CVE-2022-0492
Linux Kernel cgroups v1 Privilege Escalation via release_agent
05:16 KSA
CRITICAL
CVSS 9.8
⚠ CISA KEV
Linux Kernel — CVE-2022-0492
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for c…
CVE-2025-48595
Android Framework Integer Overflow Privilege Escalation (CVE-2025-48595)
05:16 KSA
CRITICAL
CVSS 9.8
⚠ CISA KEV
Android Framework — CVE-2025-48595
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cl…
CVE-2026-45247
Mirasvit Mirasvit Full Page Cache Warmer — CVE-2026-45247
Mirasvit Full Page Cache Warmer contains a deserialization of
05:16 KSA
CRITICAL
CVSS 9.8
⚠ CISA KEV
Mirasvit Mirasvit Full Page Cache Warmer — CVE-2026-45247
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the Cac…
CVE-2018-25388
HaPe PKH 1.1 Arbitrary File Upload RCE via Bypass
15:16 KSA
HIGH
CVSS 8.8
CWE-434
HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php t…
CVE-2025-11993
WooCommerce Infinite Scroll Plugin PHP Object Injection via Import Settings
03:16 KSA
HIGH
CVSS 8.8
CWE-502
The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' parameter in the 'import_settings' function. This is due to deserialization of untrusted data supplied via t…
CVE-2026-10019
Integer Overflow in ANGLE Graphics Library Enables Cross-Origin Data Leak
03:16 KSA
HIGH
CVSS 8.8
CWE-472
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-10062
TRENDnet TEW-432BRP Stack Buffer Overflow in formSetRoute Function
15:16 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes stack-based buffer overflow. The attack is possible to be carried …
CVE-2026-10063
TRENDnet TEW-432BRP Stack Buffer Overflow in formWPS Function
15:16 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publi…
CVE-2026-10066
Stack Buffer Overflow in Shibby Tomato UPS Service (CVE-2026-10066)
15:16 KSA
HIGH
CVSS 8.8
CWE-119
A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. This project is su…
CVE-2026-10067
Shibby Tomato 1.28 Stack-Based Buffer Overflow in multimon.cgi
15:16 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. This project is superseded by FreshTomato. This vulnerability only affects…
CVE-2026-10119
TRENDnet TEW-432BRP Stack Buffer Overflow in MAC Filter Function
21:16 KSA
HIGH
CVSS 8.8
CWE-119
A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument filter_name leads to stack-based buffer overflow. Remote exploitation of the attack is possi…
CVE-2026-10120
TRENDnet TEW-432BRP Stack-Based Buffer Overflow in Firewall Rule Function
21:16 KSA
HIGH
CVSS 8.8
CWE-119
A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name results in stack-based buffer overflow. The attack can be executed remotel…
CVE-2026-35082
ugw-logread Path Traversal Vulnerability Allows Arbitrary File Access
21:01 KSA
HIGH
CVSS 8.8
CWE-22
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.
CVE-2026-35083
Stack Buffer Overflow Enables Root-Level Remote Code Execution
21:01 KSA
HIGH
CVSS 8.8
CWE-121
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
CVE-2026-35084
Stack Buffer Overflow in dali-devconfig Allows Remote Root Access
21:01 KSA
HIGH
CVSS 8.8
CWE-121
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
CVE-2026-35085
Stack Buffer Overflow in gdv-serverconfig Enables Remote Root Access
21:01 KSA
HIGH
CVSS 8.8
CWE-121
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
CVE-2026-35674
OpenClaw Gateway Scope Bypass in chat.send Route Enables Privilege Escalation
21:16 KSA
HIGH
CVSS 8.8
CWE-863
OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliver commands through inherited external routes to bypass operator.approvals and op…
CVE-2026-44238
FreePBX CDR Reports SQL Injection via Order and Sort Parameters
15:16 KSA
HIGH
CVSS 8.8
CWE-89
FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parameters. Authentication with a FreePBX Administration Control Panel account that has CDR section access is required. Full administra…
CVE-2026-44239
FreePBX Dashboard Path Traversal RCE via getcontent AJAX Handler
15:16 KSA
HIGH
CVSS 8.8
CWE-98
FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suf…
CVE-2026-48557
Spatie Laravel Media Library File Upload Bypass via Double Extension
21:16 KSA
HIGH
CVSS 8.8
CWE-184
Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg to bypass the blocklist, with pathinfo() …
CVE-2026-7465
Spectra Gutenberg Blocks RCE via Malicious Block Payload
21:16 KSA
HIGH
CVSS 8.8
CWE-269
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute c…
CVE-2026-9887
Chrome Proxy Use-After-Free RCE via Malicious PAC Script
03:16 KSA
HIGH
CVSS 8.8
CWE-416
Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: Critical)
CVE-2026-9940
Heap Buffer Overflow in Chrome ANGLE Graphics Library (CVE-2026-9940)
03:16 KSA
HIGH
CVSS 8.8
CWE-122
Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2026-20230
Cisco Unified CM SSRF Vulnerability Allows Unauthenticated Root Privilege Escalation
21:01 KSA
HIGH
CVSS 8.6
CWE-918
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected devi…
CVE-2026-44463
Zed Code Editor Terminal Permission Bypass via Environment Variables
09:18 KSA
HIGH
CVSS 8.6
CWE-78
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g., PAGER) to execute arbitrary code. This vulnerability is fixed in 0.229.0.
CVE-2018-25383
Free MP3 CD Ripper 2.8 Stack Buffer Overflow in WMA Processing
15:16 KSA
HIGH
CVSS 8.4
CWE-121
Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protection via structured exception handling manipulation. Attackers can craft a malicious WMA file that triggers the overflow when loaded …
CVE-2026-10012
Chrome Skia Use-After-Free Sandbox Escape Vulnerability
03:16 KSA
HIGH
CVSS 8.3
CWE-416
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-32905
OpenClaw Device-Pair Plugin Authorization Bypass (CVE-2026-32905)
15:16 KSA
HIGH
CVSS 8.3
CWE-862
OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without proper scope validation. Attackers with chat command access can create setup cod…
CVE-2026-9877
Use-After-Free in Chrome ANGLE Graphics Library Sandbox Escape
03:16 KSA
HIGH
CVSS 8.3
CWE-416
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-9946
Use-After-Free in Chrome ANGLE Graphics Library Sandbox Escape
03:16 KSA
HIGH
CVSS 8.3
CWE-416
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2018-25382
Zechat 1.5 SQL Injection Vulnerability in profile.php uname Parameter
15:16 KSA
HIGH
CVSS 8.2
CWE-89
Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can send crafted requests to profile.php with UNION-based SQL injection payloads to retrieve table…
CVE-2018-25385
SQL Injection in E-Registrasi Pencak Silat 18.10 monitor_nilai.php
15:16 KSA
HIGH
CVSS 8.2
CWE-89
E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id_partai parameter. Attackers can send GET requests to monitor_nilai.php with crafted SQL payloa…
CVE-2018-25386
SQL Injection Vulnerabilities in HaPe PKH 1.1 Admin Module
15:16 KSA
HIGH
CVSS 8.2
CWE-89
HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while authenticat…
CVE-2018-25389
SQL Injection in HaPe PKH 1.1 lap-anggota-kelompok-pdf.php
15:16 KSA
HIGH
CVSS 8.2
CWE-89
HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter sent to lap-anggota-kelompok-pdf.php. Attackers can send a crafted request with a time-based …
CVE-2018-25390
SQL Injection in HaPe PKH 1.1 lap-peserta-perdesa-pdf.php desa Parameter
15:16 KSA
HIGH
CVSS 8.2
CWE-89
HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-perdesa-pdf.php. Attackers can send a crafted request with a time-based blind payl…
CVE-2018-25394
Kados R10 GreenBee Unauthenticated SQL Injection in update_release.php
15:16 KSA
HIGH
CVSS 8.2
CWE-89
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the release_id parameter of boards_buttons/update_release.php. The release_id value is concatenated directly into …
CVE-2018-25395
Kados R10 GreenBee Unauthenticated SQL Injection in update_feature.php
15:16 KSA
HIGH
CVSS 8.2
CWE-89
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the feature_id parameter of boards_buttons/update_feature.php. The feature_id value is concatenated directly into …
CVE-2018-25398
SQL Injection in Open ISES Project 3.30A frm_passwd Parameter
15:16 KSA
HIGH
CVSS 8.2
CWE-89
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the frm_passwd parameter. Attackers can send POST requests to main.php with crafted SQL payloads to extra…
CVE-2018-25399
SQL Injection in Open ISES Project 3.30A nearby.php Parameter Handling
15:16 KSA
HIGH
CVSS 8.2
CWE-89
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tick_lat and tick_lng parameters. Attackers can send GET requests to nearby.php with crafted SQL payl…
CVE-2018-25400
SQL Injection in Open ISES Project 3.30A ajax/form_post.php
15:16 KSA
HIGH
CVSS 8.2
CWE-89
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to the ajax/form_post.php endpoint with crafted SQL p…
CVE-2018-25401
SQL Injection in Open ISES Project 3.30A sever_graph.php p1 Parameter
15:16 KSA
HIGH
CVSS 8.2
CWE-89
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to sever_graph.php with crafted SQL payloads to extract…
CVE-2018-25402
SQL Injection in Open ISES Project 3.30A inc_types_graph.php p1 Parameter
15:16 KSA
HIGH
CVSS 8.2
CWE-89
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to inc_types_graph.php with crafted SQL payloads to ext…
CVE-2018-25403
SQL Injection in Open ISES Project 3.30A city_graph.php Parameter p1
15:16 KSA
HIGH
CVSS 8.2
CWE-89
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to city_graph.php with crafted SQL payloads to extract …
CVE-2018-25404
SQL Injection in Open ISES Project 3.30A add_facnote.php
15:16 KSA
HIGH
CVSS 8.2
CWE-89
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ticket_id parameter. Attackers can send GET requests to add_facnote.php with crafted SQL payloads to …
CVE-2018-25405
eNdonesia Portal 8.7 Multiple SQL Injection Vulnerabilities in mod.php
21:16 KSA
HIGH
CVSS 8.2
CWE-89
eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. Attackers can inject SQL through the artid, cid, did, contid, and aboutid paramete…
CVE-2026-9312
GitHub Enterprise Server SSRF Vulnerability via Upload Endpoint
03:16 KSA
HIGH
CVSS 8.2
CWE-918
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insufficient input validation in an upload endpoint. By injecting path traversal cont…
CVE-2026-35076
bac-scanresult Arbitrary File Deletion via Insufficient Input Validation
09:16 KSA
HIGH
CVSS 8.1
CWE-73
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35077
ugw-delete-file Arbitrary File Deletion via Insufficient Input Validation
15:03 KSA
HIGH
CVSS 8.1
CWE-73
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35078
ugw-logstop Arbitrary File Deletion via Insufficient Input Validation
15:03 KSA
HIGH
CVSS 8.1
CWE-73
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35079
ugw-restore Arbitrary File Deletion via Insufficient Input Validation
21:01 KSA
HIGH
CVSS 8.1
CWE-73
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35080
ugw-restoreinfo Arbitrary File Deletion via Input Validation Bypass
21:01 KSA
HIGH
CVSS 8.1
CWE-73
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
CVE-2026-35081
ugw-logstop Arbitrary Process Termination via Input Validation Bypass
21:01 KSA
HIGH
CVSS 8.1
CWE-20
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
CVE-2026-44237
FreePBX OAuth2 Client Credential Validation Bypass (CVE-2026-44237)
15:16 KSA
HIGH
CVSS 8.1
CWE-1390
FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledge of a valid client_id is required. The validateClient() method in ClientRepository.php unconditional…
CVE-2026-6075
Media Library Assistant WordPress Plugin CSRF Vulnerability in Bulk Actions
03:16 KSA
HIGH
CVSS 8.1
CWE-352
The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attac…
CVE-2025-14773
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus.
T
03:32 KSA
HIGH
CVSS 8.0
CWE-79
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
CVE-2026-35630
OpenClaw QQBot Authorization Bypass in Approval Buttons (CVE-2026-35630)
21:16 KSA
HIGH
CVSS 8.0
CWE-862
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin approval requests without proper authoriza…
CVE-2026-49367
IntelliJ IDEA Guest Account Command Execution Vulnerability
21:16 KSA
HIGH
CVSS 8.0
CWE-862
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
CVE-2022-49036
Synology Active Backup Recovery Media Creator Arbitrary Code Execution
21:01 KSA
HIGH
CVSS 7.8
CWE-829
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
CVE-2022-49042
Synology Hyper Backup Explorer Arbitrary Code Execution via Untrusted DLL Loading
21:01 KSA
HIGH
CVSS 7.8
CWE-829
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
CVE-2025-41278
Waterfall WF-500 RX Host Out-of-Bounds Read Code Execution
03:16 KSA
HIGH
CVSS 7.8
CWE-125
Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX Host to execute code on the RX Host.
CVE-2025-41280
Waterfall WF-500 RX Host Path Traversal Code Execution (Zip Slip)
04:00 KSA
HIGH
CVSS 7.8
CWE-23
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is ena…
CVE-2025-41281
Waterfall WF-500 RX Host OS Command Injection Vulnerability (CVE-2025-41281)
09:18 KSA
HIGH
CVSS 7.8
CWE-78
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a M…
CVE-2026-45136
Code Injection in claude-code-cache-fix quota-statusline.sh String Interpolation
03:16 KSA
HIGH
CVSS 7.8
CWE-78
claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal. A ''' byte sequence in any user-con…
CVE-2026-46246
In the Linux kernel, the following vulnerability has been resolved:
power: supply: pm8916_lbc: Fix use-after-free for e
03:18 KSA
HIGH
CVSS 7.8
CWE-416
In the Linux kernel, the following vulnerability has been resolved:
power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler
Using the `devm_` variant for requesting IRQ _before_ the `devm_`
variant for allocating/registering the `extcon` handle, means that the
`…
CVE-2026-46267
In the Linux kernel, the following vulnerability has been resolved:
nfc: hci: shdlc: Stop timers and work before freein
03:18 KSA
HIGH
CVSS 7.8
CWE-416
In the Linux kernel, the following vulnerability has been resolved:
nfc: hci: shdlc: Stop timers and work before freeing context
llc_shdlc_deinit() purges SHDLC skb queues and frees the llc_shdlc
structure while its timers and state machine work may still be active.
Timer call…
CVE-2026-4035
MLflow AI Gateway Environment Variable Injection in Secrets
09:16 KSA
HIGH
CVSS 7.7
CWE-201
A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the…
CVE-2026-42965
OpenShift Router FQDN EndpointSlice Metadata Disclosure Vulnerability
03:16 KSA
HIGH
CVSS 7.7
CWE-918
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests…
CVE-2018-25391
HaPe PKH 1.1 Missing Authorization on Record Deletion Endpoints
15:16 KSA
HIGH
CVSS 7.5
CWE-862
HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target record's id. The admin/modul/mod_pengurus/aksi_pengurus.php (module=pengurus&act=hap…
CVE-2018-25396
Heatmiser Wifi Thermostat 1.7 Plaintext Credential Disclosure
15:16 KSA
HIGH
CVSS 7.5
CWE-256
Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request the networkSetup.htm endpoint and extract plaintext username and…
CVE-2025-41271
Waterfall WF-500 Path Traversal Vulnerability Allows Unauthenticated File Access
03:16 KSA
HIGH
CVSS 7.5
CWE-23
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device.
CVE-2026-10073
DreamMaker Arbitrary File Read via Relative Path Traversal
15:16 KSA
HIGH
CVSS 7.5
CWE-23
DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files.
CVE-2026-41032
Unauthenticated Log File Download in Network Controller
09:16 KSA
HIGH
CVSS 7.5
CWE-200
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
CVE-2026-44422
FreeRDP RDPEAR NDR Parser Heap Use-After-Free Vulnerability
21:16 KSA
HIGH
CVSS 7.5
CWE-415
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR type or ownership. When the same ref-id is …
CVE-2026-44660
UltraJSON Memory Leak in ujson.dump() File Write Exception Handling
03:16 KSA
HIGH
CVSS 7.5
CWE-401
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujson.dump() writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each fa…
CVE-2026-45017
Python Liquid Path Traversal in FileSystemLoader Prior to 2.2.0
09:18 KSA
HIGH
CVSS 7.5
CWE-22
Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not guard against reading files outside their search paths when given an absolute path to resolve. This allows malicious template author…
CVE-2026-46527
cpp-httplib X-Forwarded-For Null Pointer Dereference DoS
21:16 KSA
HIGH
CVSS 7.5
CWE-476
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an attacker can send an HTTP request that includes an X-Forwarded-For header whose valu…
CVE-2026-7459
Simple History Plugin Account Takeover via Insufficient Permission Checks
21:16 KSA
HIGH
CVSS 7.5
CWE-640
The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints reg…
CVE-2026-8888
Securly Chrome Extension HTTP Config Download with Unvalidated Regex DoS
21:01 KSA
HIGH
CVSS 7.5
CWE-917
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtrackin…
CVE-2026-8889
Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) an
09:16 KSA
HIGH
CVSS 7.5
CWE-407
Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes).
CVE-2026-9757
GEO my WP WordPress Plugin SQL Injection via swlatlng/nelatlng Parameters
21:16 KSA
HIGH
CVSS 7.5
CWE-89
The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters are read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing WordPress's wp_magic_quotes protection, whic…
CVE-2026-46579
OpenShift Router X-SSL-Client Header Injection Authentication Bypass
03:16 KSA
HIGH
CVSS 7.4
CWE-287
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Clie…
CVE-2026-48555
Spatie Laravel Media Library SSRF via addMediaFromUrl Method
21:16 KSA
HIGH
CVSS 7.4
CWE-918
Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedi…
CVE-2026-10110
SQL Injection in Student Details Management System 1.0 /index.php roll Parameter
21:16 KSA
HIGH
CVSS 7.3
CWE-74
A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible to be carried out remotely. The exploit is…
CVE-2026-10111
SQL Injection in STUDENT-MANAGEMENT-SYSTEM 1.0 Login Email Parameter
21:16 KSA
HIGH
CVSS 7.3
CWE-74
A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function of the component Login Page. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has been published and ma…
CVE-2026-10694
Remote File Inclusion in SourceCodester Online Food Ordering System 2.0
09:16 KSA
HIGH
CVSS 7.3
CWE-73
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public a…
CVE-2026-10704
SQL Injection in SourceCodester Pizzafy Admin Login Function
09:16 KSA
HIGH
CVSS 7.3
CWE-74
A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injec…
CVE-2026-10771
A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-
09:16 KSA
HIGH
CVSS 7.3
CWE-918
A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the argument url results in server…
CVE-2025-11262
Link Whisper Free WordPress Plugin Stored XSS via user_id Parameter
03:16 KSA
HIGH
CVSS 7.2
CWE-79
The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
CVE-2025-41265
OS Command Injection in Waterfall WF-500 TX Host Administration WebUI
03:16 KSA
HIGH
CVSS 7.2
CWE-78
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitr…
CVE-2025-41266
Waterfall WF-500 TX Host OS Command Injection in Administration WebUI
03:16 KSA
HIGH
CVSS 7.2
CWE-78
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitr…
CVE-2025-41267
Waterfall WF-500 TX Host OS Command Injection in Administration WebUI
03:16 KSA
HIGH
CVSS 7.2
CWE-78
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitr…
CVE-2025-41279
OS Command Injection in Waterfall WF-500 RX Host Administration WebUI
04:00 KSA
HIGH
CVSS 7.2
CWE-78
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitr…
CVE-2026-10072
DreamMaker Arbitrary File Upload Vulnerability Enables Remote Code Execution
15:16 KSA
HIGH
CVSS 7.2
CWE-434
DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
CVE-2018-25392
MaxOn ERP SQL Injection in log_activity Function (CVE-2018-25392)
15:16 KSA
HIGH
CVSS 7.1
CWE-89
MaxOn ERP Software 8.x-9.x contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries through the nomor, user, and jenis parameters in the log_activity function. Attackers can send POST requests to /index.php/user/log_activity with ma…
CVE-2026-49371
JetBrains TeamCity Reflected XSS in Keyword Filter
21:16 KSA
HIGH
CVSS 7.1
CWE-79
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
CVE-2026-49373
JetBrains TeamCity RCE via Perforce Connection Settings
21:16 KSA
HIGH
CVSS 7.1
CWE-88
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
CVE-2026-0048
In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/ov
04:48 KSA
MEDIUM
CVSS 6.8
CWE-269
In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-25720
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerabil
13:16 KSA
MEDIUM
CVSS 6.5
CWE-1286
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot the monitor by sending a malformed network packet. Attackers can repeatedly send su…
CVE-2026-3870
A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.1
04:48 KSA
MEDIUM
CVSS 6.5
CWE-120
A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device.
CVE-2026-3871
A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through
10:00 KSA
MEDIUM
CVSS 6.5
CWE-120
A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device.
CVE-2026-2382
The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of
12:00 KSA
MEDIUM
CVSS 6.4
CWE-79
The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX action in all versions up to, and including, 1.9.5. This is due to insufficient input sanitization and output escaping. This makes it…
CVE-2026-4080
The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all v
16:10 KSA
MEDIUM
CVSS 6.4
CWE-79
The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the ect…
CVE-2026-4081
The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions
16:10 KSA
MEDIUM
CVSS 6.4
CWE-79
The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the 'url', 'col…
CVE-2026-8885
The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callo
21:55 KSA
MEDIUM
CVSS 6.4
CWE-79
The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on the 'width' and 'align' shortco…
CVE-2026-10581
A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/
10:00 KSA
MEDIUM
CVSS 6.3
CWE-918
A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has b…
CVE-2026-10693
A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulner
13:16 KSA
MEDIUM
CVSS 6.3
CWE-266
A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. The manipulation leads to improper authorization. The attack can be initiated remo…
CVE-2026-10703
A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRo
13:16 KSA
MEDIUM
CVSS 6.3
CWE-119
A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRouterRequestStructure of the file cipmessagerouter.c of the component SendRRData Handler. The manipulation leads to use after free. Remote exploitation of the at…
CVE-2026-45283
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, a
23:36 KSA
MEDIUM
CVSS 6.3
CWE-287
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app did not properly validate the ownership of files when processing DAV lock and unlock requests. An authenticated u…
CVE-2026-0046
In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapj
04:48 KSA
MEDIUM
CVSS 6.2
CWE-269
In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo…
CVE-2026-0055
In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC)
04:48 KSA
MEDIUM
CVSS 6.2
CWE-22
In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User …
CVE-2026-1450
The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up
12:00 KSA
MEDIUM
CVSS 6.1
CWE-79
The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w…
CVE-2026-1451
The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to
12:00 KSA
MEDIUM
CVSS 6.1
CWE-79
The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web …
CVE-2026-20175
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote loc
13:16 KSA
MEDIUM
CVSS 6.1
CWE-73
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks.
This vulnerability is due to insufficient validation of …
CVE-2026-20233
Cisco Webex Meetings XSS Vulnerability in Web UI
15:12 KSA
MEDIUM
CVSS 6.1
CWE-79
A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed.
…
CVE-2026-2425
The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' par
14:00 KSA
MEDIUM
CVSS 6.1
CWE-79
The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated atta…
CVE-2023-52951
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows
13:16 KSA
MEDIUM
CVSS 5.9
CWE-319
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.
CVE-2026-0075
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead t
04:48 KSA
MEDIUM
CVSS 5.9
CWE-89
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-5085
The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in al
12:00 KSA
MEDIUM
CVSS 5.5
CWE-79
The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin…
CVE-2026-26825
libxls 1.6.3 Use-of-Uninitialized Memory in XLS File Parsing
03:32 KSA
MEDIUM
CVSS 5.3
CWE-908
A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitize…