Skip to content

Menu
  • Home
Menu

CVE-2026-93923 – SiYuan through 3.8.4 Stored XSS via Heading Style Attribute

Posted on September 19, 2026

CVE ID :CVE-2026-93923 Published : Sept. 18, 2026, 11:12 p.m. | 28 minutes ago Description :SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored…

CVE-2026-93922 – SiYuan through 3.8.4 Stored XSS via notebook names

Posted on September 19, 2026

CVE ID :CVE-2026-93922 Published : Sept. 18, 2026, 11:12 p.m. | 28 minutes ago Description :SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing…

CVE-2026-93740 – Totolink A3002MU formWlEncrypt buffer overflow

Posted on September 19, 2026

CVE ID :CVE-2026-93740 Published : Sept. 18, 2026, 10:17 p.m. | 1 hour, 23 minutes ago Description :A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt….

CVE-2026-93739 – Totolink A3002MU formWlAc buffer overflow

Posted on September 19, 2026

CVE ID :CVE-2026-93739 Published : Sept. 18, 2026, 10:17 p.m. | 1 hour, 23 minutes ago Description :A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc….

CVE-2026-75885 – Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint

Posted on September 19, 2026

CVE ID :CVE-2026-75885 Published : Sept. 18, 2026, 10:17 p.m. | 1 hour, 23 minutes ago Description :A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows…

CVE-2026-79954 – NASA CryptoLib 1.5.0 – TC receive path accepts Security Associations from the wrong GVCID

Posted on September 18, 2026

CVE ID :CVE-2026-79954 Published : Sept. 18, 2026, 1:16 a.m. | 18 minutes ago Description :NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the…

CVE-2026-93453 – SOGo before 5.12.11 Password Reset Token Interception via Origin Header

Posted on September 18, 2026

CVE ID :CVE-2026-93453 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers…

CVE-2026-93452 – snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress

Posted on September 18, 2026

CVE ID :CVE-2026-93452 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of…

CVE-2026-93450 – go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshal

Posted on September 18, 2026

CVE ID :CVE-2026-93450 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to…

CVE-2026-85878 – Azure Database for PostgreSQL Elevation of Privilege Vulnerability

Posted on September 18, 2026

CVE ID :CVE-2026-85878 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network….

Posts pagination

1 2 … 148 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme