-2026-66037</a></p>

2026/7/24
阅读更多

CVE-2026-66036

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66036">https://www.tenable.com/cve/CVE-2026-66036</a></p>

2026/7/24
阅读更多

CVE-2026-66032

<p>High Severity</p> <h3>Description</h3> <p>libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66032">https://www.tenable.com/cve/CVE-2026-66032</a></p>

2026/7/24
阅读更多

CVE-2026-66000

<p>Low Severity</p> <h3>Description</h3> <p>Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduced to continue receiving document data by email. This issue is fixed in versions 16.23.0 and 15.112.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-66000">https://www.tenable.com/cve/CVE-2026-66000</a></p>

2026/8/7
阅读更多

CVE-2026-65819

<p>High Severity</p> <h3>Description</h3> <p>gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through DecodingLayerParser or DecodeFromBytes to trigger an unrecovered panic and remotely deny service. A patch commit is available at 210f25f.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-65819">https://www.tenable.com/cve/CVE-2026-65819</a></p>

2026/8/7
阅读更多

CVE-2026-65802

<p>High Severity</p> <h3>Description</h3> <p>External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-65802">https://www.tenable.com/cve/CVE-2026-65802</a></p>

2026/8/4
阅读更多

CVE-2026-65706

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-65706">https://www.tenable.com/cve/CVE-2026-65706</a></p>

2026/7/23
阅读更多

CVE-2026-65705

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-65705">https://www.tenable.com/cve/CVE-2026-65705</a></p>

2026/7/23
阅读更多

CVE-2026-65704

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-65704">https://www.tenable.com/cve/CVE-2026-65704</a></p>

2026/7/23
阅读更多

CVE-2026-65703

<p>High Severity</p> <h3>Description</h3> <p>FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-65703">https://www.tenable.com/cve/CVE-2026-65703</a></p>

2026/7/23
阅读更多

CVE-2026-65668

<p>High Severity</p> <h3>Description</h3> <p>Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-65668">https://www.tenable.com/cve/CVE-2026-65668</a></p>

2026/8/7
阅读更多

CVE-2026-65667

<p>Critical Severity</p> <h3>Description</h3> <p>Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-65667">https://www.tenable.com/cve/CVE-2026-65667</a></p>

2026/8/7
阅读更多

CVE-2026-65583

<p>Critical Severity</p> <h3>Description</h3> <p>Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-65583">https://www.tenable.com/cve/CVE-2026-65583</a></p>

2026/8/6
阅读更多

CVE-2026-65432

<p>High Severity</p> <h3>Description</h3> <p>Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declarations or external entities. As a result, the protections applied to the top-level document do not extend to imported documents, leaving imported WSDL/XSD content vulnerable to XML External Entity (XXE) attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-65432">https://www.tenable.com/cve/CVE-2026-65432</a></p>

2026/8/6
阅读更多

CVE-2026-65400

<p>High Severity</p> <h3>Description</h3> <p>An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-65400">https://www.tenable.com/cve/CVE-2026-65400</a></p>

2026/8/6
阅读更多

CVE-2026-64993

<p>Medium Severity</p> <h3>Description</h3> <p>Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64993">https://www.tenable.com/cve/CVE-2026-64993</a></p>

2026/8/6
阅读更多

CVE-2026-64829

<p>Critical Severity</p> <h3>Description</h3> <p>Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php. While the normal password-change flow in qa-include/pages/account.php explicitly clears the sessioncode to invalidate persistent qa_session cookies, the forgot-password handler qa_finish_reset_user() omits this step, allowing any valid persistent cookie issued before the reset to continue authenticating the account after the password reset completes.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64829">https://www.tenable.com/cve/CVE-2026-64829</a></p>

2026/7/22
阅读更多

CVE-2026-64828

<p>Medium Severity</p> <h3>Description</h3> <p>Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML and JavaScript through the order notes field without sanitization. Attackers can craft malicious payloads in customer order placement that execute in the admin's browser session when viewing order details, enabling session token theft or unauthorized administrative actions.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64828">https://www.tenable.com/cve/CVE-2026-64828</a></p>

2026/7/22
阅读更多

CVE-2026-64827

<p>Critical Severity</p> <h3>Description</h3> <p>Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64827">https://www.tenable.com/cve/CVE-2026-64827</a></p>

2026/8/3
阅读更多

CVE-2026-64676

<p>Medium Severity</p> <h3>Description</h3> <p>Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vulnerable to an authorization bypass in confidential-guest memory management. In Confidential Containers (CoCo) deployments, the kata-agent enforces an OPA/Rego-based AgentPolicy that must authorize every ttRPC API call, forming the security boundary that prevents an untrusted host from directing the confidential guest. Two ttRPC methods introduced with the mem-agent feature are missing this authorization check, so an untrusted host can invoke them unconditionally regardless of the guest's policy configuration. When mem-agent is enabled (off by default), this lets the host tamper with in-guest memory management by forcing swap, aggressive eviction, or compaction, resulting in attacker-controlled availability and performance degradation of the confidential workload entirely outside the agent-policy boundary. The impact does not include memory disclosure or code execution, and severity is bounded by the precondition that mem-agent must be explicitly enabled. This issue is fixed in version 4.0.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64676">https://www.tenable.com/cve/CVE-2026-64676</a></p>

2026/8/7
阅读更多

CVE-2026-64665

<p>High Severity</p> <h3>Description</h3> <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by email address alone. Exploitation requires OAuth to be explicitly enabled with such a provider. This issue is fixed in versions 5.74.1 and 6.24.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64665">https://www.tenable.com/cve/CVE-2026-64665</a></p>

2026/8/6
阅读更多

CVE-2026-64664

<p>Medium Severity</p> <h3>Description</h3> <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belonged to an existing user, without having permission to view users, though the endpoint only exposed user existence and not any other user data. This issue is fixed in versions 5.74.1 and 6.24.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64664">https://www.tenable.com/cve/CVE-2026-64664</a></p>

2026/8/6
阅读更多

CVE-2026-64663

<p>Medium Severity</p> <h3>Description</h3> <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templates pass untrusted input into affected areas, and exploitation did not require authentication. This issue is fixed in versions 5.74.1 and 6.24.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64663">https://www.tenable.com/cve/CVE-2026-64663</a></p>

2026/8/6
阅读更多

CVE-2026-64662

<p>Medium Severity</p> <h3>Description</h3> <p>Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom field values, from any collection and including unpublished entries, through the navigation endpoint, though no data could be modified. This issue is fixed in versions 5.74.1 and 6.24.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64662">https://www.tenable.com/cve/CVE-2026-64662</a></p>

2026/8/6
阅读更多

CVE-2026-64654

<p>Medium Severity</p> <h3>Description</h3> <p>GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content without neutralizing terminal escape sequences. An attacker who can influence that content can embed escape sequences that are interpreted by the terminal of a user who runs an affected command, with impact ranging from cosmetic manipulation of the title or on-screen content to, on some terminal emulators, command execution. This extends the same class of issue as CVE-2026-45803—which addressed only gh run view --log—to the other affected command paths. This issue is fixed in version 2.97.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64654">https://www.tenable.com/cve/CVE-2026-64654</a></p>

2026/8/6
阅读更多

CVE-2026-64653

<p>Medium Severity</p> <h3>Description</h3> <p>GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or resource values to make gh address a different API endpoint or resource than the user intended. This issue is fixed in version 2.97.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64653">https://www.tenable.com/cve/CVE-2026-64653</a></p>

2026/8/6
阅读更多

CVE-2026-64652

<p>Low Severity</p> <h3>Description</h3> <p>GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As a result, part of an affected token could appear in terminal or CI output that is captured or shared. Authenticated users are affected if they ran gh auth status (without the --show-token flag) with a token type whose format contains an underscore after the prefix. This includes fine-grained personal access tokens (github_pat_*) and GitHub App installation and user access tokens (ghs_*, ghu_*; for example, ghs_<APPID>_<JWT>), as well as the Actions GITHUB_TOKEN. Classic tokens such as gho_* and ghp_* have an underscore-free body and are not affected. This issue is fixed in version 2.97.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64652">https://www.tenable.com/cve/CVE-2026-64652</a></p>

2026/8/6
阅读更多

CVE-2026-64638

<p>High Severity</p> <h3>Description</h3> <p>WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64638">https://www.tenable.com/cve/CVE-2026-64638</a></p>

2026/8/7
阅读更多

CVE-2026-64637

<p>Critical Severity</p> <h3>Description</h3> <p>Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64637">https://www.tenable.com/cve/CVE-2026-64637</a></p>

2026/8/7
阅读更多

CVE-2026-64636

<p>High Severity</p> <h3>Description</h3> <p>An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-64636">https://www.tenable.com/cve/CVE-2026-64636</a></p>

2026/8/7
阅读更多

CVE-2026-63725

<p>High Severity</p> <h3>Description</h3> <p>sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-concatenating the backup directory path $this->path directly into the command line ('tar czf ' . $backupFileApp . ' ' . BASE_PATH . ' --exclude \"' . $this->path . '\" 2>&1') and passes the result to PHP's exec() with no application of escapeshellarg() and no validation of the path against a safe character set. The $this->path value is read from the sysPass configuration, which is persisted in the database and writable through the admin settings API and the admin UI. An administrator (or an attacker who has obtained an admin API token or admin session) can therefore store a backup path containing shell metacharacters and trigger a backup operation to execute arbitrary OS commands as the web server process user (typically www-data or apache). Because sysPass is a password manager whose sole purpose is to hold credentials for other systems, code execution as the web-server user permits reading sysPass's master password and encryption key from memory or configuration files, decrypting every stored credential in the database, exporting the entire password vault, pivoting to internal systems using the disclosed credentials, and installing persistent backdoors on the password-manager host.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-63725">https://www.tenable.com/cve/CVE-2026-63725</a></p>

2026/8/6
阅读更多

CVE-2026-63687

<p>Critical Severity</p> <h3>Description</h3> <p>Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-63687">https://www.tenable.com/cve/CVE-2026-63687</a></p>

2026/8/6
阅读更多

CVE-2026-63637

<p>High Severity</p> <h3>Description</h3> <p>Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted GraphQL query or mutation filters to inject DQL operators, disclose unintended nodes, or expand modification and deletion targets. This issue is fixed in version 25.3.8.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-63637">https://www.tenable.com/cve/CVE-2026-63637</a></p>

2026/8/6
阅读更多

CVE-2026-63508

<p>Critical Severity</p> <h3>Description</h3> <p>Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-63508">https://www.tenable.com/cve/CVE-2026-63508</a></p>

2026/8/7
阅读更多

CVE-2026-63140

<p>Medium Severity</p> <h3>Description</h3> <p>Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privileged authenticated user with read access to at least one index can exploit this condition with a single request to cause a node to terminate, disrupting search availability. In a single-node deployment this fully stops Elasticsearch; in a multi-node cluster it reduces cluster capacity for each affected node.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-63140">https://www.tenable.com/cve/CVE-2026-63140</a></p>

2026/7/21
阅读更多

CVE-2026-63136

<p>Medium Severity</p> <h3>Description</h3> <p>Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-63136">https://www.tenable.com/cve/CVE-2026-63136</a></p>

2026/7/21
阅读更多

CVE-2026-62996

<p>Medium Severity</p> <h3>Description</h3> <p>Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped resource name to be used to read the contents of arbitrary local files accessible to the PHP process. An attacker able to author or influence a template's resource reference could exploit this to disclose sensitive file contents outside the intended template/config scope. This issue is fixed in version 5.8.4.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62996">https://www.tenable.com/cve/CVE-2026-62996</a></p>

2026/8/7
阅读更多

CVE-2026-62992

<p>Medium Severity</p> <h3>Description</h3> <p>Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating that a requested path lies within a configured secure directory. An attacker able to place or reference a symlink within a directory Smarty treats as trusted (e.g., a template or config directory) could use it to point outside the intended secure directory, bypassing the containment check and reading arbitrary files accessible to the PHP process. This issue is fixed in versions 5.8.2 and 4.5.7.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62992">https://www.tenable.com/cve/CVE-2026-62992</a></p>

2026/8/7
阅读更多

CVE-2026-62918

<p>High Severity</p> <h3>Description</h3> <p>Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62918">https://www.tenable.com/cve/CVE-2026-62918</a></p>

2026/8/7
阅读更多

CVE-2026-62896

<p>Critical Severity</p> <h3>Description</h3> <p>Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62896">https://www.tenable.com/cve/CVE-2026-62896</a></p>

2026/8/7
阅读更多

CVE-2026-62873

<p>Critical Severity</p> <h3>Description</h3> <p>Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62873">https://www.tenable.com/cve/CVE-2026-62873</a></p>

2026/8/7
阅读更多

CVE-2026-62830

<p>Critical Severity</p> <h3>Description</h3> <p>Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62830">https://www.tenable.com/cve/CVE-2026-62830</a></p>

2026/8/7
阅读更多

CVE-2026-62825

<p>Critical Severity</p> <h3>Description</h3> <p>Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62825">https://www.tenable.com/cve/CVE-2026-62825</a></p>

2026/7/24
阅读更多

CVE-2026-62518

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Production Scheduling accessible data as well as unauthorized read access to a subset of Oracle Production Scheduling accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Production Scheduling. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62518">https://www.tenable.com/cve/CVE-2026-62518</a></p>

2026/7/21
阅读更多

CVE-2026-62517

<p>Medium Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62517">https://www.tenable.com/cve/CVE-2026-62517</a></p>

2026/7/21
阅读更多

CVE-2026-62516

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Demantra Demand Management. Successful attacks of this vulnerability can result in takeover of Oracle Demantra Demand Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62516">https://www.tenable.com/cve/CVE-2026-62516</a></p>

2026/7/21
阅读更多

CVE-2026-62515

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Planning Command Center. While the vulnerability is in Oracle Advanced Planning Command Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Planning Command Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Planning Command Center accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62515">https://www.tenable.com/cve/CVE-2026-62515</a></p>

2026/7/21
阅读更多

CVE-2026-62514

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Regulatory Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Regulatory Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62514">https://www.tenable.com/cve/CVE-2026-62514</a></p>

2026/7/21
阅读更多

CVE-2026-62513

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. While the vulnerability is in Oracle Process Manufacturing Regulatory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Process Manufacturing Regulatory Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Process Manufacturing Regulatory Management accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62513">https://www.tenable.com/cve/CVE-2026-62513</a></p>

2026/7/21
阅读更多

CVE-2026-62493

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62493">https://www.tenable.com/cve/CVE-2026-62493</a></p>

2026/7/21
阅读更多

CVE-2026-62296

<p>High Severity</p> <h3>Description</h3> <p>HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion between parseElementInner() and parseElement(), raising a StackOverflowError. An attacker who can submit FHIR resources containing such narratives can thus crash a parsing or validation worker thread, affecting validator services and any application that parses attacker-supplied FHIR JSON or XML. This issue is fixed in version 6.9.11.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62296">https://www.tenable.com/cve/CVE-2026-62296</a></p>

2026/8/7
阅读更多

CVE-2026-62295

<p>High Severity</p> <h3>Description</h3> <p>HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or objects. As a result, a small but deeply nested, syntactically valid FHIR JSON document can trigger unbounded readArray() or readObject() recursion, raising a StackOverflowError before structural validation runs. An attacker who can submit JSON resources for validation can thus crash the request thread, and services that do not isolate StackOverflowError safely may experience worker loss or process instability — a denial-of-service condition. This issue is fixed in version 6.9.11.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62295">https://www.tenable.com/cve/CVE-2026-62295</a></p>

2026/8/7
阅读更多

CVE-2026-62293

<p>Medium Severity</p> <h3>Description</h3> <p>HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command concatenates attacker-controlled Implementation Guide titles, profile titles, and source references into scan.html without escaping in Scanner.java. As a result, a user who scans an attacker-supplied IG/profile and then opens or publishes the generated local/CI HTML report can trigger stored cross-site scripting, executing attacker-controlled JavaScript in the report's browser context. This issue is fixed in version 6.9.11.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-62293">https://www.tenable.com/cve/CVE-2026-62293</a></p>

2026/8/7
阅读更多

CVE-2026-61891

<p>High Severity</p> <h3>Description</h3> <p>In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-61891">https://www.tenable.com/cve/CVE-2026-61891</a></p>

2026/8/5
阅读更多

CVE-2026-61808

<p>Critical Severity</p> <h3>Description</h3> <p>LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources. This issue is mitigated in version 1.5.5rc1.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-61808">https://www.tenable.com/cve/CVE-2026-61808</a></p>

2026/8/7
阅读更多

CVE-2026-61632

<p>Medium Severity</p> <h3>Description</h3> <p>PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images referenced by <img src="..."> by joining the src onto the configured base_path with os.path.normpath and opening the result directly, without verifying that the resolved path stays inside base_path. As a result, an src containing ../ sequences or an absolute path reads a file outside base_path as long as it has an allowed image extension (.png, .jpg, .jpeg, .gif, .svg), and the file's contents are then base64-encoded into the rendered output, disclosing them. An application that renders untrusted Markdown with pymdownx.b64 enabled can therefore leak the contents of image-extension files readable by the process to whoever controls the Markdown or views the output, a targeted file-read bounded by the extension check. This issue has been fixed in version 11.0.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-61632">https://www.tenable.com/cve/CVE-2026-61632</a></p>

2026/8/6
阅读更多

CVE-2026-61511

<p>Critical Severity</p> <h3>Description</h3> <p>vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style encoding with permitted characters to inject and execute arbitrary PHP code via the unauthenticated ajax/render template route without any authentication.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-61511">https://www.tenable.com/cve/CVE-2026-61511</a></p>

2026/7/27
阅读更多

CVE-2026-61477

<p>Low Severity</p> <h3>Description</h3> <p>An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-61477">https://www.tenable.com/cve/CVE-2026-61477</a></p>

2026/8/7
阅读更多

CVE-2026-61466

<p>Critical Severity</p> <h3>Description</h3> <p>In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-61466">https://www.tenable.com/cve/CVE-2026-61466</a></p>

2026/8/6
阅读更多

CVE-2026-61372

<p>High Severity</p> <h3>Description</h3> <p>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue.</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-61372">https://www.tenable.com/cve/CVE-2026-61372</a></p>

2026/8/3
阅读更多

CVE-2026-61041

<p>Critical Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demantra Demand Management. While the vulnerability is in Oracle Demantra Demand Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Demantra Demand Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-61041">https://www.tenable.com/cve/CVE-2026-61041</a></p>

2026/7/21
阅读更多

CVE-2026-60812

<p>Medium Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60812">https://www.tenable.com/cve/CVE-2026-60812</a></p>

2026/7/21
阅读更多

CVE-2026-60811

<p>Medium Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Supply Chain Trading Connector accessible data as well as unauthorized read access to a subset of Oracle Supply Chain Trading Connector accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Supply Chain Trading Connector. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60811">https://www.tenable.com/cve/CVE-2026-60811</a></p>

2026/7/21
阅读更多

CVE-2026-60810

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data as well as unauthorized update, insert or delete access to some of Oracle Supply Chain Trading Connector accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60810">https://www.tenable.com/cve/CVE-2026-60810</a></p>

2026/7/21
阅读更多

CVE-2026-60800

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Compensation Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Compensation Workbench accessible data as well as unauthorized update, insert or delete access to some of Oracle Compensation Workbench accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60800">https://www.tenable.com/cve/CVE-2026-60800</a></p>

2026/7/21
阅读更多

CVE-2026-60799

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Compensation Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Compensation Workbench accessible data as well as unauthorized update, insert or delete access to some of Oracle Compensation Workbench accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60799">https://www.tenable.com/cve/CVE-2026-60799</a></p>

2026/7/21
阅读更多

CVE-2026-60773

<p>Critical Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60773">https://www.tenable.com/cve/CVE-2026-60773</a></p>

2026/7/21
阅读更多

CVE-2026-60772

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as unauthorized read access to a subset of Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60772">https://www.tenable.com/cve/CVE-2026-60772</a></p>

2026/7/21
阅读更多

CVE-2026-60771

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Complex Maintenance, Repair and Overhaul accessible data as well as unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60771">https://www.tenable.com/cve/CVE-2026-60771</a></p>

2026/7/21
阅读更多

CVE-2026-60764

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60764">https://www.tenable.com/cve/CVE-2026-60764</a></p>

2026/7/21
阅读更多

CVE-2026-60708

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Financials accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60708">https://www.tenable.com/cve/CVE-2026-60708</a></p>

2026/7/21
阅读更多

CVE-2026-60703

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Interaction Blending executes to compromise Oracle Interaction Blending. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Interaction Blending accessible data as well as unauthorized access to critical data or complete access to all Oracle Interaction Blending accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60703">https://www.tenable.com/cve/CVE-2026-60703</a></p>

2026/7/21
阅读更多

CVE-2026-60685

<p>Medium Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iSupport accessible data as well as unauthorized read access to a subset of Oracle iSupport accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60685">https://www.tenable.com/cve/CVE-2026-60685</a></p>

2026/7/21
阅读更多

CVE-2026-60683

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. While the vulnerability is in Oracle Process Manufacturing Regulatory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Process Manufacturing Regulatory Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60683">https://www.tenable.com/cve/CVE-2026-60683</a></p>

2026/7/21
阅读更多

CVE-2026-60681

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Regulatory Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60681">https://www.tenable.com/cve/CVE-2026-60681</a></p>

2026/7/21
阅读更多

CVE-2026-60678

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in takeover of Oracle General Ledger. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60678">https://www.tenable.com/cve/CVE-2026-60678</a></p>

2026/7/21
阅读更多

CVE-2026-60674

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60674">https://www.tenable.com/cve/CVE-2026-60674</a></p>

2026/7/21
阅读更多

CVE-2026-60671

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition as well as unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60671">https://www.tenable.com/cve/CVE-2026-60671</a></p>

2026/7/21
阅读更多

CVE-2026-60670

<p>High Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Client System Analyzer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology Stack. Successful attacks of this vulnerability can result in takeover of Oracle Applications Technology Stack. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60670">https://www.tenable.com/cve/CVE-2026-60670</a></p>

2026/7/21
阅读更多

CVE-2026-60575

<p>Medium Severity</p> <h3>Description</h3> <p>Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).</p> <p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-60575">https://www.tenable.com/cve/CVE-2026-60575</a></p>

2026/7/21
阅读更多