Skip to content

Menu
  • Home
Menu

CVE-2026-55830 – RestrictedPython guard hooks can be shadowed via positional-only arguments

Posted on July 9, 2026

CVE ID :CVE-2026-55830 Published : July 8, 2026, 10:17 p.m. | 57 minutes ago Description :RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide…

CVE-2026-55471 – HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory

Posted on July 9, 2026

CVE ID :CVE-2026-55471 Published : July 8, 2026, 10:17 p.m. | 57 minutes ago Description :HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to…

CVE-2026-44024 – Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Posted on July 9, 2026

CVE ID :CVE-2026-44024 Published : July 8, 2026, 10:17 p.m. | 57 minutes ago Description :Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and…

CVE-2026-10037 – Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal

Posted on July 9, 2026

CVE ID :CVE-2026-10037 Published : July 8, 2026, 10:17 p.m. | 58 minutes ago Description :A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by…

CVE-2026-55429 – Coder’s workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

Posted on July 8, 2026

CVE ID :CVE-2026-55429 Published : July 8, 2026, 12:16 a.m. | 58 minutes ago Description :Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2,…

CVE-2026-55428 – Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

Posted on July 8, 2026

CVE ID :CVE-2026-55428 Published : July 8, 2026, 12:16 a.m. | 58 minutes ago Description :Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2,…

CVE-2026-55427 – Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

Posted on July 8, 2026

CVE ID :CVE-2026-55427 Published : July 8, 2026, 12:16 a.m. | 58 minutes ago Description :Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2,…

CVE-2026-59705 – mem0 – OpenMemory API Unauthenticated Access via Memory Endpoints

Posted on July 8, 2026

CVE ID :CVE-2026-59705 Published : July 7, 2026, 11:16 p.m. | 1 hour, 58 minutes ago Description :mem0’s openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete…

CVE-2026-59706 – mem0 – Server-Side Request Forgery and Plaintext API Key Exposure via Unauthenticated Config Endpoints

Posted on July 8, 2026

CVE ID :CVE-2026-59706 Published : July 7, 2026, 10:16 p.m. | 58 minutes ago Description :mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery…

CVE-2026-55418 – FastGPT: S3 presign/read handlers do not bind the object key to the caller’s team (cross-team file disclosure)

Posted on July 8, 2026

CVE ID :CVE-2026-55418 Published : July 7, 2026, 10:16 p.m. | 58 minutes ago Description :FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an…

Posts pagination

Previous 1 … 32 33 34 … 140 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme