#cve — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cve, aggregated by home.social.
-
🟠 CVE-2026-78268 - High (7.5)
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78268/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
CVE Alert: CVE-2026-71913 - DrayTek Corporation - VigorAP 918R - https://www.redpacketsecurity.com/cve-alert-cve-2026-71913-draytek-corporation-vigorap-918r/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-71913 #draytek-corporation #vigorap-918r
-
CVE Alert: CVE-2026-71908 - DrayTek Corporation - VigorAP 918R - https://www.redpacketsecurity.com/cve-alert-cve-2026-71908-draytek-corporation-vigorap-918r/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-71908 #draytek-corporation #vigorap-918r
-
CVE Alert: CVE-2026-76847 - nektos - act - https://www.redpacketsecurity.com/cve-alert-cve-2026-76847-nektos-act/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-76847 #nektos #act
-
CVE Alert: CVE-2026-71906 - DrayTek Corporation - VigorAP 918R - https://www.redpacketsecurity.com/cve-alert-cve-2026-71906-draytek-corporation-vigorap-918r/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-71906 #draytek-corporation #vigorap-918r
-
CVE Alert: CVE-2026-76844 - webpack - webpack-dev-middleware - https://www.redpacketsecurity.com/cve-alert-cve-2026-76844-webpack-webpack-dev-middleware/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-76844 #webpack #webpack-dev-middleware
-
CVE Alert: CVE-2026-71911 - DrayTek Corporation - VigorAP 918R - https://www.redpacketsecurity.com/cve-alert-cve-2026-71911-draytek-corporation-vigorap-918r/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-71911 #draytek-corporation #vigorap-918r
-
CVE Alert: CVE-2026-19685 - Red Hat - Red Hat Enterprise Linux 10 - https://www.redpacketsecurity.com/cve-alert-cve-2026-19685-red-hat-red-hat-enterprise-linux-10/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-19685 #red-hat #red-hat-enterprise-linux-10
-
CVE Alert: CVE-2026-78247 - SourceCodester - Simple Online Food Ordering System - https://www.redpacketsecurity.com/cve-alert-cve-2026-78247-sourcecodester-simple-online-food-ordering-system/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-78247 #sourcecodester #simple-online-food-ordering-system
-
CVE Alert: CVE-2026-78244 - itsourcecode - Real Estate Management System - https://www.redpacketsecurity.com/cve-alert-cve-2026-78244-itsourcecode-real-estate-management-system/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-78244 #itsourcecode #real-estate-management-system
-
CVE Alert: CVE-2026-78246 - itsourcecode - Online Clinic Management System - https://www.redpacketsecurity.com/cve-alert-cve-2026-78246-itsourcecode-online-clinic-management-system/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-78246 #itsourcecode #online-clinic-management-system
-
CVE Alert: CVE-2026-76841 - xorbitsai - inference - https://www.redpacketsecurity.com/cve-alert-cve-2026-76841-xorbitsai-inference/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-76841 #xorbitsai #inference
-
CVE Alert: CVE-2026-78201 - itsourcecode - Payroll System - https://www.redpacketsecurity.com/cve-alert-cve-2026-78201-itsourcecode-payroll-system/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-78201 #itsourcecode #payroll-system
-
CVE Alert: CVE-2026-78198 - SourceCodester - Simple Online Food Ordering System - https://www.redpacketsecurity.com/cve-alert-cve-2026-78198-sourcecodester-simple-online-food-ordering-system/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-78198 #sourcecodester #simple-online-food-ordering-system
-
🔴 CVE-2026-78267 - Critical (9.8)
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78267/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-78265 - Critical (9.8)
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78265/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-78284 - High (8.6)
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78284/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-61419 - High (7.8)
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61419/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-76098 - High (7.5)
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-19568 - High (7.8)
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19568/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-16783 - High (7.8)
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-77567 - High (8.1)
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77567/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-7455 - High (7.8)
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the conte...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7455/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
The vulnerability ecosystem continues its exponential growth experiment.
More CVEs, more advisories, more sightings, more feeds.
The real challenge is no longer "finding vulnerabilities". It is making sense of the noise before attackers do.
https://vulnerability.circl.lu
#vulnerability #CVE #GCVE #CNA #GNA #VulnerabilityLookup #CyberSecurity
-
I spent many hours in vulnogram today and to be honest. I'm glad that a colleague started to work on a replacement called
vulniverse. Still early beta but it's promising.#opensource #vulniverse #cybersecurity #cve #gcve
:github: work in progress https://github.com/vulnerability-lookup/vulniverse
-
CVE Alert: CVE-2026-21962 - Oracle Corporation - Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in - https://www.redpacketsecurity.com/cve-alert-cve-2026-21962-oracle-corporation-oracle-http-server-oracle-weblogic-server-proxy-plug-in/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-21962 #oracle-corporation #oracle-http-server-oracle-weblogic-server-proxy-plug-in
-
🔴 CVE-2026-76835 - Critical (9.1)
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/ut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76835/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-76073 - High (8.8)
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76073/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-76838 - High (8.5)
Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76838/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack