Skip to content

Menu
  • Home
Menu

CVE-2026-84452 – Windows ML CLI Remote Code Execution Vulnerability

Posted on September 3, 2026

CVE ID :CVE-2026-84452 Published : Sept. 2, 2026, 8:17 p.m. | 4 hours, 19 minutes ago Description :Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for…

CVE-2026-82524 – UnoPim Arbitrary File Upload Vulnerability

Posted on September 3, 2026

CVE ID :CVE-2026-82524 Published : Sept. 2, 2026, 8:17 p.m. | 4 hours, 19 minutes ago Description :UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP…

CVE-2026-84381 – HTTPX2 SOCKS5 Proxy TLS Upgrade Failure Vulnerability

Posted on September 3, 2026

CVE ID :CVE-2026-84381 Published : Sept. 2, 2026, 7:18 p.m. | 5 hours, 19 minutes ago Description :HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS…

CVE-2026-19117 – FIDO2 Authentication Bypass Vulnerability

Posted on September 3, 2026

CVE ID :CVE-2026-19117 Published : Sept. 2, 2026, 7:17 p.m. | 5 hours, 20 minutes ago Description :Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then…

CVE-2026-66786 – Submariner Configuration Injection Remote Code Execution

Posted on September 3, 2026

CVE ID :CVE-2026-66786 Published : Sept. 2, 2026, 6:21 p.m. | 6 hours, 16 minutes ago Description :A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings…

CVE-2026-84482 – WWBN AVideo Cross-Site Request Forgery via get_domain() validation

Posted on September 2, 2026

CVE ID :CVE-2026-84482 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions…

CVE-2026-84480 – WWBN AVideo Password Recovery Token Expiration Bypass

Posted on September 2, 2026

CVE ID :CVE-2026-84480 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens…

CVE-2026-84479 – WWBN AVideo Authentication Bypass via User-Agent Header

Posted on September 2, 2026

CVE ID :CVE-2026-84479 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent…

CVE-2026-84476 – WWBN AVideo Authentication Bypass via X-Real-IP Header

Posted on September 2, 2026

CVE ID :CVE-2026-84476 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof…

CVE-2026-84208 – AVideo User_Location Plugin Unauthenticated SQL Injection

Posted on September 2, 2026

CVE ID :CVE-2026-84208 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin’s regions.json.php and cities.json.php…

Posts pagination

1 2 … 138 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme