Skip to content

Menu
  • Home
Menu

CVE-2026-91752 – GNU libextractor before 1.15 Stack Overflow via OLE2

Posted on September 15, 2026

CVE ID :CVE-2026-91752 Published : Sept. 15, 2026, 12:35 a.m. | 43 minutes ago Description :GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length…

CVE-2026-91751 – Flextype CMS through 1.0.0-alpha.3 Path Traversal via Entries REST API

Posted on September 15, 2026

CVE ID :CVE-2026-91751 Published : Sept. 15, 2026, 12:35 a.m. | 43 minutes ago Description :Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing…

CVE-2026-91144 – ZFile through 5.0.5 Share Entry Filter Bypass via Download Endpoint

Posted on September 15, 2026

CVE ID :CVE-2026-91144 Published : Sept. 14, 2026, 10:16 p.m. | 1 hour, 1 minute ago Description :ZFile through 5.0.5 fails to validate requested file paths against a share link’s allowed entries on the…

CVE-2026-12944 – Incomplete Security Scanner Blocklist Enables Network-Based Code Execution

Posted on September 15, 2026

CVE ID :CVE-2026-12944 Published : Sept. 14, 2026, 10:16 p.m. | 1 hour, 1 minute ago Description :IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges…

CVE-2026-91200 – DevSpace through 6.3.21 Path Traversal via tar extraction

Posted on September 15, 2026

CVE ID :CVE-2026-91200 Published : Sept. 14, 2026, 10:10 p.m. | 1 hour, 7 minutes ago Description :DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream….

CVE-2026-90896 – Missing authentication in Ecommerce Template checkout session endpoint allows unauthenticated disclosure of buyer PII

Posted on September 15, 2026

CVE ID :CVE-2026-90896 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 1 minute ago Description :Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed at GET /api/stripe/checkout_sessions,…

CVE-2026-68489 – Plesk Extensions Ruby and Node.js Toolkit Static Code Injection

Posted on September 15, 2026

CVE ID :CVE-2026-68489 Published : Sept. 14, 2026, 9:17 p.m. | 2 hours, 1 minute ago Description :Static Code Injection in Plesk extensions “Ruby” before 1.6.6 and “Node.js Toolkit” before 2.5.0 allows remote authenticated…

CVE-2026-90606 – Totolink A3002MU boa formIpv6Setup buffer overflow

Posted on September 14, 2026

CVE ID :CVE-2026-90606 Published : Sept. 14, 2026, 12:16 a.m. | 56 minutes ago Description :A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the…

CVE-2026-90605 – Totolink A3002MU boa formFilter buffer overflow

Posted on September 14, 2026

CVE ID :CVE-2026-90605 Published : Sept. 14, 2026, 12:16 a.m. | 56 minutes ago Description :A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file…

CVE-2026-88793 – YouTube Embed 10.0 – 10.3 – Unauthenticated Stored XSS via youram_server

Posted on September 14, 2026

CVE ID :CVE-2026-88793 Published : Sept. 13, 2026, 9:17 p.m. | 1 hour, 56 minutes ago Description :The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one…

Posts pagination

1 2 … 145 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme