CVE ID :CVE-2026-94084 Published : 2026年9月20日 01:20 | 26 分钟 ago Description :Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a…
CVE-2026-94083 – Suricata DoH2 Type Confusion Vulnerability
CVE ID :CVE-2026-94083 Published : 2026年9月20日 01:18 | 28 分钟 ago Description :Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state…
CVE-2026-93993 – Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout
CVE ID :CVE-2026-93993 Published : Sept. 19, 2026, 11:17 p.m. | 28 minutes ago Description :Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git…
CVE-2026-93992 – Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal
CVE ID :CVE-2026-93992 Published : Sept. 19, 2026, 11:17 p.m. | 28 minutes ago Description :Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files…
CVE-2026-93991 – Argo Workflows 4.1.0 through 4.1.3 Cross-Namespace Disclosure via Negated Selector
CVE ID :CVE-2026-93991 Published : Sept. 19, 2026, 11:17 p.m. | 28 minutes ago Description :Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped…
CVE-2026-93990 – Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate
CVE ID :CVE-2026-93990 Published : Sept. 19, 2026, 11:17 p.m. | 28 minutes ago Description :Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences…
CVE-2026-93985 – OpenPanel js-runtime JavaScript Template Sandbox Escape RCE
CVE ID :CVE-2026-93985 Published : Sept. 19, 2026, 12:16 p.m. | 11 hours, 29 minutes ago Description :OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that…
CVE-2026-93923 – SiYuan through 3.8.4 Stored XSS via Heading Style Attribute
CVE ID :CVE-2026-93923 Published : Sept. 18, 2026, 11:12 p.m. | 28 minutes ago Description :SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored…
CVE-2026-93922 – SiYuan through 3.8.4 Stored XSS via notebook names
CVE ID :CVE-2026-93922 Published : Sept. 18, 2026, 11:12 p.m. | 28 minutes ago Description :SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing…
CVE-2026-93740 – Totolink A3002MU formWlEncrypt buffer overflow
CVE ID :CVE-2026-93740 Published : Sept. 18, 2026, 10:17 p.m. | 1 hour, 23 minutes ago Description :A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt….