Skip to content

Menu
  • Home
Menu

CVE-2026-17497 – NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python

Posted on July 27, 2026

CVE ID :CVE-2026-17497 Published : July 26, 2026, 3:16 p.m. | 9 hours, 21 minutes ago Description :NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary…

CVE-2026-17496 – NoteGen chat preview XSS via unsanitized AI/skill HTML rendering

Posted on July 27, 2026

CVE ID :CVE-2026-17496 Published : July 26, 2026, 3:16 p.m. | 9 hours, 21 minutes ago Description :NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into…

CVE-2026-15962 – Fluent Forms Pro Add On Pack <= 6.2.6 – Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field

Posted on July 27, 2026

CVE ID :CVE-2026-15962 Published : July 26, 2026, 2:16 a.m. | 22 hours, 21 minutes ago Description :The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in…

CVE-2026-66013 – OpenRemote before 1.26.2 Authentication Bypass via Console Registration

Posted on July 26, 2026

CVE ID :CVE-2026-66013 Published : July 25, 2026, 11:17 a.m. | 13 hours, 20 minutes ago Description :OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers…

CVE-2026-66012 – SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP

Posted on July 26, 2026

CVE ID :CVE-2026-66012 Published : July 25, 2026, 11:17 a.m. | 13 hours, 20 minutes ago Description :SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated…

CVE-2026-10818 – WPForms Pro <= 1.10.1.1 – Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering

Posted on July 26, 2026

CVE ID :CVE-2026-10818 Published : July 25, 2026, 7:17 a.m. | 17 hours, 20 minutes ago Description :The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to,…

CVE-2026-66374 – Knot Resolver Heap-Based Buffer Overflow Remote Code Execution

Posted on July 26, 2026

CVE ID :CVE-2026-66374 Published : July 25, 2026, 1:16 a.m. | 23 hours, 21 minutes ago Description :Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC)…

CVE-2026-61892 – Weintek cMT3092X Incorrect Permission Assignment for Critical Resource

Posted on July 25, 2026

CVE ID :CVE-2026-61892 Published : July 24, 2026, 11:16 p.m. | 1 hour, 20 minutes ago Description :Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges. Severity: 8.8 | HIGH…

CVE-2026-60134 – Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision

Posted on July 25, 2026

CVE ID :CVE-2026-60134 Published : July 24, 2026, 11:16 p.m. | 1 hour, 20 minutes ago Description :Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. Severity: 8.8 |…

CVE-2026-61884 – Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel

Posted on July 25, 2026

CVE ID :CVE-2026-61884 Published : July 24, 2026, 10:16 p.m. | 2 hours, 20 minutes ago Description :The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login…

Posts pagination

1 2 … 116 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme