Overzicht van binnengekomen advisories.
1553 resultaten gevonden
A server-side request forgery (SSRF) vulnerability has been identified in NASA earthdata-search version 1.0.0. The vulnerability exists in the scaleImage function within the file serverless/src/scaleImage/handler.js at the scale Endpoint component. An attacker can exploit this vulnerability remotely by manipulating inputs to the affected function, potentially causing the server to make unintended requests to internal or external resources. A public exploit is available, increasing the risk of active exploitation. The vulnerability was responsibly disclosed to the vendor, but no response was received. The issue carries a high criticality rating given the public exploit availability and the potential for abuse in a government-affiliated application handling geospatial and earth science data.
Bekijk origineel advisory →A server-side request forgery (SSRF) vulnerability was identified in hyperledger-firefly FireFly up to version 1.4.0. The vulnerability resides in the ValidateOptions function within the file internal/events/webhooks/webhooks.go, part of the Webhook Subscription component. An attacker can manipulate the 'url' argument to trigger SSRF attacks remotely. The exploit has been publicly disclosed and is available for use. The vulnerability allows remote exploitation without requiring local access. The vendor was notified prior to public disclosure but did not respond. No patch or mitigation from the vendor has been confirmed at the time of disclosure. This affects blockchain infrastructure tooling used in enterprise and decentralized application environments.
Bekijk origineel advisory →ToolJet versions before v3.16.208 contain a critical authorization flaw in database read routes that fails to validate organization membership. Any authenticated user can exploit this by supplying arbitrary organization IDs in URL parameters to access other organizations' data. The vulnerability allows attackers to list tables, retrieve column definitions, and execute join queries to read actual stored data from victim organizations. This represents a significant multi-tenant isolation failure in the ToolJet platform. The issue has been patched in v3.16.208 and is documented in both the GitHub Security Advisory GHSA-xqqj-pfc2-vf48 and VulnCheck advisories.
Bekijk origineel advisory →A local privilege escalation vulnerability has been identified in ieungSoft Ultra RAMDisk Pro version 1.82. The flaw resides in the kernel driver component URDSCSI.sys and involves improper privilege management. The vulnerability allows a local attacker to escalate privileges through arbitrary registry value writes. A public exploit has been disclosed, increasing the risk of active exploitation. The vendor was notified prior to public disclosure but did not respond. No patch or mitigation has been confirmed from the vendor. The vulnerability is tracked as CVE-2026-82807 and has been documented across multiple security databases.
Bekijk origineel advisory →A SQL injection vulnerability has been identified in code-projects Online Shopping System version 1.0. The flaw exists in the /action.php file within the Search Functionality component, where manipulation of the 'keyword' argument enables time-based blind SQL injection attacks. The vulnerability can be exploited remotely without authentication, making it accessible to a wide range of threat actors. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability has been assigned CVE-2026-82701 and is tracked by NVD and VulDB. This type of injection vulnerability can allow attackers to extract, modify, or delete database contents. The affected software is a widely used open-source e-commerce project, potentially impacting numerous deployments.
Bekijk origineel advisory →CVE-2026-82858 affects @hulumi/drift versions before 1.3.2, which accept externally supplied execute plans without sufficient provenance validation. This flaw allows untrusted reconciliation input to be treated as trusted, enabling attackers to supply malicious execute plans that bypass security checks. The vulnerability permits unsafe reconciliation operations to be performed without proper authorization or verification. The fix is available in version 1.3.2 and later. This is a supply chain/dependency risk for any project relying on the @hulumi/drift package. The issue is documented in the NVD, a GitHub security advisory, and a VulnCheck advisory. No active exploitation details are currently mentioned, but the nature of the flaw presents significant risk if exploited in automated infrastructure or CI/CD pipelines.
Bekijk origineel advisory →A critical OS command injection vulnerability has been discovered in multiple D-Link NAS devices including DNS-320L, DNS-327L, DNS-340L, and DNS-345 up to firmware version 20260717. The vulnerability exists in the CGI Handler component, specifically in the /cgi-bin/usb_device.cgi file. Attackers can exploit the f_ups_ip argument to inject and execute arbitrary OS commands remotely. The attack can be performed remotely without physical access to the device. A public exploit has been disclosed, making active exploitation a significant risk. The vulnerability affects a wide range of D-Link NAS products commonly used in home and small business environments. Given the public availability of the exploit, unpatched devices are at immediate risk of compromise. Users are advised to apply patches or mitigations as soon as they become available from D-Link.
Bekijk origineel advisory →Devtron versions through 2.2.0 contain a missing authorization vulnerability on the GET /orchestrator/api-token/webhook endpoint. Any authenticated user, regardless of privilege level, can query this endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens. These tokens grant full platform control over the Devtron CI/CD orchestration platform. The vulnerability stems from a failure to enforce proper authorization checks in the API token webhook handler. Successful exploitation allows privilege escalation from any authenticated account to full administrative access. The issue is documented in GitHub issue #7013 and affects the ApiTokenRestHandler and ApiTokenService components. No special permissions or exploitation techniques are required beyond basic authentication.
Bekijk origineel advisory →Pangolin versions before 1.22.0 contain a critical authentication bypass vulnerability tracked as CVE-2026-72001. The flaw resides in the share-link authentication endpoint, where an attacker-controlled URL parameter can omit the expected resource identifier from the token verification call. An attacker possessing a single valid share link for any resource can leverage this to authenticate against arbitrary resources across different organizations. The vulnerability effectively bypasses all configured authentication mechanisms, including SSO, resource passwords, PIN codes, email allowlists, and header authentication. The attack requires no prior authentication, making it accessible to unauthenticated threat actors. The issue has been patched in Pangolin version 1.22.0. Organizations using affected versions should upgrade immediately to mitigate unauthorized access risks.
Bekijk origineel advisory →A critical OS command injection vulnerability has been identified in D-Link DNS-340L and DNS-345 network-attached storage devices across multiple firmware versions (1.01B04, 1.03B06, 1.04.B02, 1.05b04). The vulnerability exists in the /cgi-bin/virtual_vol.cgi file within the Virtual Volume Handler component. Attackers can exploit this by manipulating the f_sharename, f_target, or f_name arguments to inject arbitrary OS commands. The vulnerability is remotely exploitable without requiring physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation in the wild. This affects a widely deployed line of consumer and small business NAS devices manufactured by D-Link. The public disclosure and remote exploitability make this a high-severity issue requiring immediate attention and patching.
Bekijk origineel advisory →Hulumi versions before v1.3.2 contain a vulnerability in their deployment SCP (Service Control Policy) template that allows attackers to bypass tag-on-create protections for hulumi:iac-role. The flaw enables malicious actors to circumvent intended IAM boundary restrictions through exploitation of the weakened SCP template in downstream deployments. This represents a significant privilege escalation risk in cloud infrastructure-as-code environments. The vulnerability affects all hulumi deployments using versions prior to v1.3.2. Organizations using hulumi for IaC deployments should upgrade to v1.3.2 or later immediately. The issue was disclosed via GitHub Security Advisories and VulnCheck, indicating coordinated disclosure. Exploitation could allow unauthorized access to cloud resources protected by IAM boundary controls.
Bekijk origineel advisory →A critical OS command injection vulnerability (CVE-2026-82668) has been identified in klaussilveira GitList version 2.0.0. The vulnerability resides in the getDefaultBranch function within the file src/SCM/System/Git/CommandLine.php of the Git Command Line component. Attackers can exploit this flaw remotely without requiring physical access. A public exploit has been disclosed and may already be in use. The vulnerability allows arbitrary OS command execution through manipulation of the affected function. A patch (commit 88cf2866083d5f7c20d9d565c45f828a7ad1516b) has been released as part of GitList version 3.0.0-beta. Users are strongly advised to upgrade to the patched version immediately to mitigate the risk.
Bekijk origineel advisory →A critical vulnerability identified as CVE-2026-81779 affects the Newspapers X WordPress theme developed by Silk Themes, impacting versions 1.0.46 through 1.0.48. The vulnerability is classified as 'Improper Validation of Specified Quantity in Input,' which allows attackers to implant malicious software (backdoor). This type of vulnerability can enable threat actors to insert unauthorized code into affected WordPress installations, potentially compromising the entire site. The issue was reported via NVD (National Vulnerability Database) and documented by Patchstack. Users running the affected versions of the Newspapers X theme are advised to update immediately to a patched version. The backdoor implantation capability makes this a high-severity issue, as it can lead to full site compromise, data theft, and persistent unauthorized access.
Bekijk origineel advisory →A vulnerability was identified in the Inbox Foundry ActiveInbox Chrome Extension up to version 7.10.24. The vulnerability involves hard-coded Google OAuth client secret credentials embedded within the file dist/service-worker.production-esm.js. This exposure allows remote attackers to potentially abuse the OAuth credentials. A public exploit is available and may already be in use. The vendor was notified prior to disclosure but has not yet remediated the issue. The vendor's bug bounty program is currently on hold due to a backlog of existing reports, suggesting a delayed response to the vulnerability. Users of the affected extension versions are at risk of credential compromise and unauthorized access to Google OAuth-protected resources.
Bekijk origineel advisory →CVE-2026-82861 affects @hulumi/policies versions before 1.3.2, exposing a parent spoof bypass vulnerability. Attackers can submit spoofed SecureBucket parent evidence during policy evaluation, causing the validator to incorrectly assess bucket configurations. By providing falsified evidence, attackers can bypass security policy checks entirely. This results in unsafe bucket configurations going undetected by the policy enforcement system. The vulnerability is fixed in version 1.3.2 of the @hulumi/policies package. The issue is documented in both the NVD and VulnCheck advisories, as well as a GitHub security advisory.
Bekijk origineel advisory →A SQL injection vulnerability (CVE-2026-82612) has been identified in itsourcecode Online Medicine Delivery System version 1.0. The vulnerability exists in the loadResultList function within the /index.php?q=single-item file on the Product Detail Page. An attacker can manipulate the 'ID' argument to perform SQL injection attacks. The attack can be launched remotely without requiring physical access. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability affects the product's database interaction layer, potentially exposing sensitive medical and user data. No patch information is currently mentioned in the advisory.
Bekijk origineel advisory →MCPHub, a unified hub for managing and orchestrating MCP servers and APIs, contains a critical missing authorization vulnerability prior to version 1.0.32. The built-in prompt and resource controllers perform no role checking on mutating POST/PUT routes under /api/prompts* and /api/resources*. These routes are attached to an authenticated router but lack an admin gate, and handlers never read req.user to verify permissions. DAO singletons written by these endpoints are consulted first for every session, ahead of any connected MCP server. This allows any authenticated non-admin user to create, overwrite, or shadow global prompt templates and resources served to all users. The primary impact is unauthorized integrity violation of globally-served records, with stored prompt injection into other users' LLM sessions as a downstream consequence. The vulnerability has been patched in MCPHub version 1.0.32.
Bekijk origineel advisory →CVE-2026-76133 affects an Ebyte product that uses a deprecated hashing algorithm in an authentication-related operation. The vulnerability stems from weak cryptographic construction that reduces the assurance provided by the authentication mechanism. Under conditions where an attacker can manipulate or predict the authentication exchange, unauthorized access may be facilitated. The advisory is referenced by CISA as an ICS advisory (icsa-26-237-06), indicating this is an operational technology (OT) or industrial control system (ICS) product. The use of deprecated hashing algorithms in authentication contexts is a well-known weakness that can be exploited through techniques such as hash collision or pre-image attacks. This vulnerability poses a risk to systems relying on the affected Ebyte product for secure authentication. Remediation would typically involve updating to a modern, secure hashing algorithm.
Bekijk origineel advisory →A critical OS command injection vulnerability (CVE-2026-82692) was discovered in D-Link DNS-340L and DNS-345 NAS devices up to firmware version 20260717. The vulnerability exists in the /cgi-bin/iscsi_mgr.cgi file, where manipulation of the alias, username, password, or volume_location arguments can lead to OS command injection. The attack can be initiated remotely without physical access to the device. A public exploit has been released, increasing the risk of active exploitation. The vulnerability affects network-attached storage devices commonly used in home and small business environments. No patch information is currently indicated in the advisory. The public disclosure of the exploit makes this a high-priority issue for D-Link DNS-340L and DNS-345 users.
Bekijk origineel advisory →A vulnerability has been identified in ShopEx ECShop versions up to 2.5.1 involving an unrestricted file upload flaw. The vulnerability exists in the check_img_type function within the admin/pack.php file. Attackers can manipulate the pack_img argument to bypass file type restrictions and upload arbitrary files. The attack can be launched remotely without requiring physical access. A public exploit has already been released, increasing the risk of active exploitation. The vendor was notified prior to public disclosure but did not respond. This lack of vendor response leaves users without an official patch or mitigation guidance. The vulnerability poses significant risk to e-commerce platforms running affected ECShop versions.
Bekijk origineel advisory →