Skip to content

Menu
  • Home
Menu

CVE-2026-8763 – Name Constraints bypass via trailing dot in rfc822Name and URI

Posted on August 3, 2026

CVE ID :CVE-2026-8763 Published : Aug. 3, 2026, 1:16 a.m. | 26 minutes ago Description :In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This…

CVE-2026-59650 – MTI/A0 DH agreement exponentiates unvalidated peer value

Posted on August 3, 2026

CVE ID :CVE-2026-59650 Published : Aug. 3, 2026, 1:16 a.m. | 26 minutes ago Description :In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects…

CVE-2026-59649 – OpenPGP user-attribute subpacket length bounded only by JVM max memory

Posted on August 3, 2026

CVE ID :CVE-2026-59649 Published : Aug. 3, 2026, 1:16 a.m. | 26 minutes ago Description :In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This…

CVE-2026-59646 – DTLS handshake reassembler allocates buffer from unchecked 24-bit length

Posted on August 3, 2026

CVE ID :CVE-2026-59646 Published : Aug. 3, 2026, 1:16 a.m. | 26 minutes ago Description :In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This issue…

CVE-2026-59645 – OER parser recurses without depth limit on self-referential IEEE 1609.2 schema

Posted on August 3, 2026

CVE ID :CVE-2026-59645 Published : Aug. 3, 2026, 1:16 a.m. | 26 minutes ago Description :In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema….

CVE-2026-18577 – Incomplete patch leads to administrative account takeover

Posted on August 3, 2026

CVE ID :CVE-2026-18577 Published : Aug. 2, 2026, 11:16 p.m. | 26 minutes ago Description :An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 Severity:…

CVE-2026-65321 – PyAthena 3.35.4 SQL Injection via DefaultParameterFormatter DELETE/CTAS

Posted on August 3, 2026

CVE ID :CVE-2026-65321 Published : Aug. 2, 2026, 3:16 p.m. | 8 hours, 26 minutes ago Description :PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL…

CVE-2026-68581 – Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision

Posted on August 3, 2026

CVE ID :CVE-2026-68581 Published : Aug. 2, 2026, 1:16 p.m. | 10 hours, 26 minutes ago Description :Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user…

CVE-2026-68579 – FreeRDP before 3.30.0 Heap Overflow via CliprdrStream_Read

Posted on August 3, 2026

CVE ID :CVE-2026-68579 Published : Aug. 2, 2026, 1:16 p.m. | 10 hours, 26 minutes ago Description :FreeRDP before 3.30.0 ( Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS…

CVE-2026-67356 – ArcadeDB before 26.7.3 Privilege Escalation via JavaScript Trigger

Posted on August 3, 2026

CVE ID :CVE-2026-67356 Published : Aug. 2, 2026, 1:16 p.m. | 10 hours, 26 minutes ago Description :ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to…

Posts pagination

1 2 … 121 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme