Skip to content

Menu
  • Home
Menu

CVE-2026-56817 – Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled

Posted on July 22, 2026

CVE ID :CVE-2026-56817 Published : July 21, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through…

CVE-2026-8989 – Open Recovery Mode

Posted on July 22, 2026

CVE ID :CVE-2026-8989 Published : July 21, 2026, 10:19 p.m. | 2 hours, 17 minutes ago Description :Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through…

CVE-2026-8988 – Access to Bootloader

Posted on July 22, 2026

CVE ID :CVE-2026-8988 Published : July 21, 2026, 10:19 p.m. | 2 hours, 17 minutes ago Description :Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the…

CVE-2026-8987 – Authenticated Heap Overflow

Posted on July 22, 2026

CVE ID :CVE-2026-8987 Published : July 21, 2026, 10:19 p.m. | 2 hours, 17 minutes ago Description :Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled…

CVE-2026-8986 – Command Injection via Malicious OCPP Server

Posted on July 22, 2026

CVE ID :CVE-2026-8986 Published : July 21, 2026, 10:19 p.m. | 2 hours, 17 minutes ago Description :Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics…

CVE-2026-63728 – Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature

Posted on July 21, 2026

CVE ID :CVE-2026-63728 Published : July 21, 2026, 12:17 a.m. | 18 minutes ago Description :Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report…

CVE-2026-64625 – AVideo before 29.0 OS Command Injection via execAsync

Posted on July 21, 2026

CVE ID :CVE-2026-64625 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh…

CVE-2026-64624 – FreeRDP RDP File Parser Remote Code Execution via CLI Options

Posted on July 21, 2026

CVE ID :CVE-2026-64624 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing…

CVE-2026-57495 – AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator’s Claude Code session (bridge-wake)

Posted on July 21, 2026

CVE ID :CVE-2026-57495 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex…

CVE-2026-47255 – AgenticMail API/storage and outbound relay hardening

Posted on July 21, 2026

CVE ID :CVE-2026-47255 Published : July 20, 2026, 10:17 p.m. | 2 hours, 18 minutes ago Description :AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core…

Posts pagination

1 2 … 114 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme