Overzicht van binnengekomen advisories.
1553 resultaten gevonden
CVE-2026-19873 affects HTML::FormFu versions through 2.08 for Perl, allowing unauthenticated resource exhaustion via unbounded repeat counts in Repeatable form elements. When counter_name is set, the repeat count is read directly from the query string with only a positive integer check, enabling any unauthenticated GET request to trigger deep-cloning of element subtrees without any cap. Nested Repeatable elements multiply the cost exponentially, e.g., two nested counters of 100 each produce 10,000 clones. After submission, constraint scanning in _find_field_value grows superlinearly with clone count, further amplifying CPU and memory consumption. A single crafted request can exhaust server resources. The latest CPAN release is 2.07 (2018); version 2.08 exists only in the git repository. A patch is available via MetaCPAN security advisories.
Bekijk origineel advisory →A security vulnerability has been identified in Tenda AC18 firmware version 15.03.05.19. The flaw resides in an unknown function within the /goform/telnet endpoint of the Telnet Handler component. The vulnerability stems from missing authentication controls, allowing unauthenticated remote attackers to interact with the telnet interface. The attack can be launched remotely without requiring any credentials or local access. A public exploit has already been released, increasing the risk of active exploitation in the wild. The affected product is a widely used consumer and small business wireless router. The vulnerability is tracked as CVE-2026-82695 and has been published on NVD and VulnDB. Organizations and individuals using Tenda AC18 routers should apply mitigations or patches as soon as they become available.
Bekijk origineel advisory →CVE-2026-81889 is a server-side request forgery (SSRF) vulnerability in elFinder, an open-source web file manager. Prior to version 2.1.70, the URL upload feature in php/elFinder.class.php could bypass SSRF protections via DNS rebinding when PHP cURL is unavailable. The validate_address() function validates the IP from the first DNS resolution, but fsock_get_contents() performs a second DNS resolution connecting to the hostname, allowing attackers to redirect connections to loopback or private addresses. Additionally, get_headers() makes a separate request to the original hostname without reusing the validated connection, creating a secondary blind SSRF path even when cURL is in use. Successful exploitation allows internal HTTP response bodies to be stored as uploaded files and accessed through elFinder. The vulnerability has been patched in elFinder version 2.1.70, with fixes available via two separate commits on GitHub.
Bekijk origineel advisory →A critical unauthenticated SQL injection vulnerability has been identified in the WP Data Access WordPress plugin affecting versions 5.5.81 and below. The vulnerability allows unauthenticated attackers to perform SQL injection attacks, potentially enabling unauthorized access to the database, data exfiltration, and manipulation of stored data. As the exploit requires no authentication, the attack surface is particularly broad, making it accessible to any remote attacker. The vulnerability is tracked as CVE-2026-81293 and has been published on the NVD and Patchstack databases. Users are advised to update the plugin to a patched version immediately to mitigate the risk. The high criticality rating reflects the unauthenticated nature of the exploit and the potential for significant data compromise.
Bekijk origineel advisory →A vulnerability has been identified in Kamailio versions up to 5.5.0 and 6.0.7 affecting the get_4bytes function in the AVP Handler component (src/modules/ims_registrar_scscf/cxdx_avp.c). The flaw can lead to an out-of-bounds read condition that can be triggered remotely. A public exploit has been disclosed, increasing the risk of active exploitation. A patch (abb5d60af6eefbd367bf6588c5589566b090e272) has been released to address the issue. The vendor notes that version 5.5.0 is no longer maintained, urging users to upgrade. Administrators running affected versions are strongly advised to apply the patch immediately. The vulnerability is tracked as CVE-2026-82608 and is listed on NVD and VulDB.
Bekijk origineel advisory →A PHP Object Injection vulnerability has been identified in the Tickera WordPress plugin affecting versions up to and including 3.6.0.2. The vulnerability is unauthenticated, meaning attackers do not need any credentials to exploit it. PHP Object Injection vulnerabilities can allow attackers to perform various malicious actions depending on available PHP classes, potentially including remote code execution, file manipulation, or privilege escalation. The vulnerability has been reported via NVD and documented by Patchstack. Users of the Tickera event ticketing system plugin should update to a patched version immediately. The issue highlights risks associated with improper deserialization of user-supplied data in WordPress plugins.
Bekijk origineel advisory →CVE-2026-79744 affects MCPHub, a unified hub for managing and orchestrating multiple MCP servers and APIs. Prior to version 1.0.29, the PUT /api/system-config endpoint (updateSystemConfig handler) lacked proper authorization checks. The endpoint was protected only by app-wide authentication middleware and a rate limiter, but never verified whether the requesting user had admin privileges via req.user.isAdmin. This means any authenticated user, regardless of role, could modify system configuration settings. The vulnerability represents a broken access control / missing authorization flaw. The issue has been patched in MCPHub version 1.0.29. Users are advised to upgrade immediately to mitigate the risk of unauthorized system configuration changes.
Bekijk origineel advisory →A vulnerability (CVE-2026-82808) was discovered in Inbox Foundry's ActiveInbox Chrome Extension version up to 7.10.24. The extension ships a hardcoded Google OAuth client secret within the file dist/service-worker.production-esm.js, exposing credentials to potential attackers. The attack can be executed remotely and a public exploit is already available. The vendor was notified in advance but has not yet released a fix, citing a backlog of existing bug bounty reports with the programme currently on hold. This hard-coded credential vulnerability could allow unauthorized access to OAuth-protected resources associated with users of the extension. The issue represents a supply chain risk for Chrome users relying on this Gmail productivity extension.
Bekijk origineel advisory →ToolJet Database versions before v3.16.44 contain a critical privilege escalation vulnerability in the join_tables endpoint. The flaw grants JOIN_TABLES ability to all authenticated users without performing role or workspace membership validation. This allows attackers to read arbitrary database tables belonging to any workspace by supplying victim workspace identifiers in the request path. The attacker only needs to authenticate with their own valid workspace credentials to exploit this. The vulnerability enables unauthorized cross-workspace data access, posing significant data confidentiality risks. A fix is available in ToolJet Database v3.16.44 and later. The issue is tracked as CVE-2026-82869 and has been disclosed via GitHub Security Advisories and VulnCheck.
Bekijk origineel advisory →A vulnerability has been identified in D-Link DSM-G600 version 1.01 affecting the /load_file.cgi file within the Multipart Handler component. The flaw allows an attacker to trigger an out-of-bounds write through manipulation of an unknown function. The attack can be launched remotely without physical access to the device. A public exploit has already been released, increasing the risk of active exploitation. The vulnerability is tracked as CVE-2026-82680 and has been assigned a high criticality rating. D-Link network storage devices running the affected firmware version are at risk. Users and administrators are advised to monitor for patches or mitigations from D-Link.
Bekijk origineel advisory →A Server-Side Request Forgery (SSRF) vulnerability was identified in PowerJob up to version 5.1.2. The vulnerability exists in the MuConnectionManager.getOrCreateConnection function within the TestController.java file of the Transport Endpoint component. An attacker can exploit this vulnerability remotely without authentication. A public exploit is already available, increasing the risk of active exploitation. The project was notified via an issue report but has not yet responded or released a patch. The vulnerability affects the powerjob-server-starter module of the PowerJob server. Organizations running PowerJob up to version 5.1.2 are advised to assess their exposure and implement mitigations as the vendor has not addressed the issue.
Bekijk origineel advisory →A SQL injection vulnerability has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw exists in the Customer::cusAuthentication function within the /login.php file of the Customer Login Interface component. Attackers can manipulate the U_USERNAME argument to perform SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit has already been released, increasing the risk of active exploitation. Successful exploitation could allow attackers to bypass authentication and gain unauthorized access. The vulnerability is tracked under CVE-2026-82611 and has been assigned a high criticality rating.
Bekijk origineel advisory →CVE-2026-77348 affects Wallos, an open-source self-hostable personal subscription tracker, prior to version 5.0.0. The vulnerability is an incomplete fix for a prior SSRF issue (CVE-2026-33407), which hardened only the endpoints/logos/search.php endpoint by disabling cURL proxy settings. A second, near-identical unauthenticated endpoint, endpoints/payments/search.php, was overlooked and still passes HTTP_PROXY/HTTPS_PROXY environment variables directly into CURLOPT_PROXY, enabling Server-Side Request Forgery (SSRF) attacks. The endpoint is unauthenticated, increasing the risk of exploitation by remote, unauthenticated attackers. Attackers could leverage this to route requests through attacker-controlled proxies or access internal network resources. The issue has been fully patched in Wallos version 5.0.0. Users are advised to upgrade immediately to mitigate the risk.
Bekijk origineel advisory →hulumi versions prior to v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy. The flaw allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with access to the documented principal can exploit this to create persistent higher-privilege roles within the sandbox account. This represents a significant cloud identity and access management risk. The vulnerability has been assigned CVE-2026-82857 and is documented across NVD, GitHub Security Advisories, and VulnCheck. Remediation requires upgrading to hulumi v1.3.2 or later. No exploitation details beyond the documented principal are specified in the advisory.
Bekijk origineel advisory →hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy. The flaw allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers who possess the documented principal can exploit this to create persistent higher-privilege roles within the sandbox account. This effectively enables unauthorized elevation of cloud permissions. The vulnerability is tracked as CVE-2026-82857 and has been patched in hulumi v1.3.2. It is classified as high severity due to the potential for persistent privilege escalation in cloud IAM environments. Organizations using affected versions should upgrade immediately to mitigate risk.
Bekijk origineel advisory →CVE-2026-79748 affects MCPHub, a unified hub for managing and orchestrating MCP servers/APIs. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints allowed any authenticated non-admin user to create or update server configurations without proper authorization checks. These endpoints immediately spawn the configured process via child_process.spawn without any command allowlist or sanitization. An attacker with valid (non-admin) credentials could supply arbitrary commands such as /bin/sh with arbitrary arguments, resulting in remote code execution as the MCPHub server's OS user. In many deployment scenarios including the official Docker image and npx/systemd setups, this user is root, making the impact critical. The vulnerability has been patched in MCPHub version 0.12.15.
Bekijk origineel advisory →A vulnerability has been identified in MegaEase EaseProbe up to version 2.3.0, affecting the realIP function in web/server.go within the Middleware component. The flaw allows manipulation of HTTP headers X-Forwarded-For, X-Real-IP, and True-Client-IP to bypass access controls improperly. The attack can be initiated remotely without requiring physical access. A public exploit has been published and is available for use. The vendor was contacted prior to disclosure but did not respond. This improper trust of client-supplied headers for IP resolution is a classic IP spoofing vulnerability enabling unauthorized access.
Bekijk origineel advisory →A SQL injection vulnerability has been identified in kishan0725 Hospital-Management-System version 1.0. The flaw exists in the /search.php file, where manipulation of the 'Contact' argument leads to SQL injection. The vulnerability can be exploited remotely without authentication. A public exploit has already been released, increasing the risk of active exploitation. The vendor was notified prior to disclosure but did not respond. This represents a critical risk for any organization running this software. The vulnerability is tracked as CVE-2026-82914 and is documented on NVD and VulDB.
Bekijk origineel advisory →CVE-2026-82397 affects the Tornado Python web framework and asynchronous networking library in versions prior to 6.5.8. The vulnerability exists in the parsing of application/x-www-form-urlencoded request bodies using urllib.parse.parse_qs without enforcing a max_num_fields limit. An unauthenticated attacker can send a crafted request body containing millions of separator-delimited fields, causing the single-threaded event loop to stall synchronously and delaying all active connections. The body size is only bounded by max_buffer_size, which defaults to approximately 100MB, making large payloads feasible. The vulnerable code path runs before handler dispatch, meaning no authentication is required to trigger the issue. The fix was introduced in Tornado version 6.5.8, which enforces field limits during body parsing.
Bekijk origineel advisory →A critical incorrect access control vulnerability exists in the setPasswordCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to change the administrator account credentials by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication is required to exploit this vulnerability, making it particularly dangerous for exposed devices. Successful exploitation could grant an attacker full administrative control over the affected router. The vulnerability has been assigned CVE-2026-51679 and is rated high severity. Proof-of-concept and vendor coordination details have been published on GitHub. TOTOLINK is a network equipment vendor whose devices are widely deployed in home and small business environments.
Bekijk origineel advisory →