Overview of incoming advisories.
1553 results found
CVE-2026-53728 affects Medplum, a healthcare developer platform, prior to version 5.1.6. The vulnerability exists in the external identity provider callback endpoint (GET /auth/external), which accepts attacker-controlled redirect URIs that only need to start with a registered client redirect URI rather than matching exactly. An attacker can tamper with the state.redirectUri field (serialized as raw JSON and trusted by the callback) to redirect authorization artifacts to an attacker-controlled endpoint. This can result in a cross-origin authorization code leak when the registered redirect URI is a bare origin or extendable prefix. The flaw enables theft of Medplum login codes and tokens after a successful external IdP authentication flow. The issue has been fully patched in Medplum version 5.1.6. Healthcare application developers using Medplum should upgrade immediately to mitigate the risk of credential and authorization token theft.
View original advisory →R2R versions through 3.6.6 contain a SQL injection vulnerability in the retrieval search endpoint. Unauthenticated attackers can manipulate the filter key parameter to inject SQL predicates into the chunks search query. The vulnerability arises from direct interpolation of filter keys into the SQL WHERE clause without parameterization or escaping. This allows attackers to perform time-based and boolean-based data exfiltration from the application database. No authentication is required to exploit this vulnerability, making it particularly dangerous. The affected product is SciPhi-AI's R2R, an AI retrieval framework. The issue has been reported via GitHub and documented by VulnCheck.
View original advisory →A critical OS command injection vulnerability has been identified in D-Link DNS-320 ShareCenter version 2.06B01. The flaw exists in the /cgi/file_sharing.cgi component, specifically through manipulation of the 'fileurl' argument in the File Sharing feature. Successful exploitation allows remote attackers to execute arbitrary OS commands on the affected device. The attack can be launched remotely without physical access to the device. A public exploit has been disclosed, significantly increasing the risk of active exploitation. The vulnerability affects network-attached storage devices commonly used in home and small business environments. D-Link has been referenced as the vendor responsible for the affected product. The public disclosure of the exploit raises the urgency for patching or mitigation. Users of the affected firmware version are advised to apply security updates or workarounds immediately.
View original advisory →A SQL injection vulnerability has been identified in SeaCMS up to version 13.6, specifically within the WeChat Module component. The vulnerability exists in the addslashes function located in the file weixin/index.php. Attackers can manipulate the 'Content' argument to perform SQL injection attacks remotely. The vulnerability is publicly disclosed and a working exploit is available, increasing the risk of active exploitation. No authentication details are specified, suggesting the attack surface may be broad. The affected software is SeaCMS, a content management system. The public availability of the exploit makes this a high-priority issue for administrators running affected versions. Users are advised to update or apply mitigations immediately to prevent unauthorized database access or manipulation.
View original advisory →CVE-2026-85028 affects the AWS FPGA Development Kit (aws-fpga) before version 2.3.4. The vulnerability exists in the FPGA management tool installation component, which creates temporary files in a directory with insecure permissions. Local users can exploit this by placing crafted shell content at a predictable path in a world-writable temporary directory. When the installation process elevates its privileges, it reads the attacker-controlled file, enabling arbitrary code execution with root privileges. This is a classic symlink/temp file race condition (TOCTOU) type vulnerability. The attack requires local access to the system. Remediation requires upgrading to aws-fpga version 2.3.4. AWS has published a security bulletin and a GitHub advisory addressing this issue.
View original advisory →WWBN AVideo contains a critical authentication failure vulnerability tracked as CVE-2026-85154. The vulnerability stems from the video_id_hash credential functioning as a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash value can replay it indefinitely to authenticate as the video owner with full administrative privileges. The credential remains valid even after the account owner changes their password, eliminating the standard remediation path. This design flaw allows persistent unauthorized access with no built-in mechanism for revocation. The vulnerability represents a significant risk for any AVideo installation where a video_id_hash has been exposed or intercepted.
View original advisory →A critical OS command injection vulnerability has been identified in D-Link DNS-340L firmware version 1.01B04. The vulnerability resides in the /cgi-bin/addon_center.cgi file within the Add-On Center component. Attackers can manipulate the arguments f_name, f_url, f_flag, and f_login_user to inject and execute arbitrary OS commands. The attack can be launched remotely without physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation. This vulnerability poses a significant threat to network-attached storage devices running the affected firmware. No patch or mitigation details are currently provided in the advisory. Users of the affected device should monitor D-Link's official security advisories for updates.
View original advisory →CVE-2026-85176 affects DbGate through version 7.2.6, where the jsldata controller fails to properly validate jslid parameters. Authenticated users can exploit this flaw to read and write arbitrary files on the server via file:// scheme resolution. The vulnerability resides in the getJslFileName() utility function, which can be manipulated to bypass directory containment controls. Attackers with valid credentials can access sensitive files outside intended directories, including encrypted database credentials stored in connection configurations. This represents a significant risk for deployments where DbGate is exposed to untrusted authenticated users. The issue has been documented in a GitHub issue and independently reported by VulnCheck. No patch version is specified beyond the affected 7.2.6 release. The vulnerability falls into the category of path traversal and improper input validation leading to arbitrary file access.
View original advisory →A vulnerability exists in Amazon Ion-C versions prior to 1.1.6 involving uncontrolled recursion. A remote unauthenticated attacker can craft malicious Ion data that causes the native call stack to be exhausted, resulting in application crash and denial of service. The issue requires no authentication to exploit, making it accessible to any remote actor. The vulnerability has been patched in version 1.1.6 of the Ion-C library. AWS has published a security bulletin and the fix is available via the official GitHub release. The flaw is classified as a denial of service vulnerability due to stack exhaustion triggered by specially crafted input data.
View original advisory →WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint when APIName=channels is specified. The flaw allows unauthenticated attackers to manipulate ORDER BY clauses to reference arbitrary database columns, including sensitive fields such as users.password and users.recoverPass. By exploiting this ordering oracle, attackers can infer password hash values and account recovery tokens without direct data extraction. Additionally, the vulnerability can trigger SQL errors that expose the full query statement and underlying database schema. No authentication is required to exploit this issue, significantly raising its risk profile. The vulnerability affects the AVideo open-source video platform maintained by WWBN. Security advisories have been published on GitHub and VulnCheck detailing the issue and remediation steps.
View original advisory →node-forge versions through 1.4.0 contain a critical vulnerability in RSA PKCS#1 v1.5 signature verification. The library fails to validate the element count in nested DigestAlgorithm sequences, allowing attackers to embed garbage bytes inside the DigestAlgorithm sequence. This flaw enables forging of valid signatures for arbitrary messages when low-exponent RSA keys are used. The vulnerability is identified as an incomplete fix for a prior related issue CVE-2026-33894. Affected source files include asn1.js and rsa.js in the node-forge library. The issue is tracked under GHSA-ppp5-5v6c-4jwp on GitHub and has been reported via VulnCheck advisories. Users of node-forge are advised to review and apply any available patches or mitigations promptly.
View original advisory →A buffer overflow vulnerability has been identified in TOTOLINK CP450 version 4.1.0. The vulnerability resides in an unknown function within the /cgi-bin/cstecgi.cgi file. By manipulating the 'topicurl' argument, an attacker can trigger a buffer overflow condition. The vulnerability is remotely exploitable, making it accessible to attackers without physical access to the device. TOTOLINK CP450 is a network router/access point device, placing this vulnerability in the network infrastructure category. The flaw could potentially allow remote code execution or denial of service. No authentication requirements for exploitation are mentioned, which increases the severity. The vulnerability has been assigned CVE-2026-85031 and is tracked in the NVD and VulDB databases.
View original advisory →CAT (dianping/cat) through version 3.1.0 contains a critical session cookie forgery vulnerability. The application uses Java's String.hashCode() as the sole integrity check for session cookies without any server-side secret keying, allowing attackers to forge valid checksums entirely offline. Additionally, attackers can manipulate the x-forwarded-for header to bypass IP binding validation mechanisms. By combining these two weaknesses, an attacker can craft admin session cookies granting full configuration access to the application. The vulnerability is tracked as CVE-2026-85181 and affects the TokenBuilder and HttpUtils components of the cat-home module. No server-side secret is involved in the checksum calculation, making the forgery trivial for any attacker familiar with Java's deterministic hashCode algorithm.
View original advisory →A SQL injection vulnerability has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw resides in the Order::pupdate function within the file /rider/orders/controller.php?action=edit&actions=confirm, part of the Order Status Update component. Attackers can manipulate the 'ID' argument to perform SQL injection attacks remotely without requiring physical access. The exploit has been publicly disclosed, increasing the risk of active exploitation. This type of vulnerability can allow attackers to read, modify, or delete database contents, potentially exposing sensitive patient and order data. The vulnerability is tracked as CVE-2026-85187 and is listed on NVD and VulDB. No patch information is currently noted. Given its remote exploitability and public disclosure, this represents a high-severity risk for deployments of this system.
View original advisory →zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function. The flaw is triggered during non-blocking gzwrite() operations when stale external buffer pointers are present. Attackers can exploit this by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary. This can potentially lead to memory corruption, crashes, or arbitrary code execution. The vulnerability is tracked as CVE-2026-85091 and has been assigned a high criticality rating. Affected users of zlib in the specified version range are advised to apply patches or mitigations promptly. References include the NVD advisory, the zlib GitHub repository, the specific vulnerable source file, and a VulnCheck advisory.
View original advisory →A buffer overflow vulnerability has been identified in the Tenda HG10 router (firmware version 300001138). The vulnerability resides in the formWlanSetup function within the /boaform/formWlanSetup file of the Boa Web Server component. An attacker can manipulate the 'ssid' argument to trigger a buffer overflow condition. The vulnerability is remotely exploitable without requiring physical access to the device. A public exploit has already been disclosed and made available, increasing the risk of active exploitation. The affected product is a consumer-grade IoT/networking device manufactured by Tenda. Given the public availability of the exploit and the remote attack vector, this vulnerability poses a significant risk to users of the affected hardware. Organizations and individuals using the Tenda HG10 should apply patches or mitigations as soon as they become available.
View original advisory →A privilege escalation vulnerability has been identified in the Bricksforge WordPress plugin affecting versions up to and including 3.1.8.8. The vulnerability allows subscriber-level users to escalate their privileges, potentially gaining unauthorized access to higher-level administrative functions. This type of vulnerability is particularly dangerous in WordPress environments as it can lead to full site compromise. The issue is tracked as CVE-2026-84814 and has been documented by both NVD and Patchstack. Users of the Bricksforge plugin are advised to update to a patched version immediately. The vulnerability has been assigned a high criticality rating, reflecting the significant risk it poses to affected WordPress installations.
View original advisory →Label Studio versions through 1.23.0 contain a Server-Side Request Forgery (SSRF) vulnerability due to missing validation of webhook URLs. Authenticated users can craft webhook requests targeting internal services, RFC 1918 private network addresses, and cloud metadata endpoints. This allows attackers to probe and interact with internal infrastructure that would otherwise be inaccessible. Additionally, by enabling payload transmission in outbound webhook requests, attackers can exfiltrate sensitive annotation data to attacker-controlled endpoints. The vulnerability requires authentication but poses significant risk in multi-tenant or shared environments. A fix has been committed and is referenced in the project's GitHub repository. The issue was reported and tracked via GitHub issue #9801 and documented by VulnCheck.
View original advisory →AVideo through commit c91b5975d is affected by a combined cross-site request forgery (CSRF) and path traversal vulnerability in the stopLive.php script. The vulnerability stems from missing CSRF token validation and unsanitized concatenation of the 'key' parameter, allowing attackers to craft malicious image tags with directory traversal payloads such as key=../../videos. When an authenticated administrator visits a malicious page, the payload triggers recursive deletion of targeted server directories, including the videos directory. Exploitation requires no authentication from the attacker but relies on social engineering an admin into visiting a crafted page. The impact is destructive, as it can result in permanent data loss through directory deletion. A fix has been documented in a GitHub security advisory for the WWBN/AVideo repository.
View original advisory →A vulnerability in the fast-uri JavaScript library allows malformed URI hosts containing unbalanced or misplaced authority brackets to bypass host validation logic. The parse() function returns such hosts without reporting an error, while Node.js URL and HTTP clients built on it resolve the same string to a different host. This discrepancy can be exploited to bypass SSRF denylists, redirect allowlists, or proxy routing rules, as the application evaluates security policy against a different string than the one actually used in the HTTP request. The flaw also propagates through normalize(), equal(), and resolve() functions. Affected versions include fast-uri 2.4.5, 3.1.6, and 4.1.3, and fixes are available in 2.4.6, 3.1.7, and 4.1.4 respectively. The fix ensures parse() reports a malformed host error for any host containing a bracket that is not a valid IPv6 literal.
View original advisory →