Skip to content

Menu
  • Home
Menu

CVE-2026-67531 – FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool

Posted on August 6, 2026

CVE ID :CVE-2026-67531 Published : Aug. 6, 2026, 12:16 a.m. | 1 hour, 33 minutes ago Description :FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool…

CVE-2026-19024 – HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message

Posted on August 6, 2026

CVE ID :CVE-2026-19024 Published : Aug. 5, 2026, 11:16 p.m. | 33 minutes ago Description :NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.1.1 allows attackers to cause a denial of service via…

CVE-2026-71320 – Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

Posted on August 6, 2026

CVE ID :CVE-2026-71320 Published : Aug. 5, 2026, 10:17 p.m. | 1 hour, 33 minutes ago Description :Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker…

CVE-2026-71319 – Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution

Posted on August 6, 2026

CVE ID :CVE-2026-71319 Published : Aug. 5, 2026, 10:17 p.m. | 1 hour, 33 minutes ago Description :Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only)…

CVE-2026-71315 – Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)

Posted on August 6, 2026

CVE ID :CVE-2026-71315 Published : Aug. 5, 2026, 9:16 p.m. | 2 hours, 33 minutes ago Description :Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules…

CVE-2026-71312 – rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

Posted on August 6, 2026

CVE ID :CVE-2026-71312 Published : Aug. 5, 2026, 9:16 p.m. | 2 hours, 33 minutes ago Description :rclone is a command-line program to sync files and directories to and from different cloud storage providers….

CVE-2026-46334 – OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning

Posted on August 5, 2026

CVE ID :CVE-2026-46334 Published : Aug. 5, 2026, 12:17 a.m. | 1 hour, 32 minutes ago Description :OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a…

CVE-2026-45809 – OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watcher URI

Posted on August 5, 2026

CVE ID :CVE-2026-45809 Published : Aug. 5, 2026, 12:17 a.m. | 1 hour, 32 minutes ago Description :OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a…

CVE-2026-45537 – OpenSIPS: Global Buffer Overflow in construct_uri

Posted on August 5, 2026

CVE ID :CVE-2026-45537 Published : Aug. 4, 2026, 11:16 p.m. | 32 minutes ago Description :OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri()…

CVE-2026-70619 – Odysseus Missing Admin Authorization via Embedding Endpoint Routes

Posted on August 5, 2026

CVE ID :CVE-2026-70619 Published : Aug. 4, 2026, 10:17 p.m. | 1 hour, 31 minutes ago Description :Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide…

Posts pagination

1 2 … 123 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme