Skip to content

Menu
  • Home
Menu

CVE-2026-64863 – goshs –no-delete WebDAV MOVE bypass allows file deletion/overwrite

Posted on July 29, 2026

CVE ID :CVE-2026-64863 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go…

CVE-2026-62325 – goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

Posted on July 29, 2026

CVE ID :CVE-2026-62325 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the…

CVE-2026-54658 – @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

Posted on July 29, 2026

CVE ID :CVE-2026-54658 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape…

CVE-2026-54650 – openhole-server vulnerable to path traversal via URL-decoded request path

Posted on July 29, 2026

CVE ID :CVE-2026-54650 Published : July 28, 2026, 11:17 p.m. | 1 hour, 21 minutes ago Description :openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded…

CVE-2026-54691 – datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirects

Posted on July 29, 2026

CVE ID :CVE-2026-54691 Published : July 28, 2026, 10:17 p.m. | 2 hours, 20 minutes ago Description :datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts –url targets…

CVE-2026-55685 – React Router: Unauthenticated Denial of Service via Inefficient Route Matching

Posted on July 28, 2026

CVE ID :CVE-2026-55685 Published : July 27, 2026, 10:17 p.m. | 2 hours, 20 minutes ago Description :React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be…

CVE-2026-66824 – Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding

Posted on July 28, 2026

CVE ID :CVE-2026-66824 Published : July 27, 2026, 9:17 p.m. | 3 hours, 20 minutes ago Description :A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized…

CVE-2026-66014 – Potential authentication bypass leading to privilege escalation in Artifactory

Posted on July 28, 2026

CVE ID :CVE-2026-66014 Published : July 27, 2026, 8:16 p.m. | 4 hours, 21 minutes ago Description :JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow…

CVE-2026-65921 – Potential path traversal leading to unauthorized file writes

Posted on July 28, 2026

CVE ID :CVE-2026-65921 Published : July 27, 2026, 8:16 p.m. | 4 hours, 21 minutes ago Description :A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside…

CVE-2026-65617 – Potential remote code execution on an Artifactory package service container.

Posted on July 28, 2026

CVE ID :CVE-2026-65617 Published : July 27, 2026, 8:16 p.m. | 4 hours, 21 minutes ago Description :A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity,…

Posts pagination

1 2 … 117 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme