Skip to content

Menu
  • Home
Menu

CVE-2026-44693 – Pi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global Session Buffer

Posted on June 11, 2026

CVE ID :CVE-2026-44693 Published : June 10, 2026, 11:16 p.m. | 2 hours, 48 minutes ago Description :Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version…

CVE-2026-42305 – Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows

Posted on June 11, 2026

CVE ID :CVE-2026-42305 Published : June 10, 2026, 11:16 p.m. | 2 hours, 48 minutes ago Description :Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and…

CVE-2026-53738 – Copy & Delete Posts through 1.5.4 Privilege Escalation via cdp_action_handling Handler

Posted on June 11, 2026

CVE ID :CVE-2026-53738 Published : June 10, 2026, 10:17 p.m. | 1 hour ago Description :Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX…

CVE-2026-50131 – Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

Posted on June 11, 2026

CVE ID :CVE-2026-50131 Published : June 10, 2026, 10:17 p.m. | 1 hour ago Description :Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network…

CVE-2026-46689 – Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion

Posted on June 11, 2026

CVE ID :CVE-2026-46689 Published : June 10, 2026, 10:17 p.m. | 1 hour ago Description :Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/… endpoint…

CVE-2026-46669 – `openvm-pairing` pairing check missing proper subfield check on scaling factor

Posted on June 11, 2026

CVE ID :CVE-2026-46669 Published : June 10, 2026, 10:17 p.m. | 1 hour ago Description :OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the…

CVE-2026-46654 – Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss

Posted on June 11, 2026

CVE ID :CVE-2026-46654 Published : June 10, 2026, 10:16 p.m. | 1 hour ago Description :Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side…

CVE-2026-53673 – BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter

Posted on June 10, 2026

CVE ID :CVE-2026-53673 Published : June 10, 2026, 12:16 a.m. | 58 minutes ago Description :BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers…

CVE-2026-46491 – SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion

Posted on June 10, 2026

CVE ID :CVE-2026-46491 Published : June 10, 2026, 12:16 a.m. | 58 minutes ago Description :SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior…

CVE-2026-45782 – Cloud Hypervisor: Use-after-free in virtio-block Async I/O Completion

Posted on June 10, 2026

CVE ID :CVE-2026-45782 Published : June 10, 2026, 12:16 a.m. | 58 minutes ago Description :Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a…

Posts pagination

Previous 1 2 3 4 … 95 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme