Overzicht van binnengekomen advisories.
1553 resultaten gevonden
CVE-2026-6223 describes an improper restriction of excessive authentication attempts vulnerability in the Bahçelievler Municipality BiHayat mobile application. This flaw allows attackers to perform authentication bypass, potentially gaining unauthorized access to user accounts. The affected versions span from 2.1.7 through 07092026. The vulnerability is classified under CWE for brute-force or unlimited login attempts without lockout mechanisms. The vendor was contacted prior to public disclosure but did not respond. The disclosure was published via the Turkish cybersecurity authority siberguvenlik.gov.tr as well as the NVD. No patch or mitigation has been confirmed from the vendor side.
Bekijk origineel advisory →league/commonmark (thephpleague/commonmark) versions 2.7.0 through 2.9.0 contain a cross-site scripting (XSS) vulnerability in the AttributesExtension. Attackers can prefix attribute names with a U+000C form feed byte to bypass the AttributesHelper::filterAttributes() event-handler filter, as PHP's trim() does not strip this character. This allows injection of event handlers like onclick into rendered HTML. The same bypass also defeats the allow_unsafe_links check, permitting javascript: URIs in href/src attributes even when the setting is disabled. Exploitation requires that untrusted Markdown is processed with the AttributesExtension enabled. The injected script executes when the rendered HTML is viewed by a victim's browser. The vulnerability has been fixed in version 2.9.1.
Bekijk origineel advisory →A critical Missing Authorization vulnerability (CVE-2026-61410) has been identified in Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted request to the application, bypassing code execution restrictions and achieving remote command execution. The vulnerability is rated critical due to its unauthenticated and remote exploitability. No credentials are required to exploit this flaw, significantly lowering the barrier for attackers. Dell has issued a security advisory (DSA-2026-382) and strongly recommends customers upgrade to the patched versions at the earliest opportunity.
Bekijk origineel advisory →A SQL injection vulnerability has been identified in itsourcecode School Management System version 1.0. The vulnerability exists in the User_Login.php file, where manipulation of the 'email' argument allows an attacker to perform SQL injection. The attack can be executed remotely without requiring local access. A public exploit is already available, increasing the risk of active exploitation. The affected function within User_Login.php is not fully identified but the attack vector is well-documented. This vulnerability poses a significant risk to institutions using this school management software. Organizations running this system should apply patches or mitigations immediately to prevent unauthorized database access or data breaches.
Bekijk origineel advisory →A vulnerability has been identified in SourceCodester Simple Traffic Offense System version 1.0. The flaw resides in the file saveuser.php within the User Creation component. By manipulating the 'position' argument, an attacker can bypass authentication controls entirely. The vulnerability is remotely exploitable without requiring prior authentication or user interaction. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a PHP-based web application commonly used for traffic violation management. The missing authentication flaw could allow unauthorized users to create or manipulate user accounts. This represents a significant access control weakness with potential for full system compromise. Organizations using this software should apply mitigations or remove public exposure immediately.
Bekijk origineel advisory →LibreNMS versions before 26.8.0 are affected by an argument injection vulnerability in the graph_title parameter. Authenticated attackers can break out of double-quote escaping to inject arbitrary rrdtool arguments. By injecting DEF and LINE arguments, attackers can read RRD files from devices they are not authorized to access. Additionally, newline injection can be used to execute arbitrary rrdtool commands, effectively bypassing per-device authorization checks. The vulnerability requires authentication but can lead to unauthorized data access and command execution within the rrdtool context. A fix is available in LibreNMS version 26.8.0 and later. Security advisories have been published on GitHub and VulnCheck detailing the issue and remediation steps.
Bekijk origineel advisory →PocketMine-MP versions prior to 3.26.5 and 4.0.5 contain a vulnerability where skin data fields submitted by players are not properly validated for length. This allows attackers to submit oversized values that exceed the 32767 byte TAG_String limit used in NBT data serialization. Fields such as skinID and geometryName can be exploited by sending oversized data, triggering exceptions during NBT serialization and causing server crashes. The vulnerability enables unauthenticated remote attackers to perform denial-of-service attacks against PocketMine-MP game servers. Fixes were introduced in versions 3.26.5 and 4.0.5 with proper input length validation.
Bekijk origineel advisory →A SQL injection vulnerability has been identified in jaychouchannel's Tourism-Management-System up to commit 8122bf020d91199eddfff3ee02d1632a70a9a132. The vulnerability resides in the file travel/src/main/java/com/controller/CommonController.java within the CommonDao component. Attackers can manipulate the table, column, xColumn, and yColumn arguments to execute SQL injection attacks remotely. The exploit has been publicly disclosed, increasing the risk of active exploitation. The product does not use versioning, making it difficult to identify affected and unaffected releases. A patch (commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86) has been made available and should be applied immediately. The vulnerability was reported via GitHub issues and pull requests and tracked on VulDB as well as NVD.
Bekijk origineel advisory →A critical OS command injection vulnerability has been identified in the Linksys RE7000 range extender running firmware version 2.0.15. The vulnerability exists in the platform_event_pingTest function accessible via /cgi-bin/json.cgi?PingTest endpoint. Attackers can manipulate the arguments pingTestIp, pingTestPktSize, and pingTestTimes to inject arbitrary OS commands. The attack can be executed remotely without physical access to the device. A public exploit is already available, significantly increasing the risk of active exploitation. The vulnerability affects the PingTest Handler component of the device's CGI interface. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Given the public availability of the exploit and the remote attack vector, this is considered a high-severity issue.
Bekijk origineel advisory →A critical vulnerability was discovered in FreeIPA where the self-managed OTP token Access Control Instruction (ACI) neither requires authentication nor restricts which attributes may be added alongside a token entry. An unauthenticated LDAP client can exploit this flaw, in combination with a related directory server ACI evaluation vulnerability, to create an attacker-controlled Kerberos principal and insert it into the FreeIPA administrators group. This grants the remote, unauthenticated attacker full FreeIPA administrator-group membership, enabling administrative operations against the directory. On SID-enabled deployments, the impact extends to other Identity Management (IdM) services. The flaw represents a severe authentication bypass leading to complete privilege escalation. It is tracked under CVE-2026-76578 and referenced in Red Hat security advisories and Bugzilla.
Bekijk origineel advisory →CVE-2026-86428 affects the commonmark PHP library versions 1.5.0 through before 2.10.0. The vulnerability exists in the AttributesExtension component, which fails to efficiently handle Markdown input containing numerous distinctly-named attributes. Attackers can craft malicious Markdown payloads with many unique attribute names to trigger quadratic-time complexity during attribute merging and filtering operations. This results in excessive CPU consumption, effectively causing a denial of service condition. Legitimate requests are prevented from completing while the server processes the malicious input. The issue is classified as a denial of service vulnerability with a high criticality rating. Users are advised to upgrade to commonmark version 2.10.0 or later to remediate the vulnerability. The flaw was disclosed via GitHub Security Advisories and VulnCheck.
Bekijk origineel advisory →A critical vulnerability has been identified in Tenda AC9 firmware version 15.03.05.14, specifically affecting the R7WebsSecurityHandler function within the Web Management component. The flaw results in improper authentication, allowing attackers to bypass authentication mechanisms remotely. The vulnerability can be exploited without local access, significantly increasing its risk profile. A public exploit has already been published, raising the likelihood of active exploitation in the wild. The affected product is a widely used consumer and small business router manufactured by Tenda. The vulnerability has been assigned CVE-2026-86300 and is tracked on NVD and VulDB. Multiple proof-of-concept references have been published on GitHub detailing unauthorized password setting and product information disclosure. Organizations and individuals using the Tenda AC9 router are advised to apply patches or mitigations immediately.
Bekijk origineel advisory →A vulnerability identified as CVE-2026-86303 was discovered in the 92181 markdown library up to commit 058cab0cb7fb245a0ccc6b8446963ff8d573558f. The vulnerability affects the function 'lds' in the file md.c, where a crafted manipulation can trigger an out-of-bounds read condition. The attack can be executed remotely, increasing its risk profile. The product uses a rolling release model, making version-based tracking unavailable. A patch commit (c000d2f9cf390c315378d3717cf20911cf3e80a6) has been identified and should be applied to remediate the issue. The vulnerability is tracked on both NVD and VulDB platforms. No authentication details or CVSS scores are mentioned in the article. Users of the affected library are advised to apply the available patch immediately.
Bekijk origineel advisory →league/commonmark versions before 2.9.1 are affected by multiple denial of service vulnerabilities in their Markdown parsing logic. Specifically, the fenced code block detection, reference link label lookup, and emphasis delimiter processing perform super-linear (potentially exponential) work on specially crafted input. Attackers can exploit this by submitting Markdown content containing long backtick runs, deeply nested brackets, or complex delimiter sequences. This causes disproportionate CPU consumption on the server, effectively blocking legitimate requests from completing. The vulnerability is classified as a ReDoS or algorithmic complexity attack vector. A fix is available in version 2.9.1 of the library. The issue has been documented across multiple security advisories including a GitHub Security Advisory and a VulnCheck entry.
Bekijk origineel advisory →CVE-2026-86433 affects commonmark versions 1.5.0 through 2.8.4, exposing a denial of service vulnerability in the Attributes extension. The vulnerable function AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning, leading to algorithmic complexity issues. Unauthenticated attackers can exploit this by submitting approximately 32 KB of repeated attribute blocks to the parser. This input causes parsing operations to exceed 5 seconds, effectively exhausting server resources. The vulnerability requires no authentication, lowering the barrier for exploitation. Affected users should upgrade to commonmark version 2.8.4 or later to remediate the issue. The flaw is documented across NVD, GitHub Security Advisories, and VulnCheck.
Bekijk origineel advisory →A security flaw has been identified in the light0011 CMS project affecting the Upload::upload function within ThinkPHP/Library/Think/Upload.class.php. The vulnerability allows unrestricted file uploads, which can be exploited remotely. A public exploit has already been released, increasing the risk of active exploitation. The affected software uses a rolling release strategy, making it impossible to specify exact affected or patched version numbers. The vendor was notified via a GitHub issue report but has not responded or issued a fix. The vulnerability is tracked as CVE-2026-86305 and is indexed on both NVD and VulDB. Due to the public availability of exploit code and lack of vendor response, the risk remains high for users of this CMS.
Bekijk origineel advisory →A critical unrestricted file upload vulnerability has been identified in Beijing Meite Software Technology's U+Smart Enjoyment WebSite version 18.6001.1096.1000. The vulnerability exists in the file /Report/Upload/UploadFormImg.ashx, where manipulation of the 'File' argument allows attackers to upload arbitrary files without restriction. The flaw can be exploited remotely, making it accessible to a wide range of threat actors. A public exploit has already been disclosed, increasing the risk of active exploitation in the wild. The vulnerability has been catalogued under CVE-2026-86272 and tracked in VulDB as entry 399431. No authentication bypass or additional prerequisites are detailed, suggesting the attack surface may be broad. Organizations using this software should apply patches or mitigations immediately. The unrestricted upload capability could allow attackers to upload malicious scripts or web shells, potentially leading to full system compromise.
Bekijk origineel advisory →A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /delete_subject.php file, where manipulation of the 'ID' argument allows an attacker to perform SQL injection. The attack can be initiated remotely without requiring physical access. A public exploit has already been released, increasing the risk of active exploitation. The vulnerability affects an unknown function within the identified file. No authentication bypass details are specified, but remote exploitability makes this a significant risk. The issue has been documented across multiple security databases including NVD and VulDB.
Bekijk origineel advisory →A vulnerability was identified in D-Link DIR-605 B1v202WWB03 affecting the function tunnel_set_params in the L2TP Control Message Parser component. The flaw resides in the file progs.gpl/pppd.alpha/l2tp/tunnel.c and is triggered by manipulation of the peer_hostname argument, leading to an off-by-one error. The attack can be performed remotely, though it is assessed as highly complex and difficult to exploit. A public exploit is available, increasing the risk of exploitation in the wild. The vulnerability is classified as an out-of-bounds write condition. It impacts the L2TP tunneling functionality of the affected router firmware. No patch details are mentioned in the article. The availability of a public exploit elevates the overall risk level. Organizations using the affected D-Link hardware should monitor for updates from D-Link.
Bekijk origineel advisory →A critical privilege escalation vulnerability (CVE-2026-80238) has been identified in Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and Application versions prior to 5.36.00.00. The flaw is classified as Execution with Unnecessary Privileges and allows a low-privileged user with SSH access to gain root-level control of the host by exploiting an exposed Docker socket, without requiring a password. Additionally, an attacker who compromises a containerized service can use the same Docker socket to escape the container and achieve full host-level control. The vulnerability can also be leveraged by unauthenticated attackers with local access, leading to protection mechanism bypass. Dell has rated this vulnerability as critical and strongly recommends customers upgrade immediately to the patched versions.
Bekijk origineel advisory →