#tenda β Public Fediverse posts
Live and recent posts from across the Fediverse tagged #tenda, aggregated by home.social.
-
π CVE-2026-105293 - High (8.1)
Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as thro...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105293/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105293 - High (8.1)
Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as thro...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105293/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105293 - High (8.1)
Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as thro...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105293/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105295 - High (7.5)
GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid ...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105295 - High (7.5)
GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid ...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105295 - High (7.5)
GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid ...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105220 - High (7.8)
Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScra...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105220 - High (7.8)
Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScra...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105220 - High (7.8)
Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScra...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105219 - High (7.5)
Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an untermina...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105219/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105219 - High (7.5)
Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an untermina...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105219/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105219 - High (7.5)
Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an untermina...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105219/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105089 - High (8.7)
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and chann...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105089/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105089 - High (8.7)
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and chann...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105089/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105089 - High (8.7)
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and chann...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105089/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105086 - High (8.7)
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entitie...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105086/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105086 - High (8.7)
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entitie...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105086/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105086 - High (8.7)
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entitie...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105086/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105135 - Critical (10)
A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection....
π https://www.thehackerwire.com/vulnerability/CVE-2026-105135/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105135 - Critical (10)
A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection....
π https://www.thehackerwire.com/vulnerability/CVE-2026-105135/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105135 - Critical (10)
A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection....
π https://www.thehackerwire.com/vulnerability/CVE-2026-105135/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105134 - Critical (10)
A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os comman...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105134/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105134 - Critical (10)
A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os comman...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105134/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105134 - Critical (10)
A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os comman...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105134/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-103355 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection...
π https://www.thehackerwire.com/vulnerability/CVE-2026-103355/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-103355 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection...
π https://www.thehackerwire.com/vulnerability/CVE-2026-103355/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-103355 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection...
π https://www.thehackerwire.com/vulnerability/CVE-2026-103355/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-97307 - High (7.5)
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
π https://www.thehackerwire.com/vulnerability/CVE-2026-97307/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-97307 - High (7.5)
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
π https://www.thehackerwire.com/vulnerability/CVE-2026-97307/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-97307 - High (7.5)
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
π https://www.thehackerwire.com/vulnerability/CVE-2026-97307/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105208 - High (7.7)
ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An atta...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105208/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105208 - High (7.7)
ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An atta...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105208/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105208 - High (7.7)
ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An atta...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105208/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105207 - Critical (9.8)
ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User S...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105207/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105207 - Critical (9.8)
ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User S...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105207/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105207 - Critical (9.8)
ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User S...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105207/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105215 - Critical (9.1)
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105215 - Critical (9.1)
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π΄ CVE-2026-105215 - Critical (9.1)
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105213 - High (8.2)
ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refres...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105213/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105213 - High (8.2)
ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refres...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105213/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105213 - High (8.2)
ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refres...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105213/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105212 - High (7.5)
ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105212/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105212 - High (7.5)
ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105212/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105212 - High (7.5)
ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105212/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105211 - High (8.1)
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with ...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105211/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105211 - High (8.1)
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with ...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105211/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105211 - High (8.1)
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with ...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105211/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105210 - High (8.2)
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Att...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105210/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
π CVE-2026-105210 - High (8.2)
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Att...
π https://www.thehackerwire.com/vulnerability/CVE-2026-105210/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack