Skip to content

Menu
  • Home
Menu

CVE-2026-67595 – VaahCMS 2.0.0 – 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php

Posted on July 30, 2026

CVE ID :CVE-2026-67595 Published : July 29, 2026, 10:16 p.m. | 2 hours, 21 minutes ago Description :VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible…

CVE-2026-13308 – Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability

Posted on July 30, 2026

CVE ID :CVE-2026-13308 Published : July 29, 2026, 9:17 p.m. | 3 hours, 20 minutes ago Description :Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers…

CVE-2026-6267 – Insertion of Sensitive Information Into Sent Data in GitLab

Posted on July 30, 2026

CVE ID :CVE-2026-6267 Published : July 29, 2026, 8:17 p.m. | 4 hours, 21 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before…

CVE-2026-67436 – Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins

Posted on July 30, 2026

CVE ID :CVE-2026-67436 Published : July 29, 2026, 8:17 p.m. | 4 hours, 21 minutes ago Description :Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier,…

CVE-2026-67431 – MCP Ruby SDK: Ruby SSE Session Poisoning

Posted on July 30, 2026

CVE ID :CVE-2026-67431 Published : July 29, 2026, 8:17 p.m. | 4 hours, 21 minutes ago Description :MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to…

CVE-2026-64863 – goshs –no-delete WebDAV MOVE bypass allows file deletion/overwrite

Posted on July 29, 2026

CVE ID :CVE-2026-64863 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go…

CVE-2026-62325 – goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

Posted on July 29, 2026

CVE ID :CVE-2026-62325 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the…

CVE-2026-54658 – @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

Posted on July 29, 2026

CVE ID :CVE-2026-54658 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape…

CVE-2026-54650 – openhole-server vulnerable to path traversal via URL-decoded request path

Posted on July 29, 2026

CVE ID :CVE-2026-54650 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded…

CVE-2026-54691 – datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirects

Posted on July 29, 2026

CVE ID :CVE-2026-54691 Published : July 28, 2026, 10:17 p.m. | 2 hours, 20 minutes ago Description :datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts –url targets…

Posts pagination

1 2 … 118 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme