Skip to content

Menu
  • Home
Menu

CVE-2026-79954 – NASA CryptoLib 1.5.0 – TC receive path accepts Security Associations from the wrong GVCID

Posted on September 18, 2026

CVE ID :CVE-2026-79954 Published : Sept. 18, 2026, 1:16 a.m. | 18 minutes ago Description :NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the…

CVE-2026-93453 – SOGo before 5.12.11 Password Reset Token Interception via Origin Header

Posted on September 18, 2026

CVE ID :CVE-2026-93453 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers…

CVE-2026-93452 – snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress

Posted on September 18, 2026

CVE ID :CVE-2026-93452 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of…

CVE-2026-93450 – go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshal

Posted on September 18, 2026

CVE ID :CVE-2026-93450 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to…

CVE-2026-85878 – Azure Database for PostgreSQL Elevation of Privilege Vulnerability

Posted on September 18, 2026

CVE ID :CVE-2026-85878 Published : Sept. 18, 2026, 12:17 a.m. | 1 hour, 17 minutes ago Description :Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network….

CVE-2026-93436 – vLLM through 0.29.0 Memory Exhaustion via Rejected Requests

Posted on September 18, 2026

CVE ID :CVE-2026-93436 Published : Sept. 17, 2026, 11:18 p.m. | 16 minutes ago Description :vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments….

CVE-2026-93435 – redis-parser through 3.0.0 Denial of Service via Unbounded Recursion

Posted on September 18, 2026

CVE ID :CVE-2026-93435 Published : Sept. 17, 2026, 11:18 p.m. | 16 minutes ago Description :redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis…

CVE-2026-87701 – Azure Cosmos DB Elevation of Privilege Vulnerability

Posted on September 18, 2026

CVE ID :CVE-2026-87701 Published : Sept. 17, 2026, 11:18 p.m. | 16 minutes ago Description :Improper neutralization of special elements in output used by a downstream component (‘injection’) in Azure Cosmos DB allows…

CVE-2026-85889 – Azure AI Foundry Elevation of Privilege Vulnerability

Posted on September 18, 2026

CVE ID :CVE-2026-85889 Published : Sept. 17, 2026, 11:18 p.m. | 16 minutes ago Description :Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a…

CVE-2026-85885 – Microsoft 365 Copilot Elevation of Privilege Vulnerability

Posted on September 18, 2026

CVE ID :CVE-2026-85885 Published : Sept. 17, 2026, 11:18 p.m. | 16 minutes ago Description :Improper neutralization of special elements used in a command (‘command injection’) in M365 Copilot allows an authorized attacker…

Posts pagination

1 2 … 147 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme