CVE ID :CVE-2026-58593 Published : July 1, 2026, 7:27 p.m. | 3 hours, 45 minutes ago Description :NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor….
CVE-2026-58592 – Ladybird – Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssembly ESM Integration
CVE ID :CVE-2026-58592 Published : July 1, 2026, 7:27 p.m. | 3 hours, 45 minutes ago Description :Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is…
CVE-2026-58457 – Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp
CVE ID :CVE-2026-58457 Published : July 1, 2026, 7:22 p.m. | 3 hours, 50 minutes ago Description :Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows…
CVE-2026-49119 – Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()
CVE ID :CVE-2026-49119 Published : July 1, 2026, 6:30 p.m. | 4 hours, 42 minutes ago Description :Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component’s preprocess() method that allows unauthenticated…
CVE-2026-50110 – Use of Hard-coded Credentials in StoneFly Storage Concentrator
CVE ID :CVE-2026-50110 Published : June 30, 2026, 10:54 p.m. | 2 hours, 18 minutes ago Description :Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file….
CVE-2026-56413 – OS Command Injection in StoneFly Storage Concentrator
CVE ID :CVE-2026-56413 Published : June 30, 2026, 10:50 p.m. | 2 hours, 21 minutes ago Description :Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on…
CVE-2026-56415 – OS Command Injection in StoneFly Storage Concentrator
CVE ID :CVE-2026-56415 Published : June 30, 2026, 10:40 p.m. | 2 hours, 31 minutes ago Description :Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable…
CVE-2026-55721 – SQL Injection in StoneFly Storage Concentrator
CVE ID :CVE-2026-55721 Published : June 30, 2026, 10:36 p.m. | 2 hours, 36 minutes ago Description :Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl…
CVE-2026-57995 – phpMyFAQ – Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissions
CVE ID :CVE-2026-57995 Published : June 30, 2026, 10:08 p.m. | 3 hours, 4 minutes ago Description :phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary…
CVE-2026-7656 – Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack
CVE ID :CVE-2026-7656 Published : June 29, 2026, 10:09 p.m. | 3 hours, 3 minutes ago Description :The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined…