home.social

#cve — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve, aggregated by home.social.

fetched live
  1. CVE-2026-32556 - Unauthenticated XSS in Boost <= 2.0.4. CVSS 7.1. Currently unpatched. Audit systems and mitigate risk immediately. #CVE #XSS #infosec

    valtersit.com/cve/CVE-2026-325

  2. 🟠 CVE-2026-78268 - High (7.5)

    Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads &lt;= 1.2.0 versions.

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  3. 🟠 CVE-2026-61419 - High (7.8)

    Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  4. 🟠 CVE-2026-76098 - High (7.5)

    Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursi...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  5. 🟠 CVE-2026-19568 - High (7.8)

    A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  6. 🟠 CVE-2026-16783 - High (7.8)

    A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  7. 🟠 CVE-2026-77567 - High (8.1)

    Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery c...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  8. 🟠 CVE-2026-7455 - High (7.8)

    A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  9. The vulnerability ecosystem continues its exponential growth experiment.

    More CVEs, more advisories, more sightings, more feeds.

    The real challenge is no longer "finding vulnerabilities". It is making sense of the noise before attackers do.

    vulnerability.circl.lu

  10. I spent many hours in vulnogram today and to be honest. I'm glad that a colleague started to work on a replacement called vulniverse. Still early beta but it's promising.

    #opensource #vulniverse #cybersecurity #cve #gcve

    :github: work in progress github.com/vulnerability-looku

  11. CVE Alert: CVE-2026-21962 - Oracle Corporation - Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in - redpacketsecurity.com/cve-aler

    #OSINT #ThreatIntel #CyberSecurity #cve-2026-21962 #oracle-corporation #oracle-http-server-oracle-weblogic-server-proxy-plug-in

  12. 🔴 CVE-2026-76835 - Critical (9.1)

    OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  13. 🟠 CVE-2026-76073 - High (8.8)

    Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup ...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  14. 🟠 CVE-2026-76838 - High (8.5)

    Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges...

    🔗 thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack