Skip to content

Menu
  • Home
Menu

CVE-2026-58593 – NodeBB – ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User

Posted on July 2, 2026

CVE ID :CVE-2026-58593 Published : July 1, 2026, 7:27 p.m. | 3 hours, 45 minutes ago Description :NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor….

CVE-2026-58592 – Ladybird – Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssembly ESM Integration

Posted on July 2, 2026

CVE ID :CVE-2026-58592 Published : July 1, 2026, 7:27 p.m. | 3 hours, 45 minutes ago Description :Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is…

CVE-2026-58457 – Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp

Posted on July 2, 2026

CVE ID :CVE-2026-58457 Published : July 1, 2026, 7:22 p.m. | 3 hours, 50 minutes ago Description :Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows…

CVE-2026-49119 – Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()

Posted on July 2, 2026

CVE ID :CVE-2026-49119 Published : July 1, 2026, 6:30 p.m. | 4 hours, 42 minutes ago Description :Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component’s preprocess() method that allows unauthenticated…

CVE-2026-50110 – Use of Hard-coded Credentials in StoneFly Storage Concentrator

Posted on July 1, 2026

CVE ID :CVE-2026-50110 Published : June 30, 2026, 10:54 p.m. | 2 hours, 18 minutes ago Description :Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file….

CVE-2026-56413 – OS Command Injection in StoneFly Storage Concentrator

Posted on July 1, 2026

CVE ID :CVE-2026-56413 Published : June 30, 2026, 10:50 p.m. | 2 hours, 21 minutes ago Description :Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on…

CVE-2026-56415 – OS Command Injection in StoneFly Storage Concentrator

Posted on July 1, 2026

CVE ID :CVE-2026-56415 Published : June 30, 2026, 10:40 p.m. | 2 hours, 31 minutes ago Description :Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable…

CVE-2026-55721 – SQL Injection in StoneFly Storage Concentrator

Posted on July 1, 2026

CVE ID :CVE-2026-55721 Published : June 30, 2026, 10:36 p.m. | 2 hours, 36 minutes ago Description :Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl…

CVE-2026-57995 – phpMyFAQ – Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissions

Posted on July 1, 2026

CVE ID :CVE-2026-57995 Published : June 30, 2026, 10:08 p.m. | 3 hours, 4 minutes ago Description :phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary…

CVE-2026-7656 – Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack

Posted on June 30, 2026

CVE ID :CVE-2026-7656 Published : June 29, 2026, 10:09 p.m. | 3 hours, 3 minutes ago Description :The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined…

Posts pagination

Previous 1 … 26 27 28 … 129 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme