CVE-2026-14607 - RT-Thread lwp_syscall.c sys_getaddrinfo memory corruption
CVE ID :CVE-2026-14607
Published : July 3, 2026, 7:45 p.m. | 2 hours, 1 minute ago
Description :A weakness has been identified in RT-Thread up to 5.0.2. This affects the function sys_getaddrinfo of the file components/lwp/lwp_syscall.c. Executing a manipulation of the argument ai_addr can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14607
Published : July 3, 2026, 7:45 p.m. | 2 hours, 1 minute ago
Description :A weakness has been identified in RT-Thread up to 5.0.2. This affects the function sys_getaddrinfo of the file components/lwp/lwp_syscall.c. Executing a manipulation of the argument ai_addr can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14608 - SourceCodester CET Automated Grading System with AI Predictive Analytics POST index.php view_student authorization
CVE ID :CVE-2026-14608
Published : July 3, 2026, 8 p.m. | 1 hour, 46 minutes ago
Description :A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14608
Published : July 3, 2026, 8 p.m. | 1 hour, 46 minutes ago
Description :A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58292 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE ID :CVE-2026-58292
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58292
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58293 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE ID :CVE-2026-58293
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58293
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58294 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE ID :CVE-2026-58294
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58294
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58295 - Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE ID :CVE-2026-58295
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58295
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58296 - Microsoft Edge for Android Information Disclosure Vulnerability
CVE ID :CVE-2026-58296
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58296
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58297 - Microsoft Edge for Android Information Disclosure Vulnerability
CVE ID :CVE-2026-58297
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58297
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58298 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE ID :CVE-2026-58298
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58298
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58300 - Microsoft Edge for Android Information Disclosure Vulnerability
CVE ID :CVE-2026-58300
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 6.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58300
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 6.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58524 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE ID :CVE-2026-58524
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58524
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58597 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE ID :CVE-2026-58597
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58597
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45489 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE ID :CVE-2026-45489
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-45489
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58291 - Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE ID :CVE-2026-58291
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58291
Published : July 3, 2026, 8:35 p.m. | 3 hours, 12 minutes ago
Description :None
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12481 - Deserialization of Untrusted Data in keras-team/keras
CVE ID :CVE-2026-12481
Published : July 3, 2026, 8:36 p.m. | 3 hours, 11 minutes ago
Description :A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard when `safe_mode` is set to `None`, which is the default value when `from_config()` is called outside of a `SafeModeScope` context. This logic error conflates `None` (unset/default-deny) with `False` (explicitly disabled), bypassing the guard and allowing attacker-controlled `marshal` bytecode to be deserialized. Affected call sites include `keras.layers.deserialize(config)`, `keras.models.clone_model(model)`, and any direct invocation of `Lambda.from_config(config)` without an enclosing `SafeModeScope(True)`. This vulnerability can be exploited to achieve arbitrary OS-level code execution in the context of the server or user process.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-12481
Published : July 3, 2026, 8:36 p.m. | 3 hours, 11 minutes ago
Description :A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard when `safe_mode` is set to `None`, which is the default value when `from_config()` is called outside of a `SafeModeScope` context. This logic error conflates `None` (unset/default-deny) with `False` (explicitly disabled), bypassing the guard and allowing attacker-controlled `marshal` bytecode to be deserialized. Affected call sites include `keras.layers.deserialize(config)`, `keras.models.clone_model(model)`, and any direct invocation of `Lambda.from_config(config)` without an enclosing `SafeModeScope(True)`. This vulnerability can be exploited to achieve arbitrary OS-level code execution in the context of the server or user process.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-14610 - Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile heap-based overflow
CVE ID :CVE-2026-14610
Published : July 3, 2026, 8:45 p.m. | 3 hours, 2 minutes ago
Description :A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-14610
Published : July 3, 2026, 8:45 p.m. | 3 hours, 2 minutes ago
Description :A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58418 - SSRF via HTTP Redirect in Repository Migration
CVE ID :CVE-2026-58418
Published : July 3, 2026, 8:54 p.m. | 2 hours, 53 minutes ago
Description :SSRF via HTTP Redirect in Repository Migration
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58418
Published : July 3, 2026, 8:54 p.m. | 2 hours, 53 minutes ago
Description :SSRF via HTTP Redirect in Repository Migration
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58419 - Notification API leaks private issue metadata after access revocation
CVE ID :CVE-2026-58419
Published : July 3, 2026, 8:54 p.m. | 2 hours, 53 minutes ago
Description :Notification API leaks private issue metadata after access revocation
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58419
Published : July 3, 2026, 8:54 p.m. | 2 hours, 53 minutes ago
Description :Notification API leaks private issue metadata after access revocation
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58421 - Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE ID :CVE-2026-58421
Published : July 3, 2026, 8:54 p.m. | 2 hours, 53 minutes ago
Description :Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58421
Published : July 3, 2026, 8:54 p.m. | 2 hours, 53 minutes ago
Description :Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58422 - Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE ID :CVE-2026-58422
Published : July 3, 2026, 8:54 p.m. | 2 hours, 53 minutes ago
Description :Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-58422
Published : July 3, 2026, 8:54 p.m. | 2 hours, 53 minutes ago
Description :Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...