#tenda — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #tenda, aggregated by home.social.
-
🔴 CVE-2026-62928 - Critical (9.8)
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62928/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85094 - High (8.8)
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85094/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85085 - Critical (9.6)
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85085/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85506 - Critical (9.8)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85506/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85505 - High (7.5)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has differe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85505/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85504 - Critical (9.8)
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-64200 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffer during string conversion. Successful exploitation requires an attacker...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64200/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-64199 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an allocated data structure. Successful exploitation requires an attacker to get a user to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64199/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-64198 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated heap buffer during file handling. Successful exploitation requires an at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-64197 - High (7.8)
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a spec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85224 - Critical (9.1)
A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85224/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85223 - Critical (9.9)
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85223/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85391 - Critical (9.8)
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85391 - Critical (9.8)
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85391 - Critical (9.8)
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85391 - Critical (9.8)
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85388 - High (8.1)
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85388 - High (8.1)
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85388 - High (8.1)
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85388 - High (8.1)
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85028 - High (7.8)
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85028 - High (7.8)
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85028 - High (7.8)
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85028 - High (7.8)
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85396 - High (7.5)
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85396/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85396 - High (7.5)
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85396/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85396 - High (7.5)
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85396/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85396 - High (7.5)
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85396/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85394 - Critical (9.1)
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85394 - Critical (9.1)
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85394 - Critical (9.1)
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85394 - Critical (9.1)
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85393 - High (7.5)
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85393 - High (7.5)
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85393 - High (7.5)
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85393 - High (7.5)
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-58400 - Critical (9.1)
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58400/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-83959 - High (7.8)
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83959/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85012 - High (8)
Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85154 - Critical (9.8)
WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85154/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85175 - High (8.8)
SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85175/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85174 - High (8.8)
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85174/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-20277 - High (8.2)
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-20277/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-45730 - High (8.3)
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project)...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-45730/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-53635 - High (7.6)
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-52833 - High (8)
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttribut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52833/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-84394 - High (7.5)
fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicaliz...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-84851 - High (7.5)
An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84851/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-49832 - High (8)
DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Veloci...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-49832/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-53649 - Critical (9.6)
Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multip...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53649/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack