Skip to content

Menu
  • Home
Menu

CVE-2026-102361 – mall4j through 4.0 Missing Authentication in Password Update Endpoint

Posted on September 29, 2026

CVE ID :CVE-2026-102361 Published : Sept. 29, 2026, 12:17 a.m. | 13 minutes ago Description :mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to…

CVE-2026-101264 – Ziroom ZHOME A0101 set_passwd command injection

Posted on September 29, 2026

CVE ID :CVE-2026-101264 Published : Sept. 29, 2026, 12:17 a.m. | 13 minutes ago Description :A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd….

CVE-2026-101263 – Ziroom ZHOME A0101 set_online_client command injection

Posted on September 29, 2026

CVE ID :CVE-2026-101263 Published : Sept. 29, 2026, 12:17 a.m. | 13 minutes ago Description :A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file…

CVE-2026-102334 – Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection

Posted on September 29, 2026

CVE ID :CVE-2026-102334 Published : Sept. 28, 2026, 11:17 p.m. | 1 hour, 13 minutes ago Description :Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password…

CVE-2026-101262 – Ziroom ZHOME A0101 set_online_client command injection

Posted on September 29, 2026

CVE ID :CVE-2026-101262 Published : Sept. 28, 2026, 11:17 p.m. | 1 hour, 13 minutes ago Description :A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the…

CVE-2026-100886 – Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication

Posted on September 28, 2026

CVE ID :CVE-2026-100886 Published : Sept. 27, 2026, 11:16 p.m. | 1 hour, 8 minutes ago Description :A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an…

CVE-2026-101090 – Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri

Posted on September 28, 2026

CVE ID :CVE-2026-101090 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional…

CVE-2026-101084 – obot before v0.21.1 Authorization Bypass via /mcp-connect

Posted on September 28, 2026

CVE ID :CVE-2026-101084 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated…

CVE-2026-101065 – Obot Quickstart Docker Deployment Unauthenticated Admin Access

Posted on September 28, 2026

CVE ID :CVE-2026-101065 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the…

CVE-2026-101064 – Obot before v0.23.0 Server-Side Request Forgery via MCP

Posted on September 28, 2026

CVE ID :CVE-2026-101064 Published : Sept. 27, 2026, 9:17 p.m. | 3 hours, 8 minutes ago Description :Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged…

Posts pagination

1 2 … 154 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme