Skip to content

Menu
  • Home
Menu

CVE-2026-78239 – Xiiaozet LK100W Missing Authentication for Critical Function

Posted on August 28, 2026

CVE ID :CVE-2026-78239 Published : Aug. 28, 2026, 12:18 a.m. | 17 minutes ago Description :Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to…

CVE-2026-78037 – Xiiaozet LK100W OS Command Injection

Posted on August 28, 2026

CVE ID :CVE-2026-78037 Published : Aug. 28, 2026, 12:18 a.m. | 17 minutes ago Description :Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be…

CVE-2026-77977 – Ebyte NE2-D11 Missing Authentication for Critical Function

Posted on August 28, 2026

CVE ID :CVE-2026-77977 Published : Aug. 28, 2026, 12:18 a.m. | 17 minutes ago Description :Ebyte gateway product’s vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default…

CVE-2026-77358 – cpp-httplib: Use-after-free of TLS session in WebSocketClient::shutdown_and_close()

Posted on August 28, 2026

CVE ID :CVE-2026-77358 Published : Aug. 28, 2026, 12:18 a.m. | 17 minutes ago Description :cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the…

CVE-2026-76945 – Ebyte NE2-D11 Use of Client-Side Authentication

Posted on August 28, 2026

CVE ID :CVE-2026-76945 Published : Aug. 28, 2026, 12:18 a.m. | 17 minutes ago Description :The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or…

CVE-2026-65956 – KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover and SSRF

Posted on August 27, 2026

CVE ID :CVE-2026-65956 Published : Aug. 26, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration…

CVE-2026-47665 – Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML

Posted on August 27, 2026

CVE ID :CVE-2026-47665 Published : Aug. 26, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is…

CVE-2026-77317 – SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwrite

Posted on August 27, 2026

CVE ID :CVE-2026-77317 Published : Aug. 26, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the…

CVE-2026-77298 – SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy

Posted on August 27, 2026

CVE ID :CVE-2026-77298 Published : Aug. 26, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3…

CVE-2026-65647 – Plesk Improper Symlink Resolution Arbitrary Code Execution

Posted on August 27, 2026

CVE ID :CVE-2026-65647 Published : Aug. 26, 2026, 10:16 p.m. | 2 hours, 19 minutes ago Description :Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as…

Posts pagination

1 2 … 135 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme