National CERT advisories
A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server. Performing a manipulation o…
Citrix heeft kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De kwetsbaarheid met kenmerk CVE-2026-19489 betreft een memory overflow in NetScaler ADC en NetScaler Gateway, wanneer de producten zijn geconf…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local acces…
The league/commonmark (thephpleague/commonmark) library in versions = 1.5.0 and
LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can…
Poljski CERT (CERT Polska) identificirao je i koordinirao objavu šest ranjivosti u sustavu MikroTik RouterOS. Kombinacijom dviju od njih (CVE-2026-67276 i CVE-2026-86060), nazvanom “MikroTrick”, napadač može …
Er is een ernstige kwetsbaarheid, CVE-2026-86218, gevonden in N-central van N-able met een CVSS-score van 10. Deze kwetsbaarheid maakt het voor onbevoegden mogelijk om op afstand, zonder inloggegevens, schadelijke code u…
Control de acceso incorrecto en PrestaShop Lun, 07/09/2026 - 12:52 Aviso Recursos Afectados PrestaShop, versiones anteriores a la 9.1.5 y a la 8.2.8, según la rama. Descripción INCIBE ha coordinado la publicación de una …
A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object,…
Múltiples vulnerabilidades en productos de Cisco Lun, 07/09/2026 - 10:37 Aviso Recursos Afectados Cisco IOS XR Software:Todas las versiones de Cisco IOS XR Software, incluido Cisco IOS XR7 (LNT), independientemente de la…
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it poss…
An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafte…
Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.
Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted W…
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument …
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can l…
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to s…
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results…
A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes s…
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course res…
When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy …
MikroTik ha rilasciato aggiornamenti di sicurezza al fine di correggere 6 nuove vulnerabilità, di cui 2 con gravità “critica” e 2 con gravità “alta”. Tra queste, si evidenzia lo sfruttamento attivo in rete delle vulnerab…
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects a…
PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_d…
A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_na…
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_…
Zespół CERT Polska znalazł 6 podatności (od CVE-2026-67276 do CVE-2026-67279, CVE-2026-67281 oraz CVE-2026-86060) w oprogramowaniu Mikrotik RouterOS.
CERT Polska has found 6 vulnerabilities (from CVE-2026-67276 to CVE-2026-67279, CVE-2026-67281 and CVE-2026-86060) in Mikrotik RouterOS software.
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelp…
Classification: Severe, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None, CVEs: CVE-2026-85046, CVE-2026-85052, CVE-2026-85043, CVE-2026-85048, CVE-2026-85045, CVE-2026-85050, CVE-2026-85053, CVE-2026-85042…
YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. B…
YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify…
End-of-Day report Timeframe: Donnerstag 03-09-2026 18:00 - Freitag 04-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Alexander Riepl News Critical Citrix NetScaler auth bypass now leveraged in attacks Tracked …
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.
IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended…
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to …
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database…
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/…
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissi…
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace valida…
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.
IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config f…
IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.
IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local fi…
Google Chrome pārlūkprogrammā ir atklāta ievainojamība CVE-2026-85046, kas jau pirms drošības "ielāpa" publicēšanas tika aktīvi izmantota uzbrukumos. Ievainojamība var ļaut izpildīt uzbrucēja kontrolētu kodu Chrome pārlū…
Er zijn meerdere kwetsbaarheden gevonden in Google Chrome, specifiek in versie 152.0.7977.82. Deze kwetsbaarheden, waaronder CVE-2026-85042 en CVE-2026-85047, betreffen verschillende onderdelen van de browser. Het advies…
Google heeft meerdere kwetsbaarheden verholpen in Google Chrome, specifiek in versies voor 152.0.7977.82. De kwetsbaarheden bevinden zich in verschillende componenten van Google Chrome, waaronder DevTools, Network, V8 Ja…
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 12 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 7 con gravità “alta”. Tra queste, si evidenzia lo sfruttamento attiv…
Múltiples vulnerabilidades en productos de ABB Vie, 04/09/2026 - 11:42 Aviso SCI Recursos Afectados Las siguientes herramientas y servicios de ABB están afectados por estas vulnerabilidades:Automation Builder versiones a…
Permisos incorrectos en Ignition de Inductive Automation Vie, 04/09/2026 - 10:48 Aviso SCI Recursos Afectados Inductive Automation Ignition: versión 8.1.53 y anteriores. Descripción Inductive Automation ha publicado 1 vu…
Neutralización incorrecta de secuencias en VPN Client de IXON Vie, 04/09/2026 - 10:16 Aviso SCI Recursos Afectados Cliente VPN IXON: versiones anteriores a la 1.4.7. Descripción Luuk van Rheden y Stan van Duijnhoven, de …
Verificación incorrecta de firma criptográfica en Mendix SAML de Siemens Vie, 04/09/2026 - 10:05 Aviso SCI Recursos Afectados Mendix SAML (Mendix 9.24 compatible): versiones anteriores a la V3.6.27;Mendix SAML (Mendix 10…
Múltiples vulnerabilidades en productos de VMware Vie, 04/09/2026 - 09:55 Aviso Recursos Afectados VMware Workstation, versiones 25H2 y 26H1;VMware Fusion, versiones 25H2 y 26H1. Descripción h4urek, de secsys lab, Y² &nb…
Desbordamiento de búfer en NetStaX EtherNet/IP Stack de Pyramid Solutions Vie, 04/09/2026 - 09:53 Aviso SCI Recursos Afectados Los siguientes productos con versión anterior a la 5.6.1:EtherNet/IP Adapter DLL Kit (EIPA);E…
Classification: Critical, Solution: Temporary Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-15630, Summary: Casdoor is an open-source Access Management (IAM) platform used to manage web applications.…
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-73749, CVE-2026-73750, CVE-2026-73751, CVE-2026-73752, CVE-2026-73753, CVE-2026-73782, CVE-2026-73781, CVE-20…
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Google indique que la vulnérabilité CVE-2026-85046 est …
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary co…
An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error…
End-of-Day report Timeframe: Mittwoch 02-09-2026 18:00 - Donnerstag 03-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a News Critical Elementor Pro flaw exploited to take over WordPress sites A recently patc…
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data…
An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminat…
An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the p…
A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal.…
A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interfa…
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a calle…
HPE heeft meerdere kwetsbaarheden verholpen in HPE Networking Fabric Composer. De kwetsbaarheden in HPE Networking Fabric Composer betreffen onder andere authenticatiebypasses, privilege-escalaties, remote code execution…
Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers.
Disponibile un Proof of Concept (PoC) per lo sfruttamento della CVE-2026-84115 – già sanata dal vendor – presente in Cleo Harmony.
Plaintext Storage of a Password vulnerability (CVE-2026-15933) has been found in OptimiDoc Server (On-Premise) software.
W oprogramowaniu OptimiDoc Server (On-Premise) wykryto podatność polegającą na przechowywaniu poświadczeń w jawnej formie (CVE-2026-15933).
Múltiples vulnerabilidades en Ocsreports de OCS Inventory NG Jue, 03/09/2026 - 10:00 Aviso Recursos Afectados Ocsreports 2.12.4. Descripción INCIBE ha coordinado la publicación de 5 vulnerabilidades, 1 de severidad críti…
Múltiples vulnerabilidades en productos de SonicWall Jue, 03/09/2026 - 09:50 Aviso Recursos Afectados Modelos SMA1000 - 6210, 7210, 8200v: versión 12.4.3-03453 (platform-hotfix) y anteriores, y versión 12.5.0-02835 (plat…
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5, CVEs: CVE-2026-20281, Summary: A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Ci…
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-73827, CVE-2026-77838, CVE-2026-78238, CVE-2026-78032, Summary: SOY series provided by Tsuyoshi Saito contain…
Classification: Critical, Solution: Unavailable, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-80047, Summary: A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allo…
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20212, Summary: A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could all…
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20274, CVE-2026-20275, CVE-2026-20276, CVE-2026-20277, CVE-2026-20278, CVE-2026-20279, CVE-2026-20280, Summar…
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-84353, CVE-2026-84352, CVE-2026-84354, CVE-2026-84359, CVE-2026-84357, CVE-2026-84324, CVE-2026-84349, CVE-2…
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.0: 10.0, CVEs: CVE-2026-83548, CVE-2026-83549, Summary: 1) CVE-2026-83548 - Pre-authentication SSRF via unintended forward-proxy A Pre-auth…
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 8.6, CVEs: CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-9633, CVE-2026-9634, CVE-2026-9637, CVE-2026-16675,…
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 5.9, CVEs: CVE-2026-20354, CVE-2026-20355, Summary: Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions…
End-of-Day report Timeframe: Dienstag 01-09-2026 18:00 - Mittwoch 02-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a News Hackers abuse Faronics Deploy admin tool to install ScreenConnect Phishing actors ar…
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins t…
Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permiss…
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable b…
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear…
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via for…
In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an H…
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submittin…
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent'…
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuratio…
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will…
The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, an…
Rilevato lo sfruttamento attivo in rete delle vulnerabilità CVE-2026-83548 e CVE-2026-83549 – già sanate dal vendor – presenti nel prodotto Secure Mobile Access (SMA) 1000 Series, soluzione per l'accesso remoto sicuro al…
2.September 2026 Beschreibung In SonicWalls SMA1000 Series Appliances existieren zwei schwerwiegende Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der …
2.September 2026 Beschreibung In SonicWalls SMA1000 Series Appliances existieren zwei schwerwiegende Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der …
Condición de carrera en el firmware de Sauter Mié, 02/09/2026 - 10:19 Aviso SCI Recursos Afectados Las siguientes versiones de firmware están afectadas por esta vulnerabilidad:EY-RC504F*** (ecos504): EY-modulo 5 versión …
Múltiples vulnerabilidades en productos de Rockwell Automation Mié, 02/09/2026 - 09:38 Aviso SCI Recursos Afectados RSLinx® Clásico, versión 4.50 y anteriores (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625);…
Konstatēta augstas bīstamības Microsoft Exchange Server ievainojamība (CVE-2026-62911). Ievainojamību izraisa autentifikācijas apiešanas nepilnība, kas ļauj atkārtoti izmantot iepriekš pārtvertus autentifikācijas datus (…
Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treate…
A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component com.mapquest.android.ace. The …
A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of…
Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys…
UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Ch…
Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium securit…
Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
De multiples vulnérabilités ont été découvertes dans les produits SonicWall. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une falsification de requêtes côté serveur (SSRF). …
Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext H…
A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whe…
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a …
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interfa…
A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrat…
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administra…
An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable…
A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an admi…
An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met…
Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC sig…
End-of-Day report Timeframe: Montag 31-08-2026 18:00 - Dienstag 01-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Alexander Riepl News Hackers push malicious Virtualizor update in BGP hijacking attack Hackers …
Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code wit…
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privilege…
Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system informati…
Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privilege…
Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
Konstatēta Zimbra Collaboration Suite (ZCS) augstas bīstamības ievainojamības CVE-2026-73570 aktīva izmantošana uzbrukumos. Tā ļauj neautentificētam uzbrucējam attālināti izpildīt patvaļīgu kodu (RCE) ievainojamajā serve…
Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesyst…
Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.
Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.
An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits lar…
Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege …
Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.
NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.
Falta de autorización en OpenNebula de OpenNebula Systems Mar, 01/09/2026 - 09:54 Aviso Recursos Afectados OpenNebula 7.4. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad alta que afect…
Ingested from the RSS/Atom/JSON feeds catalogued on the European CERT map. Advisory titles and links belong to their issuing CERT; this is an index, not a republication.