Skip to content

Menu
  • Home
Menu

CVE-2026-55652 – Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin)

Posted on July 16, 2026

CVE ID :CVE-2026-55652 Published : July 15, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in…

CVE-2026-55576 – MaaAssistantArknights: PR-title expression injection in release-preparation.yml

Posted on July 16, 2026

CVE ID :CVE-2026-55576 Published : July 15, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled…

CVE-2026-55445 – Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication

Posted on July 16, 2026

CVE ID :CVE-2026-55445 Published : July 15, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the…

CVE-2026-55234 – Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule)

Posted on July 16, 2026

CVE ID :CVE-2026-55234 Published : July 15, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in…

CVE-2026-54458 – AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin

Posted on July 16, 2026

CVE ID :CVE-2026-54458 Published : July 15, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site…

CVE-2026-59733 – rclone `serve restic –private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users’ repositories

Posted on July 15, 2026

CVE ID :CVE-2026-59733 Published : July 14, 2026, 10:17 p.m. | 2 hours, 16 minutes ago Description :Rclone is a command-line program to sync files and directories to and from different cloud storage providers….

CVE-2026-50130 – Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`

Posted on July 15, 2026

CVE ID :CVE-2026-50130 Published : July 14, 2026, 10:17 p.m. | 2 hours, 16 minutes ago Description :Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From…

CVE-2026-48334 – Illustrator | Improper Input Validation (CWE-20)

Posted on July 15, 2026

CVE ID :CVE-2026-48334 Published : July 14, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in…

CVE-2026-48290 – CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)

Posted on July 15, 2026

CVE ID :CVE-2026-48290 Published : July 14, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary…

CVE-2026-48275 – Illustrator | Untrusted Search Path (CWE-426)

Posted on July 15, 2026

CVE ID :CVE-2026-48275 Published : July 14, 2026, 10:17 p.m. | 2 hours, 17 minutes ago Description :Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in…

Posts pagination

Previous 1 … 17 18 19 … 129 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme