Overzicht van binnengekomen advisories.
1553 resultaten gevonden
A heap-based buffer overflow vulnerability has been identified in Open5GS version 2.8.0, specifically in the function hss_ogs_diam_s6a_air_cb located in src/hss/hss-s6a-path.c. The vulnerability is triggered by manipulating the Visited-PLMN-Id argument within the S6a Authentication-Information-Request Handler component. Remote exploitation is possible, making this a significant security risk for 5G core network deployments using Open5GS. A patch has been identified with commit hash a9c82ee0b590d76a581b0580cb46b598984e2392 on the Open5GS GitHub repository. Administrators are advised to apply the patch immediately to remediate the issue. The vulnerability has been tracked under CVE-2026-78156 and documented on both NVD and VulDB. No workaround is mentioned; patching is the recommended remediation path.
Bekijk origineel advisory →A critical unauthenticated Local File Inclusion (LFI) vulnerability has been identified in WP Cafe Pro, a WordPress plugin, affecting versions prior to 3.0.15. The vulnerability allows unauthenticated attackers to include local files on the server, potentially exposing sensitive data or enabling remote code execution. No authentication is required to exploit this flaw, making it particularly dangerous. The issue has been assigned CVE-2026-66587 and is tracked by both NVD and Patchstack. Users are strongly advised to update to version 3.0.15 or later to remediate the vulnerability. The vulnerability was catalogued by Patchstack as part of their WordPress security monitoring program. LFI vulnerabilities can be leveraged to read sensitive configuration files, credentials, or execute malicious payloads. The unauthenticated nature of this vulnerability significantly raises its risk profile.
Bekijk origineel advisory →A prototype pollution vulnerability has been identified in ractivejs/ractive up to version 1.4.4. The flaw exists in the Ractive#set function within the Keypath Handler component, allowing improperly controlled modification of object prototype attributes. The vulnerability can be exploited remotely, and a public exploit is already available, increasing the risk of active attacks. The project maintainers were notified via an issue report but have not yet responded or released a patch. The unpatched status combined with public exploit availability makes this a high-severity concern. Prototype pollution vulnerabilities can lead to application logic bypass, denial of service, or remote code execution depending on the context. Users of ractivejs ractive up to version 1.4.4 are advised to monitor for patches and apply mitigations as available.
Bekijk origineel advisory →CVE-2026-32563 describes a PHP Object Injection vulnerability in the ACPT (Pro) - Custom Post Types Plugin for WordPress, affecting versions up to and including 2.0.63. The vulnerability can be exploited by subscriber-level authenticated users, allowing them to inject PHP objects. PHP Object Injection vulnerabilities can lead to a variety of attacks depending on available POP chains in the environment, including remote code execution, file manipulation, or privilege escalation. The issue was reported via the Patchstack vulnerability database and catalogued on the NVD. WordPress site administrators running the affected plugin version should update to a patched version immediately. The vulnerability is rated as high severity.
Bekijk origineel advisory →A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The vulnerability exists in the file /fos/view_prod.php, where manipulation of the 'ID' argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring local access. A public exploit is already available, increasing the risk of active exploitation. The affected function within the file is currently unspecified. The vulnerability has been catalogued under CVE-2026-78199 and is tracked on NVD, VulDB, and GitHub. Organizations using this software should apply patches or mitigations immediately given the public exploit availability.
Bekijk origineel advisory →A SQL injection vulnerability has been identified in itsourcecode Payroll System version 1.0. The vulnerability exists in the Login function within the admin_class.php file, where manipulation of the Username argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit has already been disclosed, increasing the risk of active exploitation. The affected product is a payroll management system, making it a target for potential data theft or unauthorized access. The vulnerability is tracked under CVE-2026-78201 and has been reported via GitHub and VulDB. Organizations using this software are advised to apply patches or mitigations immediately. The public disclosure of the exploit raises the criticality of this issue significantly.
Bekijk origineel advisory →A security flaw has been identified in alibaba-fusion next up to version 1.27.34. The vulnerability exists in the ConfigProvider.getContextProps function within components/dialog/index.tsx, specifically in the deepMerge component. An attacker can manipulate the locale argument to cause improperly controlled modification of object prototype attributes, a class of vulnerability known as prototype pollution. The attack can be initiated remotely without requiring local access. The issue was reported on GitHub but was automatically closed due to inactivity, suggesting it may remain unpatched. This type of vulnerability can potentially allow attackers to alter application behavior, bypass security controls, or cause denial of service.
Bekijk origineel advisory →rConfig versions 8.0.0 through 8.2.12 contain a critical authentication bypass vulnerability tracked as CVE-2026-77915. The flaw stems from a duplicate bare Auth::routes() call in routes/web.php that inadvertently re-enables the POST /register route after it was explicitly disabled. Unauthenticated attackers can exploit this to self-register accounts that are immediately granted full Administrator privileges. This occurs because the registration controller does not assign a role, and the users.role database column defaults to Admin. Successful exploitation grants attackers access to stored device credentials, user data, and the ability to issue API tokens. The vulnerability is patched in rConfig version 8.2.13. rConfig is a network device configuration management tool, making this vulnerability particularly severe in network infrastructure environments.
Bekijk origineel advisory →A security flaw has been identified in alibaba-fusion/next up to version 1.27.34, involving a prototype pollution vulnerability. The issue resides in the ConfigProvider.getContextProps function within components/dialog/index.tsx, specifically in the deepMerge component. Manipulation of the locale argument leads to improperly controlled modification of object prototype attributes, a classic prototype pollution attack vector. The vulnerability can be exploited remotely without requiring local access. The flaw was reported via a GitHub issue, but the issue was closed automatically due to inactivity, suggesting no official patch or acknowledgment from maintainers. Prototype pollution vulnerabilities can have serious consequences, including property injection, logic manipulation, and potential remote code execution depending on the application context. The vulnerability affects a widely used React-based UI component library maintained by Alibaba.
Bekijk origineel advisory →A SQL injection vulnerability was identified in SourceCodester Simple Online Food Ordering System version 1.0. The flaw exists in the file /fos/admin/ajax.php?action=save_settings, where manipulation of the 'Name' argument leads to SQL injection. The vulnerability can be exploited remotely without requiring physical access. A public exploit has been disclosed and is available for use by threat actors. The affected product is a PHP-based web application commonly used for learning and small-scale deployments. The vulnerability poses a significant risk as it could allow attackers to manipulate or extract database contents. No patch details are currently mentioned in the article. The issue has been documented across multiple security databases including NVD and VulDB.
Bekijk origineel advisory →A vulnerability has been identified in Open5GS version 2.8.0 affecting the function pcrf_rx_aar_cb within the file src/pcrf/pcrf-rx-path.c, part of the Rx AA-Request Handler component. The flaw allows an attacker to trigger an out-of-bounds read through manipulation of the affected function. The attack can be initiated remotely without requiring physical access to the target system. Open5GS is an open-source implementation of 5G and LTE core network components, making this vulnerability relevant to telecommunications infrastructure. A patch has been identified with commit hash c18dc6938bf63cc7374315d3dca303d92066e746 on the official GitHub repository. Users are strongly recommended to apply the patch immediately to mitigate potential exploitation. The vulnerability is tracked under CVE-2026-78157 and is also referenced in VulDB under entry 394540.
Bekijk origineel advisory →Mistune, a Python Markdown parser, contains a denial-of-service vulnerability in versions 3.3.0 through 3.3.2. The vulnerability arises from deeply nested emphasis tokens generated by consecutive asterisk characters in crafted Markdown input. The HTMLRenderer.render_token() method processes these tokens recursively, which can exceed Python's default recursion limit and raise a RecursionError. This allows an attacker to crash any process that parses untrusted Markdown using affected versions of Mistune. The issue is classified as a DoS vulnerability with no data exfiltration or code execution implications. A fix has been released in version 3.3.3, which addresses the recursive rendering behavior. Users are advised to upgrade immediately to mitigate the risk.
Bekijk origineel advisory →CVE-2026-19200 describes a privilege escalation vulnerability in Velociraptor's VQL verify() function. The function is intended to allow users to check artifacts for syntactic and other issues, but due to an implementation flaw, it uses the global artifact repository instead of a scoped one. This allows any user with the NOTEBOOK_EDIT permission (such as an analyst role) to overwrite existing artifacts without the required elevated permissions. The vulnerability bypasses access controls meant to restrict artifact modification. An attacker exploiting this flaw could alter artifacts in the global repository, potentially affecting forensic investigations or security monitoring workflows. A fix has been proposed via a GitHub pull request to the Velociraptor project. The issue is documented in Velociraptor's official security advisories. Organizations using Velociraptor should review analyst-level permissions and apply available patches promptly.
Bekijk origineel advisory →A critical unauthenticated PHP Object Injection vulnerability has been identified in The Events Calendar WordPress plugin affecting versions up to and including 6.17.2. The vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to remote code execution or other serious security impacts. No authentication is required to exploit this vulnerability, significantly raising its risk level. The flaw has been assigned CVE-2026-78265 and is documented in both the NVD and Patchstack databases. WordPress site owners using The Events Calendar plugin should update immediately to a patched version. The vulnerability was discovered and reported through the Patchstack vulnerability disclosure program. This type of PHP Object Injection flaw can be leveraged by attackers to exploit POP (Property Oriented Programming) chains present in the application or its dependencies. The unauthenticated nature of the exploit makes it especially dangerous for any publicly accessible WordPress installation running the affected plugin versions.
Bekijk origineel advisory →A buffer overflow vulnerability has been identified in UTT HiPER 1200GW devices running firmware version up to 2.5.3-170306. The flaw exists in the strcpy function within the file /goform/formConfigFastDirectionW, where manipulation of the 'ssid' argument can trigger a buffer overflow condition. The vulnerability is remotely exploitable, meaning an attacker does not require local access to the device. A public exploit has already been released and is available for use, increasing the risk of active exploitation. The affected product is a network gateway device, making this vulnerability particularly impactful for network infrastructure security. No authentication bypass details are specified, but the remote attack vector significantly raises the threat level. Organizations using UTT HiPER 1200GW devices should apply patches or mitigations immediately.
Bekijk origineel advisory →Hi.Events, an open-source event management platform, contains a Server-Side Request Forgery (SSRF) vulnerability tracked as CVE-2026-76838. The flaw arises because webhook destination URLs are validated only at registration time using NoInternalUrlRule, which resolves hostnames with gethostbyname() and blocks private/reserved IP ranges. However, no revalidation occurs at dispatch time, and the Guzzle HTTP client follows redirects by default. An attacker can register a legitimate public URL that later redirects to internal addresses (loopback, private, or cloud metadata endpoints), or change the DNS record after registration (DNS rebinding). The full response body from internal services is stored in webhook logs and returned via the webhook logs API endpoint, enabling full response exfiltration rather than mere blind SSRF. Both event and organizer webhook types are affected. Version 1.11.1-beta patches the issue by revalidating at dispatch, pinning resolved addresses, checking each redirect hop, and decoding IPv6 transition addresses that previously bypassed the filter.
Bekijk origineel advisory →A prototype pollution vulnerability has been identified in ractivejs/ractive up to version 1.4.4. The flaw resides in the Ractive#set function within the Keypath Handler component, allowing improperly controlled modification of object prototype attributes. The vulnerability can be exploited remotely, and a public exploit is already available, increasing the risk of active attacks. The project maintainers were notified via an issue report but have not yet responded or released a patch. This type of vulnerability can lead to serious consequences including denial of service, property injection, or remote code execution depending on the application context.
Bekijk origineel advisory →A critical unauthenticated privilege escalation vulnerability has been identified in the Jawn WordPress theme affecting versions 1.4.2 and below. The vulnerability allows unauthenticated attackers to escalate their privileges without any prior authentication, posing a significant security risk to WordPress sites using this theme. The flaw is tracked as CVE-2026-66648 and has been documented by both NVD and Patchstack. Sites running Jawn theme version 1.4.2 or earlier are advised to update immediately. No exploitation details have been publicly disclosed in the available content, but the unauthenticated nature of the attack vector makes it particularly dangerous. WordPress administrators should patch or disable the theme until a secure version is available.
Bekijk origineel advisory →A critical out-of-bounds write vulnerability has been identified in warmcat libwebsockets version 4.5.0. The flaw resides in the function report_raw_cbor within lib/misc/lecp.c, part of the LECP CBOR Recording component. The vulnerability can be exploited remotely, allowing attackers to perform out-of-bounds memory writes. A public proof-of-concept exploit has been released, increasing the risk of active exploitation. The patch commit 1d44554a1bb262db63ff4e240152a9deecd99054 has been made available to address the issue. Users are strongly advised to apply the patch immediately to mitigate potential risks.
Bekijk origineel advisory →A SQL injection vulnerability has been identified in itsourcecode Online Clinic Management System version 1.0. The vulnerability exists in the file success/login.php within the Admin Login component. An attacker can manipulate the Username argument to perform SQL injection attacks remotely. The exploit has been publicly disclosed and is available for use, making it an active threat. No authentication is required to exploit this vulnerability, increasing its severity. The issue affects an unspecified section of the login handling code. Successful exploitation could allow unauthorized access to the underlying database. Organizations using this system are advised to apply patches or mitigations promptly.
Bekijk origineel advisory →