home.social

#vulnerability β€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vulnerability, aggregated by home.social.

  1. 🚨 EUVD-2026-33030

    πŸ“Š Score: 6.5/10 (CVSS v3.1)
    πŸ“¦ Product: Kibana, Kibana, Kibana
    🏒 Vendor: Elastic
    πŸ“… Updated: 2026-05-28

    πŸ“ Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload that is processed prior to authorization ch...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  2. 🚨 EUVD-2026-33031

    πŸ“Š Score: 6.5/10 (CVSS v3.1)
    πŸ“¦ Product: Kibana, Kibana
    🏒 Vendor: Elastic
    πŸ“… Updated: 2026-05-28

    πŸ“ Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a speci...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  3. 🚨 EUVD-2026-33032

    πŸ“Š Score: 7.7/10 (CVSS v3.1)
    πŸ“¦ Product: Kibana, Kibana
    🏒 Vendor: Elastic
    πŸ“… Updated: 2026-05-28

    πŸ“ Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kib...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  4. 🚨 EUVD-2026-33033

    πŸ“Š Score: 7.2/10 (CVSS v3.1)
    πŸ“¦ Product: Kibana, Kibana, Kibana
    🏒 Vendor: Elastic
    πŸ“… Updated: 2026-05-28

    πŸ“ Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent policy configuration by injecting values into ...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  5. 🚨 EUVD-2026-33034

    πŸ“Š Score: 6.5/10 (CVSS v3.1)
    πŸ“¦ Product: Kibana
    🏒 Vendor: Elastic
    πŸ“… Updated: 2026-05-28

    πŸ“ Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections manag...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  6. 🚨 EUVD-2026-33035

    πŸ“Š Score: 6.3/10 (CVSS v3.1)
    πŸ“¦ Product: Kibana
    🏒 Vendor: Elastic
    πŸ“… Updated: 2026-05-28

    πŸ“ Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server to issue outbound requests to destinations the egress control...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  7. 🚨 EUVD-2026-33036

    πŸ“Š Score: 9.8/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Hospitality OPERA 5 Property Services, Oracle Hospitality OPERA 5 Property Services, Oracle Hospitality OPERA 5 Property Services (+2 more)
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  8. 🚨 EUVD-2026-33037

    πŸ“Š Score: 7.9/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle REST Data Services
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise ...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  9. 🚨 EUVD-2026-33038

    πŸ“Š Score: 8.1/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle REST Data Services
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Or...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  10. 🚨 EUVD-2026-33039

    πŸ“Š Score: 9.9/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle REST Data Services
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Or...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  11. 🚨 EUVD-2026-33040

    πŸ“Š Score: 9.8/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Payments
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  12. 🚨 EUVD-2026-33041

    πŸ“Š Score: 7.4/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Payments
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with netwo...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  13. 🚨 EUVD-2026-33042

    πŸ“Š Score: 9.1/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Internet Procurement Connector
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabilit...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  14. 🚨 EUVD-2026-33043

    πŸ“Š Score: 8.5/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Financials Common Modules
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  15. 🚨 EUVD-2026-33044

    πŸ“Š Score: 7.7/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Financials Common Modules
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  16. 🚨 EUVD-2026-33045

    πŸ“Š Score: 9.9/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle iAssets
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  17. 🚨 EUVD-2026-33046

    πŸ“Š Score: 7.7/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Public Sector Financials (International)
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitabl...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  18. 🚨 EUVD-2026-33047

    πŸ“Š Score: 9.9/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Universal Work Queue
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerabilit...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  19. 🚨 EUVD-2026-33048

    πŸ“Š Score: 8.8/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Payroll
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  20. 🚨 EUVD-2026-33049

    πŸ“Š Score: 8.8/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Payroll
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  21. 🚨 EUVD-2026-33050

    πŸ“Š Score: 8.1/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Payroll
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  22. 🚨 EUVD-2026-33051

    πŸ“Š Score: 7.5/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle REST Data Services
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromi...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  23. 🚨 EUVD-2026-33052

    πŸ“Š Score: 5.3/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle REST Data Services
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromi...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  24. 🚨 EUVD-2026-33013

    πŸ“Š Score: 9.0/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Database Server
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compro...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  25. 🚨 EUVD-2026-33015

    πŸ“Š Score: 7.5/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Database Server
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromi...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  26. 🚨 EUVD-2026-33014

    πŸ“Š Score: 7.5/10 (CVSS v3.1)
    πŸ“¦ Product: Oracle Database Server
    🏒 Vendor: Oracle Corporation
    πŸ“… Updated: 2026-05-28

    πŸ“ Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromi...

    πŸ”— euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  27. 🟠 CVE-2026-45047 - High (7.5)

    bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read si...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  28. πŸ“Š EUVD Daily CVSS Summary

    🟑 Average Score: 6.96/10 (Medium)
    πŸ“ˆ Vulnerabilities: 397
    ⬇️ Min: 2.7 | ⬆️ Max: 10.0

    πŸ“… Date: 2026-05-27

    #cybersecurity #infosec #euvd #cvss #vulnerability

  29. πŸ“Š EUVD Daily CVSS Summary

    🟑 Average Score: 6.74/10 (Medium)
    πŸ“ˆ Vulnerabilities: 286
    ⬇️ Min: 1.8 | ⬆️ Max: 10.0

    πŸ“… Date: 2026-05-26

    #cybersecurity #infosec #euvd #cvss #vulnerability

  30. 🟠 CVE-2026-42735 - High (8.2)

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <= 4.3.0.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  31. 🟠 CVE-2026-42735 - High (8.2)

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <= 4.3.0.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  32. 🟠 CVE-2026-42735 - High (8.2)

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <= 4.3.0.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  33. πŸ”΄ CVE-2026-42755 - Critical (9.3)

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allows Blind SQL Injection.This issue affects TableOn: from n/a through <= 1.0.5.1.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  34. πŸ”΄ CVE-2026-42755 - Critical (9.3)

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allows Blind SQL Injection.This issue affects TableOn: from n/a through <= 1.0.5.1.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  35. πŸ”΄ CVE-2026-42755 - Critical (9.3)

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allows Blind SQL Injection.This issue affects TableOn: from n/a through <= 1.0.5.1.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  36. πŸ”΄ CVE-2026-42748 - Critical (9.9)

    Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue affects WPify Woo Czech: from n/a through <= 5.4.1.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  37. πŸ”΄ CVE-2026-42748 - Critical (9.9)

    Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue affects WPify Woo Czech: from n/a through <= 5.4.1.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack