Overview of incoming advisories.
1553 results found
The league/commonmark PHP library (thephpleague/commonmark) in versions >= 1.5.0 and < 2.9.1 is vulnerable to a denial-of-service attack due to quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. These extensions are not enabled by default but when explicitly registered, an unauthenticated attacker can craft small Markdown documents with patterns such as unpaired quotes, repeated block-level attribute blocks, or repeated class attributes to trigger disproportionate CPU consumption. The vulnerability does not affect standard CommonMark or GitHub-Flavored Markdown converters out of the box. Applications that explicitly enable either of the two affected extensions are at risk. The issue has been fixed in version 2.9.1 of the library.
View original advisory →A vulnerability has been identified in sfturing hosp_order up to commit 627f426331da8086ce8fff2017d65b1ddef384f8. The flaw resides in an unknown function within the OrderController.java file of the Order Controller component. By manipulating the 'userIdenf' argument, an attacker can achieve authorization bypass remotely. The exploit is publicly available, increasing the risk of active exploitation. The product uses a rolling release model, making version tracking difficult. The maintainer was notified via a GitHub issue but has not yet responded. No patch or mitigation has been released at this time.
View original advisory →A SQL injection vulnerability has been identified in SourceCodester Online Voting System version 1.0. The flaw exists in the file /voting/ajax.php?action=save_category, where manipulation of the 'Category' argument leads to SQL injection. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a web-based voting application distributed by SourceCodester. No authentication details are specified, suggesting the endpoint may be accessible without prior authentication. The vulnerability has been assigned CVE-2026-86290 and is listed in the NVD database. Organizations using this software should apply patches or mitigations immediately given the public availability of the exploit.
View original advisory →An out-of-bounds write vulnerability has been identified in Samsung Opensource Walrus, classified under CVE-2026-86313. The vulnerability allows overflow buffers and affects a specific commit of the Walrus project (af80e665ea49d9003695a66502f841ed1d8397e7). Out-of-bounds write vulnerabilities can lead to memory corruption, potential code execution, or application crashes. The issue has been reported via the NVD (National Vulnerability Database) and is linked to a pull request on the Samsung Walrus GitHub repository. Samsung Walrus is an open-source WebAssembly runtime. The vulnerability is currently rated as high criticality. A fix or patch may be available or in progress via the referenced GitHub pull request.
View original advisory →A command injection vulnerability (CVE-2026-79698) was identified in multiple Advantech WISE-6610 series IoT gateway devices running firmware version 1.2.1_20251110. The flaw resides in the nodered_lib_apply function within the Node-RED Library component, where manipulation of the 'act' argument allows remote command injection. The vulnerability is remotely exploitable and a public exploit is available, raising the risk of active exploitation. All major WISE-6610 variants are affected, including NB, EB, TB, JB, CB, EL, and P-series models. Advantech was notified early and responded professionally, releasing a patched firmware version 1.2.4_20260821. Users are strongly advised to upgrade to the fixed version immediately. The coordinated disclosure reflects a positive vendor response to the reported issue.
View original advisory →MikroTik released an emergency patch for a critical SSH authentication bypass vulnerability that is already being actively exploited in the wild. The vulnerability allows attackers to bypass SSH authentication on affected MikroTik devices. Exploitation has been confirmed, and attackers are creating new user accounts on compromised devices to maintain persistent access even after patching. Administrators are strongly urged to patch immediately and assume compromise if running vulnerable versions. Post-patch forensic review is recommended to identify unauthorized accounts added by attackers.
View original advisory →Attackers are actively exploiting MikroTik routers with internet-exposed SSH services to gain full administrative control without authentication. CERT Polska issued a warning on September 5 about these attacks, with successful compromises dating back to at least September 2. The attackers are leveraging the SSH remote-access service being publicly reachable to bypass authentication entirely. No victim count or further technical details were disclosed in the initial warning. The campaign represents a significant threat to network infrastructure given MikroTik's widespread deployment in enterprise and ISP environments. The ability to gain full administrative control without credentials makes this a critical severity issue.
View original advisory →A critical OS command injection vulnerability has been identified in Tenda CP3 firmware version 27.5.57.101. The flaw resides in the function CAutoAddWifi::ThreadProc within the file Functions/AutoAddWifi.cpp, part of the Kylin component. An attacker can exploit this vulnerability by manipulating inputs to execute arbitrary OS commands on the affected device. The attack can be launched remotely without requiring physical access to the device. This poses a significant security risk to users of the affected Tenda CP3 device running the specified firmware version. The vulnerability has been reported via VulDB and tracked under CVE-2026-86152.
View original advisory →A buffer overflow vulnerability has been identified in the Tenda HG10 router, firmware version 300001138. The flaw exists in the formURL function located at /boaform/admin/formURL. Attackers can exploit this by manipulating the Keywd or urlFQDN arguments to trigger a buffer overflow condition. The vulnerability can be exploited remotely without requiring physical access to the device. A public exploit has been released, increasing the risk of active exploitation. The affected product is a consumer/SOHO networking device manufactured by Tenda. This type of vulnerability in IoT/networking devices is commonly leveraged for unauthorized access or device compromise. Users and administrators are advised to apply patches or mitigations as soon as they become available. The public disclosure and exploit availability elevate the urgency of remediation.
View original advisory →A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The flaw resides in the mysqli_query function within the file /admin/modal_add_course1.php, where manipulation of the 'course' argument enables SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the target system. A public exploit has already been published, increasing the risk of active exploitation. The issue is tracked under CVE-2026-86221 and has been reported via VulDB and GitHub. Affected users should apply patches or mitigations immediately. The attack surface is limited to the administrative interface of the application. No authentication bypass details were specified, but remote exploitability significantly raises the severity. This type of vulnerability can lead to unauthorized database access, data exfiltration, or full system compromise.
View original advisory →A vulnerability has been identified in Tenda CP3 firmware version 27.5.57.101 affecting the function CRedirServer::SetRedirectEnable in the file Functions/Redirect.cpp. The flaw involves improper privilege management that can be triggered through manipulation of this function. The vulnerability is remotely exploitable, meaning an attacker does not need local access to the device. Tenda CP3 is a network device, making this vulnerability particularly relevant to network infrastructure security. The issue has been catalogued under CVE-2026-86153 and is referenced across multiple vulnerability databases including NVD and VulDB. No patch or mitigation details are explicitly mentioned in the article. The remote exploitability increases the risk profile for affected deployments.
View original advisory →A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the mysqli_query function within the file /admin/modal_add_coursea.php, where manipulation of the 'course' argument allows SQL injection attacks. The vulnerability is remotely exploitable, meaning attackers do not require local access to the target system. A public exploit has already been released, increasing the risk of active exploitation in the wild. The vulnerability is tracked as CVE-2026-86223 and has been assigned a high criticality rating. Organizations using this software should apply mitigations or patches immediately to prevent unauthorized database access or data exfiltration.
View original advisory →A SQL injection vulnerability has been identified in the code-projects Task Management System In PHP version 1.0. The vulnerability exists in the /index.php file within the Login component, where the 'email' parameter is susceptible to SQL injection attacks. An unauthenticated remote attacker can exploit this vulnerability by manipulating the email argument to inject malicious SQL code. The exploit has been publicly disclosed and is available for use, increasing the risk of active exploitation. This type of vulnerability can lead to unauthorized access, data exfiltration, or complete database compromise. The attack requires no special privileges or user interaction, making it particularly dangerous. Organizations using this task management system should apply patches or mitigations immediately.
View original advisory →A SQL injection vulnerability has been identified in SourceCodester Online Voting System version 1.0. The vulnerability exists in the /ajax.php?action=delete_category file, where manipulation of the 'ID' argument leads to SQL injection. The vulnerability can be exploited remotely without requiring local access. A public exploit has been released, increasing the risk of active exploitation. The affected product is a web-based online voting system developed by SourceCodester. The vulnerability has been assigned CVE-2026-86161 and is documented in both the NVD and VulDB databases. Given the public availability of the exploit and the sensitive nature of voting systems, this vulnerability poses a significant risk.
View original advisory →The MemberDash plugin for WordPress contains a critical Insecure Direct Object Reference (IDOR) vulnerability in all versions up to and including 1.8.5. The flaw exists in the 'id' parameter due to missing validation on a user-controlled key during registration. Unauthenticated attackers can exploit this vulnerability to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID. This allows complete account takeover without any notification being sent to the victim. The vulnerability requires no authentication, making it trivially exploitable by remote attackers. The impact is severe as it enables full compromise of WordPress sites running the affected plugin version. Site administrators are advised to update to a patched version immediately.
View original advisory →A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The vulnerability exists in the /delete_user_account.php file, where manipulation of the 'ID' argument allows SQL injection attacks. The flaw can be exploited remotely without requiring physical access to the target system. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability affects an unknown functionality within the targeted file. Attackers could potentially manipulate database queries to gain unauthorized access or extract sensitive data. The issue has been documented in VulDB and tracked under CVE-2026-86210. Users of the affected system are advised to apply patches or mitigations promptly.
View original advisory →CVE-2026-86242 affects Bifrost HTTP transport versions before 2.0.0, allowing unauthenticated remote code execution via a malicious plugin submission to POST /api/plugins when management authentication is disabled (the default configuration). The vulnerability arises because the shared-object loader accepts HTTP URLs as plugin paths, downloads them as .so files, and loads them via Go's plugin.Open, executing any Init function as the Bifrost process user. On dynamically linked builds (DYNAMIC=1), this results in full unauthenticated RCE. On the published statically linked Docker image, the attack is limited to server-side request forgery (SSRF) since plugin.Open fails. Attack complexity is rated High due to constraints around matching Go version, OS, architecture, and linkage. The 1.6.x branch through 1.6.11 does not contain the fix. The fix is available in version 2.0.0 of the HTTP transport.
View original advisory →A SQL injection vulnerability has been identified in the Mstfakts College-Management-System, specifically in the mysqli_query function within the file Front-end/university.php under the Search Handler component. The vulnerability is triggered by manipulating the book_name or book_author arguments, allowing an attacker to perform SQL injection remotely. A public exploit is available, increasing the risk of exploitation. The product uses a rolling release model, so no specific version information is disclosed for affected or patched releases. The vendor was notified via a GitHub issue report but has not yet responded. The vulnerability has been catalogued in VulDB and NVD. No patch or mitigation has been confirmed at this time, leaving users exposed.
View original advisory →A SQL injection vulnerability has been identified in code-projects Content Management System version 1.0. The flaw exists in the /login.php file where manipulation of the user_name parameter allows SQL injection attacks. The vulnerability can be exploited remotely without authentication. A public exploit has already been released, increasing the risk of active exploitation. The issue stems from insufficient input validation on the user_name argument. Attackers could potentially bypass authentication or extract sensitive database information. The vulnerability has been assigned CVE-2026-86168 and is listed in the NVD database. Users of the affected CMS version are advised to apply patches or mitigations immediately.
View original advisory →A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The vulnerability exists in the mysqli_query function within the file /admin/modal_add_course.php, where manipulation of the 'course' argument leads to SQL injection. The attack can be executed remotely without requiring physical access to the system. A public exploit is already available, increasing the risk of active exploitation. The vulnerability affects the administrative interface of the timetabling application. Attackers could potentially access, modify, or delete database contents. Given the public availability of the exploit and remote exploitability, this poses a significant risk to any organization using this software.
View original advisory →